Skip to main content
Emerging ThreatsMalware & Ransomware

Ransomware Attacks Pivot to Identity-Based Exploits

Blurred laptop on reception desk in brightly-lit office lobby with large window.

"Four out of five ransomware attacks now begin with identity in one form or another," Rafe Pilling, Director of Threat Intelligence at Sophos, warned in a briefing with Asia Pacific technology media.

Identity-based entry surpasses software flaws

Sophos' latest threat intelligence, as presented by Pilling, documents a clear shift in how ransomware operators gain access to organisations. For the first time in recent years, exploited software vulnerabilities are no longer the leading root cause. Instead, the State of Ransomware report that Pilling cited places malicious email at the top (26 percent), followed by phishing (24 percent) and compromised credentials (23 percent). "Identity is no longer just part of the ransomware story. It is increasingly how ransomware operators are gaining access in the first place," he said.

AI is speeding up familiar attack techniques

The firm's findings stress that artificial intelligence is not necessarily inventing wholly new classes of cyberattack, but is making existing techniques dramatically faster and more scalable. Sophos tracked a campaign in which attackers coordinated "around a dozen AI agents through a commercial coding assistant to write, test and refine malware against endpoint security products." That operation tested nearly 80 malware modules and multiple evasion techniques in what Pilling described as a "virtual laboratory." The result was a tempo change: "Work that would previously have taken a human operator weeks was completed in a matter of days,” he explained.

AI platforms, chatbot tokens and a governance gap

Pilling warned that as organisations rush to deploy generative AI and autonomous agents, they are simultaneously creating new classes of credential risk. Threat actors are increasingly targeting credentials tied to AI platforms and business applications; Pilling cited incidents in which chatbot access tokens were used to compromise enterprise environments, and noted that stolen ChatGPT credentials continue appearing on underground criminal marketplaces. He also referenced industry research showing that 71 percent of large enterprises are already running AI agents against core business systems, while only 16 percent have governance controls in place.

Connected defences are improving resilience — and cutting payouts

Despite the growth and acceleration of attacks, Sophos reports some measurable improvements in ransomware outcomes where security operations are stronger and better integrated. Average recovery costs remain around US$1.7 million, and 56 percent of ransomware attacks still result in data encryption. But ransomware demands have fallen by 65 percent compared with two years ago, and actual ransom payments have dropped by 62 percent over the same period. Pilling attributed those improvements to earlier detection across multiple control points and the combination of signals: "firewall telemetry on its own has value, but when it's combined with endpoint, email and identity signals through an XDR platform or managed service, organisations are significantly better positioned to stop attacks before encryption occurs,” he said.

What this means for technologists, procurement leaders, and policymakers

  • Technologists and security teams: The research underscores a need to treat identity signals as primary telemetry alongside email and endpoint data, and to prioritise integration through XDR platforms or managed services that can correlate identity events with other controls.
  • Procurement leaders and enterprise IT: Rapid adoption of AI agents (71 percent among large enterprises, per the research Pilling cited) creates an acute procurement and configuration challenge; the gap between deployment and governance (16 percent with controls) suggests procurement choices should include governance and credential protection as explicit selection criteria.
  • Policymakers and regulators: The rise of credential-driven attacks and the appearance of stolen chatbot and ChatGPT credentials in underground markets point to an evolving risk category tied to AI platform authentication and access tokens that may merit focused guidance or standards.

Pilling summed the trend bluntly: "The common thread across everything we're seeing is that attacks are becoming faster, more automated and more capable across multiple parts of an environment at the same time." His closing prescription was equally specific: future cyber resilience will depend less on deploying a greater number of discrete security products and more on building connected security operations capable of seeing and responding to the entire attack chain as one coordinated event.

Original story