"This data confirms what we’ve been saying: 79% of ransomware attacks start with identity — nearly double malicious email and phishing combined," Chandra Gnanasambandam, Chief Technology Officer at SailPoint, told researchers summarizing a new Sophos report. The report frames compromised credentials, not exotic zero-days, as the single most common opening move in modern ransomware.
Key findings from the Sophos report
Sophos found that 79% of ransomware incidents began with the abuse of legitimate user logins and identities. The report breaks down the initial-access vectors that rely on valid credentials: intrusions on systems or applications (38%), remote device logins (30%), firewall access (21%), VPNs (8%), and IoT devices (3%).
Other headline metrics in the study show shifting patterns year over year: malicious email was the entry point in 26% of incidents (up from 19% in 2025); phishing attacks caused 24% of incidents (up from 18% the prior year); brute force attacks accounted for 23% of incidents (compared with 22% in 2025); and exploitation of known security vulnerabilities fell from 32% to 18% in 2026.
How compromised identities are used to move inside networks
The report and quoted security leaders make a simple tactical point: once an attacker has a legitimate identity, they can often move and operate while blending into normal activity. Shane Barney, Chief Information Security Officer at Keeper Security, said stolen credentials “are now the dominant ransomware entry point” and that attackers who obtain legitimate identities “can move through an environment undetected, escalating privileges and staging ransomware before most teams know something is wrong.”
Several contributors to the report urged shrinking the window of exposure: apply least-privilege principles, eliminate standing administrative access, and build visibility into who is accessing critical systems and whether that access is appropriate. James Maude, Field CTO at BeyondTrust, recommended investing “more in shifting left” by securing identities and access to reduce attack surface and blast radius, rather than focusing only on post-breach measures.
Malicious email, phishing, and the role of AI
The Sophos data shows email and phishing remain significant vectors. Malicious email accounted for 26% of ransomware entry points and phishing for 24% — both higher than the previous year. Mika Aalto, Co‑Founder and CEO at Hoxhunt, warned that phishing is usually a front door to larger compromises: “If ransomware is the explosion, phishing is often the spark.”
Aalto added that phishing has been modernized: recent research cited in the report found that AI‑generated phishing “surged 14‑fold almost overnight” at the turn of 2025 to 2026. She described the new wave as upgrades to old attacks — cleaner formatting, more personalized messaging, and scale through automation — and argued that security awareness programs must evolve from information to behavior, shaping how people act in real time.
Organizational constraints: gaps in detection, resources, and solutions
The Sophos report surveyed cybersecurity leaders on why attacks go undetected. Sixty‑two percent cited network security gaps as the reason; 58% said their organization was inhibited by lack of resources or employee expertise; and 57% believed their organization had not implemented sufficient cybersecurity solutions. Trey Ford, Chief Strategy and Trust Officer at Bugcrowd, cautioned that criminal ransomware operations have become “a scalable business model” and predicted continued growth in attack volume, noting also that reported incidents will lag actual incidents because larger targets have invested more aggressively to mitigate exposure.
What this means for technologists, policymakers, and enterprises
- Technologists and security teams: The data directs attention to identity controls as the critical perimeter. Leaders in the report called for continuous validation of identities, elimination of standing privileges, and better visibility into account usage — actions intended to reduce the blast radius when credentials are compromised.
- Policymakers and regulators: The shift described in the report — from exploiting software vulnerabilities to abusing legitimate credentials — suggests regulatory and policy emphasis may need to account for identity governance, workforce skill gaps, and resource constraints cited by 58% of survey respondents.
- Affected enterprises and procurement leaders: With malicious email and phishing rising and AI making social engineering more convincing, procurement choices that prioritize adaptive identity solutions, least‑privilege architectures, and continuous monitoring are the practical levers highlighted by multiple contributors.
Security leaders quoted in the report converge on one clear theme: identity is now the primary vector of ransomware, and defenses must be reoriented accordingly. Chandra Gnanasambandam described the shift as moving to a “human‑plus‑AI world that demands adaptive identity and zero standing privilege as baseline.” Whether organizations can translate that diagnosis into sustained changes in policy, tooling, and day‑to‑day behavior remains the urgent operational question the Sophos data leaves on the table.




