Ransomware · 60 days ago
Ransomware is leaning harder on identity than on software flaws. The weak point is no longer just patched vulnerabilities; attackers are getting in with real-looking credentials, then using those logins to reach exposed apps, remote access, firewalls, and VPNs that trust them.
Sophos says 79% of ransomware incidents traced to compromised identities and legitimate user logins. In the same research snapshot, vulnerability-based starts fell from 32% in 2025 to 18% in 2026, while phishing accounted for 24% and brute force for 23% of initial access.
That shifts the failure mode for defenders from malware detection to identity control. If passwords, MFA, and remote login are the trust boundary, ransomware can start long before any payload is visible.
4 sources covering this story
Ransom demands are down, email is the top way attackers get in - Help Net Security
The State of Ransomware 2026 shows email and stolen logins now drive most attacks, ransom demands falling, recovery costs climbing.
Srsly Risky Biz: Ransomware uses AI to amp up negotiations
Tom Uren and James Wilson talk about different ways ransomware groups are taking advantage of AI.
Identity Attacks Overtake Exploits as Top Ransomware Cause
Phishing and malicious email now cause half of all ransomware attacks, overtaking vulnerabilities.
Compromised Logins Surge as the Most Common Entry Point for Ransomware
Research of incidents by Sophos finds that phishing, brute force attacks and other identity-based threats have surpassed software vulnerabilities as means of delivering ransomware
Part of the PlainSec briefing for 2026-07-16