79% of Ransomware Attacks Start With Compromised Identities

Compromised identities have overtaken exploited vulnerabilities as the leading way ransomware gangs break into organisations, according to new research from Sophos, with Singapore recording a 67% identity-based attack rate.

Sophos‘ seventh annual State of Ransomware report, a vendor-agnostic survey of 2,158 IT and cybersecurity decision-makers across 17 countries, found that four in five (79%) ransomware attacks globally now begin with compromised identities. For the first time in four years, exploited vulnerabilities are no longer the most common root cause, with malicious email (26%) and phishing (24%) taking the top spot instead.

Singapore’s identity attack rate

In Singapore, 67% of ransomware attacks began with an identity-based attack, according to the report, followed by exploited vulnerabilities (27%), compromised credentials (24%), malicious emails (21%) and phishing (18%). Locally, 15% of organisations hit by ransomware had their data encrypted, while 21% had data both encrypted and stolen. On recovery, 6% of Singapore organisations recovered in less than a day, and 48% recovered within a week.

Globally, two-thirds of ransomware victims (67%) confirmed their ransomware incident was also their most significant identity attack, establishing identity compromise as a primary delivery mechanism. Multi-factor authentication was deployed in some capacity for 97% of incidents where compromised credentials were the root cause, underscoring that MFA alone is not enough to stop ransomware.

“As we see ransomware criminals experiment with AI, it has the potential to accelerate their ability to steal valuable assets, hold them hostage and do it at a scale that exceeds their previous capability. This speed requires careful round-the-clock monitoring of the most exploited means of entry, which our data shows to be stolen and compromised valid accounts,” said Ross McKerchar, Chief Information Security Officer, Sophos.

Recovery improves, but costs keep rising

Over half of ransomware attacks (56%) succeeded in encrypting data globally, up from 50% in 2025 but below the 75% peak in 2023. When data is encrypted, organisations face roughly a 50-50 chance of paying a ransom — 48% did so, bringing the four-year average payment rate to 50%. Median ransom demands have dropped 65% over the last two years, yet average recovery costs following an attack have climbed to $1.7 million per incident.

Organisations have also become faster at bouncing back: 55% recovered within a week and 16% in under a day, which Sophos attributes to increased investment in backup infrastructure.

AI raises the stakes for defenders

“As AI becomes more capable, attackers will be able to enumerate identity misconfigurations and weak points across organisations far more cheaply and quickly than before. Organisations can no longer rely on complexity or obscurity to hide gaps in their environment,” said McKerchar.

Sophos recommends organisations treat identity as a foundational security layer by enforcing phishing-resistant MFA across all access points, regularly auditing both human and non-human identities, investing in tested and immutable backup infrastructure, and connecting firewalls to XDR and MDR solutions to detect ransomware before payloads deploy.

The survey was conducted by Vanson Bourne on behalf of Sophos in the first quarter of 2026, interviewing organisations with 100 to 5,000 employees that had been hit by ransomware in the previous 12 months across 15 industry sectors.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading