2 min read

Past the Perimeter: Why Identity, Not Exploits, Now Drives Ransomware- 261

Past the Perimeter: Why Identity, Not Exploits, Now Drives Ransomware- 261

July 17, 2026

For three consecutive years, unpatched vulnerabilities held the dubious distinction of being ransomware's most common point of entry. Sophos' newly published State of Ransomware 2026 report, drawn from a survey of more than 2,100 security leaders across 17 countries whose organizations were hit over the past year, shows that title has changed hands: malicious email and phishing now account for half of all root causes combined, while vulnerability exploitation has fallen to 18 percent, down from 32 percent. The shift marks less a decline in exploitable software flaws than a redirection of attacker effort toward the credential layer, where the return on investment has proven higher.

The report's most consequential finding is not that identity-based attacks are rising, but that the defenses organizations have already deployed against them are failing at a rate that should trouble any security leader who has treated multifactor authentication as a solved problem. Compromised credentials were the root cause in 23 percent of ransomware incidents, and in 97 percent of those cases, the victim organization had MFA deployed at the time of the attack. Sophos offers two explanations that are not mutually exclusive: incomplete deployment across all relevant systems leaving gaps for attackers to route around, and the simple reality that MFA bypass techniques have matured faster than the credibility of MFA as a standalone control. FIDO2 tokens, the phishing-resistant standard often held up as the answer to bypass concerns, ranked only fourth among the secondary authentication methods in use, behind one-time passwords, push-based approval, and passkeys — the very mechanisms most susceptible to fatigue attacks and social engineering.

identity vs. exploits

The report's practical implication is a reorientation of security investment rather than an abandonment of any existing control. Sophos' own recommendation is not a specific MFA technology but a shift toward identity threat detection and response, comprehensive credential auditing across both human and non-human accounts, and what Sophos field CISO Chet Wisniewski describes as aggressive defense-in-depth: segmentation, zero-trust network access replacing legacy VPNs, and continuous threat hunting built on the assumption that any single layer, MFA included, will eventually be bypassed and should be treated as a speed bump and an alert trigger rather than a wall. The finding lands with particular weight given the parallel rise of AI-driven offensive tooling capable of automating credential-phishing and social-engineering campaigns at a scale human operators cannot match, a trend that stands to accelerate the very identity-attack vector this report identifies as ransomware's new center of gravity.