Sophos reported that identity-focused intrusion methods have overtaken software exploitation as the leading root cause of ransomware incidents, marking a shift in how attackers gain access to victim environments. In its State of Ransomware 2026 survey of 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the past year, malicious email accounted for 26% of attacks, phishing for 24%, and compromised credentials for 23%, while vulnerability exploitation fell to 18% from 32% previously.
The findings also showed that 67% of victims said their ransomware incident was the most significant identity attack they faced during the year, underscoring the overlap between ransomware and identity compromise. Sophos said the presence of MFA in 97% of credential-compromise cases indicates that MFA alone often failed to stop intrusions, likely due to incomplete deployment and evolving bypass techniques, and urged organizations to strengthen identity threat detection, credential auditing, segmentation, ZTNA, and continuous detection and response alongside patch management.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Sophos released its State of Ransomware 2026 report, based on a survey of 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the past year. The report found identity-based intrusion methods had overtaken vulnerability exploitation as the leading root cause of ransomware incidents.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcescworld.com
Open sourcehelpnetsecurity.com
Open sourcesophos.com
Open sourcedarkreading.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.