Ransomware attackers are no longer primarily exploiting software vulnerabilities to gain access—they are stealing identities.
Sophos’ seventh annual State of Ransomware report revealed that 79% of ransomware incidents now originate from compromised credentials, marking a decisive shift in how cybercriminals breach organisations worldwide.
The vendor-agnostic survey of 2,158 IT and cybersecurity leaders across 17 countries found that malicious emails (26%) and phishing campaigns (24%) have overtaken exploited vulnerabilities as the leading root causes of ransomware attacks. This marks the first time in four years that vulnerabilities have fallen from the top spot, underscoring how threat actors are prioritising human and identity weaknesses over technical flaws.
Despite this shift, exploited vulnerabilities remain high-value targets. Attacks initiated through firewall vulnerabilities carry median ransom demands of $1 million or more in 59% of cases, compared to 48% across all attack types.
“As we see ransomware criminals experiment with AI, it has the potential to accelerate their ability to steal valuable assets, hold them hostage and do it at a scale that exceeds their previous capability,” said Ross McKerchar, chief information security officer at Sophos.

“This speed requires careful round-the-clock monitoring of the most exploited means of entry, which our data shows to be stolen and compromised valid accounts. However, the improvement of unguarded open-weight AI models will give attackers a growing advantage in finding and exploiting software vulnerabilities. Defenders cannot rely on patching alone to keep pace, so reducing external exposure and maintaining strong endpoint protection is essential.” Ross McKerchar
The report also reveals that 56% of ransomware victims had their data encrypted, reversing a two-year downward trend. Of those, 48% paid the ransom, with median demands dropping 65% over the past two years. While organisations are becoming more effective at negotiating settlements—51% secured reductions below initial demands—the average recovery cost has risen to $1.7 million per incident.
Smaller organisations remain disproportionately vulnerable. Only 34% of businesses with 100–250 employees stopped attacks before encryption or extortion, compared to 46% of firms with 3,001–5,000 employees.
Despite widespread multi-factor authentication (MFA) deployment—present in 97% of incidents involving compromised credentials—the findings highlight that MFA alone is insufficient. Coverage gaps and misconfigurations continue to create exposure.
Sophos recommends treating identity as a foundational security layer, enforcing phishing-resistant MFA, investing in immutable backup infrastructure, and maintaining rigorous exposure management programmes. The firm also advises reducing internet-facing services and integrating firewall telemetry with XDR and MDR solutions to detect attacks earlier.
“Organisations have strengthened their ransomware resilience in the past year, and those investments are largely paying off,” McKerchar added. “However, ransomware continues to cost organisations millions. As AI becomes more capable, attackers will be able to enumerate identity misconfigurations and weak points across organisations far more cheaply and quickly than before.”









