Ransomware Attacks Rise as Breached User Accounts Become Primary Attack Vector, Report Finds

Use Sophos' victim survey to prioritize account security, MFA coverage, and faster ransomware containment.

A new Sophos survey does not establish that ransomware attacks rose overall. It does show that compromised identities became the dominant initial-access vector, while successful data encryption increased from 50% in 2025 to 56% in 2026. A compromised identity is a user or service account that an attacker has taken over. Sophos found that 79% of surveyed ransomware incidents began with compromised identities, shifting defensive attention toward account security and access controls.

Table of Contents

How breached accounts lead to ransomware

Attackers can use a compromised account to enter systems, move through an organization, and deliver ransomware. The account may appear legitimate, making the intrusion harder to distinguish from normal activity. Sophos reported that 67% of victims considered ransomware their most significant identity attack.

Its findings connect account compromise directly with ransomware delivery. Malicious email accounted for 26% of reported root causes, followed by phishing at 24%. Exploited vulnerabilities were not the leading root cause for the first time in four years. These categories describe how an incident started, while compromised identity describes the access attackers obtained.

More incidents ended with encrypted data

attackers encrypted data in 56% of surveyed incidents. That included 16% in which attackers both encrypted and stole information, exposing victims to operational disruption and possible data disclosure. The encryption rate provides the survey's clearest evidence of worsening outcomes.

However, it does not prove that the total number or overall rate of ransomware attacks increased. Smaller organizations had greater difficulty containing attacks. Only 34% of organizations with 100–250 employees stopped ransomware before encryption or extortion, compared with 46% of organizations employing 3,001–5,000 people, according to Sophos' reported comparison.

Why MFA was not enough

Multi-factor authentication, or MFA, requires another verification step beyond a password. It remains an important control, but simply deploying it somewhere does not mean every sensitive account and access route is protected.

Sophos found that 97% of compromised-credential ransomware incidents involved organizations with MFA deployed "in some capacity." That result points to gaps in MFA coverage or configuration, rather than showing that MFA has no value. Organizations should check whether MFA covers administrators, remote access, email, cloud services, and other accounts that can reach important systems. They should also identify legacy access paths, stale accounts, and exceptions that weaken otherwise broad coverage.

What organizations should prioritize

The findings support treating identity security and ransomware defense as one connected problem. Security teams should focus on preventing account takeover while preparing to contain attackers who obtain valid access.

Smaller organizations may need to concentrate limited resources on accounts with the broadest access. A short, verified list of privileged accounts can make emergency containment faster and more precise.

  • Inventory user, administrator, service, and remote-access accounts.
  • Apply MFA consistently and document every exception.
  • Remove dormant accounts and unnecessary privileges.
  • Monitor unexpected sign-ins and unusual account activity.
  • Prepare procedures to disable accounts and revoke active access quickly.

What the survey cannot tell readers

Sophos surveyed 2,158 IT and cybersecurity decision-makers across 17 countries. Every participating organization employed 100–5,000 people and had experienced ransomware during the previous 12 months.

That design offers insight into victims' experiences, not ransomware incidence across all organizations. The Sophos survey population therefore cannot support the broader claim that ransomware attacks rose overall.


You Might Also Like