Ransomware is leaning harder on identity than on software flaws. The weak point is no longer just patched vulnerabilities; attackers are getting in with real-looking credentials, then using those logins to reach exposed apps, remote access, firewalls, and VPNs that trust them.
Sophos says 79% of ransomware incidents traced to compromised identities and legitimate user logins. In the same research snapshot, vulnerability-based starts fell from 32% in 2025 to 18% in 2026, while phishing accounted for 24% and brute force for 23% of initial access.
That shifts the failure mode for defenders from malware detection to identity control. If passwords, MFA, and remote login are the trust boundary, ransomware can start long before any payload is visible.