Sophos State of Ransomware 2026: Payments Drop as Encryption Success Climbs, Identity-Based Attacks Now Dominant Vector
Sophos State of Ransomware 2026 (TL-2026-1365), also tracked as Sophos State of Ransomware 2026, is a medium-severity ransomware operation, first published 2026-07-15. It has no confirmed attribution, affects Cross-industry Global organizations surveyed on ransomware incidents, maps to 18 MITRE ATT&CK techniques (T1018, T1021, T1078), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-1365
- Threat ID
- TL-2026-1365
- Also known as
- Sophos State of Ransomware 2026, SoR 2026
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- RANSOMWARE
- First published
- 2026-07-15
- Last reviewed
- 2026-07-15
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- local and state government, retail, cross-sector 2158 organizations surveyed
- Target regions
- united kingdom, North America, Europe, Global (17 countries surveyed)
- Detection rules
- 9
- Indicators of compromise
- 17
Sophos' seventh annual State of Ransomware report, surveying 2,158 IT/security leaders across 17 countries, finds email/phishing has overtaken exploited vulnerabilities as the top ransomware root cause (50% combined vs 18%), while 79% of attacks started with an identity-based approach. Encryption success held/rose to 56% despite lower ransom demands, and average recovery cost rose 11% YoY to $1.7 million per incident.
How Sophos State of Ransomware 2026 works
Sophos' 2026 State of Ransomware report (seventh annual edition) surveyed 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the past 12 months. The headline shift: for the first time in four years, exploited vulnerabilities (18%, down 14 percentage points year-over-year) are no longer the top initial-access root cause. Malicious email (26%) and phishing (24%) now combine for 50% of root causes, and compromised credentials account for a further 23%, meaning identity-adjacent and social-engineering vectors together dwarf direct exploitation. Brute-force attacks account for 6% of incidents.
Identity is the connective tissue across the report: 79% of ransomware attacks started with an identity-based approach, and 67% of victims confirmed their ransomware incident traced back to their most significant identity attack of the year. Critically, 97% of victims whose root cause was compromised credentials had MFA enabled somewhere in the environment -- the failure is one of coverage and configuration, not adoption. Sophos incident-response and MDR telemetry shows MFA gaps concentrated on VPNs, firewall admin consoles, and legacy applications, even where SaaS accounts are well-protected; 59% of IR/MDR cases reviewed showed MFA missing at the point that mattered.
Entry-point data reinforces the same picture: exposed applications/systems (38%) and user devices (30%) are now the leading beachheads, with firewalls (21%) and VPNs (8%) trailing but disproportionately consequential -- when a ransomware attack starts with exploitation of a firewall vulnerability, 59% of resulting ransom demands are $1 million or more, and IoT devices account for a residual 3% of entry points.
On outcomes: 56% of attacks succeeded in encrypting data (up from 50% in 2025), and only 34% of small organizations (100-250 employees) managed to stop an attack before encryption or extortion, versus 46% success at mid-to-large organizations (3,001-5,000 employees). Backup-based recovery was used in 66% of encrypted-data cases, a 12-point rise from 2025, suggesting resilience investment is paying off even as raw encryption success climbs. Financially, the median ransom demand fell to $698,000 (down 65% over two years) and the median payment to $769,000 (down from $1,000,000 in 2025); 51% of paying organizations successfully negotiated the amount down. The UK recorded the highest regional median demand at $2.5 million. 48% of encrypted victims ultimately paid, consistent with the four-year average of roughly 50%, though payment behavior varies sharply by sector: local/state government paid in 72% of cases (highest), while retail paid in only 32% (lowest). Despite lower demands and payments, the average total recovery cost per incident rose 11% year-over-year to $1.7 million, reflecting downtime, remediation, and business-disruption costs that ransom-payment trends alone do not capture.
Sophos frames the core defensive takeaway as convergence: outcomes improve materially when identity, email, endpoint, and network defenses are operated as one integrated system rather than as isolated point controls -- a direct rebuttal to security programs still organized primarily around patch-and-perimeter vulnerability management for a threat that increasingly walks in through the identity plane.
