Threat Briefing
Stolen credentials have become the primary entry point for ransomware attacks, and enterprise identity security urgently needs to be strengthened.
According to a recent Sophos report, 79% of ransomware attacks begin with stolen credentials and abuse of legitimate logins. Identity-based attacks have replaced exploit-based attacks as the most common initial intrusion method, and enterprises need to rethink their identity security strategies.
Introduction
The entry points for ransomware attacks are undergoing a fundamental shift. According to Sophos's latest annual ransomware report, 79% of analyzed ransomware incidents can be traced back to the initial intrusion phase exploiting stolen identities and legitimate user logins. This data indicates that the identity layer has become the preferred breach point for cybercriminals, challenging traditional defense strategies centered on vulnerability remediation.
Incident Overview
- Timeline: The report is based on actual incident investigations from 2025–2026, covering 2,158 cybersecurity leaders.
- Background: Identity attacks have surged to become the most common initial intrusion method, replacing the previous pattern dominated by exploit attacks.
- Key Data:
- - 79% of ransomware incidents started with stolen identities or abuse of legitimate credentials.
- - The proportion of malicious emails as an entry point rose from 19% to 26%.
- - Phishing attacks accounted for 24% (18% in the previous year).
- - Brute force attacks accounted for 23% (slightly decreased).
- - Exploit attacks plummeted from 32% to 18%.
- Methods of Exploitation: 38% through exposed applications/systems, 30% through remote device logins, 21% through firewalls, 8% through exposed VPNs, 3% through IoT devices.
Technical and Risk Analysis
Attack Methods and Exploitation Chain
Why have attackers shifted to identity attacks? Sophos CISO Ross McKerchar points out that criminals are relying on "easier" attack methods—using stolen identities as initial access vectors. The proliferation of AI has further amplified social engineering threats: AI can polish phishing emails and design sophisticated ClickFix campaigns to trick users into bypassing MFA.
A typical attack chain includes: 1. Credential harvesting: Stealing valid credentials through phishing, malicious emails, or brute force. 2. Initial access: Using legitimate logins to enter exposed applications, remote desktops, or firewalls. 3. Lateral movement and privilege escalation: Spreading within the internal network using legitimate identities. 4. Deploying ransomware: Finally encrypting data and demanding ransom.
Affected Assets
- Identity attacks are not limited to IT systems. Entry points mentioned in the report include:
- Exposed applications or systems (38%) — such as web applications, SaaS platforms.
- Remote device logins (30%) — including employee personal devices, unhardened remote workstations.
- Firewalls (21%) — management interfaces or VPN gateways.
- VPNs (8%) — remote access points.
- IoT devices (3%) — with weak security on edge devices.
It is worth noting that exploit attacks are no longer mainstream, but that does not mean patching is no longer important. Attackers have simply prioritized the "easier" path.
Enterprise Impact Analysis### Operational Risk
Identity attacks are often difficult to detect because attackers use legitimate credentials and their behavior appears normal. This leads to extended incident response times and potentially broader data encryption. The report shows that 62% of organizations acknowledge known or unknown security gaps that allow attacks to go undetected.
Financial Risk
Data indicates that the median ransom has dropped from $2 million two years ago to $698,000, but large enterprises still face ransom demands in the millions. Attackers are increasingly tailoring ransoms based on the victim's ability to pay—an excessively high demand may force a company to refuse, while a "reasonable" ransom is more likely to prompt payment. 48% of victims paid the ransom, and 66% used backups to recover data. Paying the ransom does not guarantee data recovery and may encourage further attacks.
Compliance and Brand Risk
Identity breaches often involve personal data, which can trigger notification obligations under regulations such as GDPR and CCPA. Ransomware incidents also severely damage customer trust and brand reputation, especially in industries that handle sensitive data (e.g., finance, healthcare, critical infrastructure).
Data Risk
Ransomware attacks not only encrypt data but may also involve data theft and multi-layered extortion. Attackers steal sensitive data before encryption and threaten to leak it publicly, applying additional pressure.
Industry Trend Observations
From Vulnerability Patching to Identity Protection
Over the past five years, vulnerability exploitation has been the primary entry point for ransomware. However, the 2026 report shows that attackers have significantly shifted to identity attacks. This shift means organizations must move their security focus from patch management to identity threat detection and response (ITDR), multi-factor authentication (MFA), and credential governance.
AI-Driven Social Engineering
AI is making phishing emails more realistic and capable of bypassing traditional email security detection. The ClickFix campaign demonstrates how attackers exploit user fatigue with MFA to trick them into approving malicious requests. Is this an isolated event or a trend? All signs point to a rapid increase in AI-powered identity attacks.
Refinement of Ransom Strategies
The drop in median ransom does not mean the threat is weakening. Attackers are adopting more precise extortion models: setting different amounts for organizations of varying sizes to increase the likelihood of payment. This requires organizations to be better prepared in terms of negotiation and backup strategies.
Defense and Response Recommendations
Enterprise Level - Strengthen identity security: Implement a zero-trust architecture to continuously verify all access requests, never trusting default valid credentials. - Comprehensively deploy MFA: Enforce phishing-resistant MFA for all remote access, administrator accounts, and critical systems. - Regularly audit credentials: Identify and remove zombie accounts, weak passwords, and unused privileged accounts.### Technical Level - Deploy Identity Threat Detection and Response (ITDR): Monitor abnormal login behavior, credential misuse, and lateral movement in real time. - SIEM/SOAR Integration: Correlate identity logs with network traffic and endpoint data to accelerate incident response. - Endpoint Protection (EDR/XDR): Detect malicious processes and suspicious activities, even if the initial credentials are legitimate.
Management Level - Develop Ransomware Incident Response Plans: Include backup recovery procedures, ransom decision mechanisms, and communication strategies. - Conduct Red Team Exercises: Simulate identity-based attack scenarios to test employee and system defenses. - Third-Party Risk Management: Ensure key suppliers also enforce strict MFA and access controls.
SecurityPost Insight
Core Revelation
The entry point for ransomware attacks is shifting from technical vulnerabilities to human behavior. 79% of attacks begin with stolen identities, meaning that even if a company perfectly patches all known vulnerabilities, it can still be compromised by a weak password or a successful phishing attempt. Identity security is no longer just a compliance requirement but a cornerstone of modern security architecture.
Implications for Enterprise Security
- Redefine the “Perimeter”: Identity is the new perimeter. Enterprises should elevate Identity Governance and Access Control (IGA) to the same importance as network defense.
- Humans Remain the Weak Link: However, we can reduce risk through technology (e.g., phishing-resistant MFA) and training (security awareness education).
- Backup Is Not a Panacea: Although 66% of enterprises recover data through backups, 48% still pay ransoms. Backups must be combined with offline storage and recovery testing.
Trends to Watch in the Future
- AI-driven credential theft and social engineering will become more common; enterprises need to deploy AI defense tools.
- Identity Threat Detection and Response (ITDR) will become a standard component of security operations centers.
- Supply Chain Identity Attacks: Attackers may infiltrate large enterprises through the identity credentials of third-party service providers.
Enterprise security leaders should learn from Sophos’ report: Attackers are taking shortcuts, and defenders must block the widest shortcut — identity.
Evidence route · securitypost
securitypost frames this note through Security Post publishes defensive cybersecurity intelligence for enterprise security leaders, covering thre.... Threat Briefing / Enterprise Security / AI & Cybersecurity explains the local editorial angle: Source links should be opened before the summary is reused. dates, names and status changes still need checking.