Ransomware & Extortion · Ransomware
Ransomware Now Enters Through Stolen Logins Ransomware is leaning harder on identity than on software flaws. The weak point is no longer just patched vulnerabilities; attackers are getting in with real-looking credentials, then using those logins to reach exposed apps, remote access, firewalls, and VPNs that trust them.
Sophos says 79% of ransomware incidents traced to compromised identities and legitimate user logins. In the same research snapshot, vulnerability-based starts fell from 32% in 2025 to 18% in 2026, while phishing accounted for 24% and brute force for 23% of initial access.
That shifts the failure mode for defenders from malware detection to identity control. If passwords, MFA, and remote login are the trust boundary, ransomware can start long before any payload is visible.
4 sources · Jul 16
Timeline Sources Jul 16 Help Net Security
Ransom demands are down, email is the top way attackers get in - Help Net Security
The State of Ransomware 2026 shows email and stolen logins now drive most attacks, ransom demands falling, recovery costs climbing.
original Jul 16 Risky Biz News
Srsly Risky Biz: Ransomware uses AI to amp up negotiations
Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI.
original Jul 15 Dark Reading
Identity Attacks Overtake Exploits as Top Ransomware Cause
Phishing and malicious email now cause half of all ransomware attacks, overtaking vulnerabilities.
original Part of the PlainSec briefing for 2026-07-15
Every edition of this story: Ransomware Now Enters Through Stolen Logins
Ransomware & Extortion · Ransomware
Ransomware Now Enters Through Stolen Logins Ransomware is leaning harder on identity than on software flaws. The weak point is no longer just patched vulnerabilities; attackers are getting in with real-looking credentials, then using those logins to reach exposed apps, remote access, firewalls, and VPNs that trust them.
Sophos says 79% of ransomware incidents traced to compromised identities and legitimate user logins. In the same research snapshot, vulnerability-based starts fell from 32% in 2025 to 18% in 2026, while phishing accounted for 24% and brute force for 23% of initial access.
That shifts the failure mode for defenders from malware detection to identity control. If passwords, MFA, and remote login are the trust boundary, ransomware can start long before any payload is visible.
4 sources · Jul 16
Timeline Sources Jul 16 Help Net Security
Ransom demands are down, email is the top way attackers get in - Help Net Security
The State of Ransomware 2026 shows email and stolen logins now drive most attacks, ransom demands falling, recovery costs climbing.
original Jul 16 Risky Biz News
Srsly Risky Biz: Ransomware uses AI to amp up negotiations
Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI.
original Jul 15 Dark Reading
Identity Attacks Overtake Exploits as Top Ransomware Cause
Phishing and malicious email now cause half of all ransomware attacks, overtaking vulnerabilities.
original Part of the PlainSec briefing for 2026-07-15
Every edition of this story: Ransomware Now Enters Through Stolen Logins