MITRE ATT&CK techniques used in TL-2026-1365
Discovery
T1018 Remote System Discovery; T1087 Account Discovery
Lateral Movement
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1199 Trusted Relationship; T1566 Phishing
Command and Control
Credential Access
T1110 Brute Force; T1552 Unsecured Credentials; T1621 Multi-Factor Authentication Request Generation
Impact
T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1531 Account Access Removal
defense-impairment
T1556 Modify Authentication Process; T1685 Disable or Modify Tools
Affected products and versions in Sophos State of Ransomware 2026
- Cross-industry — Global organizations surveyed on ransomware incidents (2,158 IT/security leaders, 17 countries)
Vulnerable versions: organizations relying on perimeter/vulnerability-centric defense without identity-plane MFA coverage
Fixed in: N/A - survey/trend research, not a patchable product
Remediation for Sophos State of Ransomware 2026
Immediate actions
- Extend MFA enforcement to VPNs, firewall/network-appliance admin consoles, and legacy applications, not just SaaS and email accounts
- Audit and patch internet-exposed applications, systems, and firewall management interfaces, which now account for 38% and 21% of initial entry points respectively
- Validate backup integrity and restoration speed given 66% of encrypted-data cases relied on backup-based recovery
- Deploy phishing-resistant email/identity controls to address the combined 50% malicious-email + phishing root cause
Workarounds
- Restrict and monitor VPN and firewall admin-console access with just-in-time/conditional access where full MFA rollout is not yet complete
- Segment legacy applications lacking MFA support behind additional network-layer authentication controls
Longer-term hardening
- Converge identity, email, endpoint, and network detection/response into a unified security operations workflow rather than siloed point tools
- Build an identity-attack-specific incident response playbook given 79% of ransomware incidents start with identity-based approaches
- Prioritize firewall and VPN vendor patch management given disproportionate $1M+ demand rates tied to firewall-originated attacks
- Invest in small-organization (100-250 employee) pre-encryption detection capability, currently only 34% effective at stopping attacks before encryption
Timeline of Sophos State of Ransomware 2026
- Two-year-prior baseline against which the 2026 report measures decline: median ransom demand roughly 2.9x higher than the $698,000 recorded in 2026 (65% cumulative drop over two years).
- Data-collection window closes for the companion Sophos Active Adversary Report 2026, covering 661 incident-response/MDR cases across 70 countries (Nov 1, 2024 - Oct 31, 2025); finds 67% identity-related root causes, 3.4-hour median time-to-Active-Directory, and 88% of encryptions deployed outside business hours -- data later cited to corroborate the State of Ransomware 2026 identity findings.
- 2025 baseline year: exploited vulnerabilities still the top ransomware root cause; encryption success rate measured at 50%; median ransom payment near $1,000,000; median demand roughly double the 2026 figure.
- Sophos publishes 'The State of Ransomware in Enterprise 2025,' a companion enterprise-focused study drawing on 1,733 enterprises hit by ransomware, feeding into the broader 2026 ransomware research cycle.
- Related Sophos identity-driven-breach research finds ransomware activity peaks outside business hours, reinforcing the identity/monitoring-gap narrative later detailed in the 2026 State of Ransomware report.
- Sophos publishes 'State of Identity Security 2026,' finding 71% of organizations suffered at least one identity breach and that 67% of incidents investigated by Sophos IR/MDR were rooted in identity-related attacks -- directly corroborating the ransomware report's identity-attack findings.
- TL-Intel-Harness ingests the Sophos State of Ransomware 2026 blog post via RSS hunt phase and opens threat record TL-2026-1365 for research and publication.
- Sophos publishes the seventh annual State of Ransomware 2026 report, surveying 2,158 IT/security leaders across 17 countries; finds identity-based approaches behind 79% of attacks, email/phishing displacing exploited vulnerabilities as top root cause, 56% encryption success rate, and $1.7M average recovery cost (up 11% YoY).
Sources cited for Sophos State of Ransomware 2026
- The State of Ransomware 2026: Payments Drop as Encryption Climbs
- Sophos Active Adversary Report 2026: Identity attacks dominate as threat groups proliferate
- State of Identity Security 2026 Report | Identity Breach Insights
- 71% of Organizations Suffered At Least One Identity Breach in the Past Year, Sophos Research Finds
- Over 70% of organizations hit by identity breaches
- Identity-Related Breach Hit 71% of Enterprises, Sophos Survey Finds
- Ransomware activity peaks outside business hours
- The State of Ransomware in Enterprise 2025
Threats related to Sophos State of Ransomware 2026
Detection coverage for TL-2026-1365
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1365 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.