Sophos State of Ransomware 2026: Payments Drop as Encryption Success Climbs, Identity-Based Attacks Now Dominant Vector — Threadlinqs Intelligence
As of 2026-07-15, Sophos State of Ransomware 2026: Payments Drop as Encryption Success Climbs, Identity-Based Attacks Now Dominant Vector is a medium-severity ransomware threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-1365 · Severity: MEDIUM · Status: ACTIVE · Category: RANSOMWARE
Sophos' seventh annual State of Ransomware report, surveying 2,158 IT/security leaders across 17 countries, finds email/phishing has overtaken exploited vulnerabilities as the top ransomware root
Sophos' 2026 State of Ransomware report (seventh annual edition) surveyed 2,158 IT and cybersecurity leaders across 17 countries whose organizations were hit by ransomware in the past 12 months. The headline shift: for the first time in four years, exploited vulnerabilities (18%, down 14 percentage points year-over-year) are no longer the top initial-access root cause. Malicious email (26%) and phishing (24%) now combine for 50% of root causes, and compromised credentials account for a further 23%, meaning identity-adjacent and social-engineering vectors together dwarf direct exploitation. Brute-force attacks account for 6% of incidents.
Identity is the connective tissue across the report: 79% of ransomware attacks started with an identity-based approach, and 67% of victims confirmed their ransomware incident traced back to their most significant identity attack of the year. Critically, 97% of victims whose root cause was compromised credentials had MFA enabled somewhere in the environment -- the failure is one of coverage and configuration, not adoption. Sophos incident-response and MDR telemetry shows MFA gaps concentrated on VPNs, firewall admin consoles, and legacy applications, even where SaaS accounts are well-protected; 59% of IR/MDR cases reviewed showed MFA missing at the point that mattered.
Entry-point data reinforces the same picture: exposed applications/systems (38%) and user devices (30%) are now the leading beachheads, with firewalls (21%) and VPNs (8%) trailing but disproportionately consequential -- when a ransomware attack starts with exploitation of a firewall vulnerability, 59% of resulting ransom demands are $1 million or more, and IoT devices account for a residual 3% of entry points.
On outcomes: 56% of attacks succeeded in encrypting data (up from 50% in 2025), and only 34% of small organizations (100-250 employees) managed to stop an attack before encryption or extortion, versus 46% success at mid-to-large organizations (3,001-5,000 employees). Backup-based recovery was used in 66% of encrypted-data cases, a 12-point rise from 2025, suggesting resilience investment is paying off even as raw encryption success climbs. Financially, the median ransom demand fell to $698,000 (down 65% over two years) and the median payment to $769,000 (down from $1,000,000 in 2025); 51% of paying organizations successfully negotiated the amount down. The UK recorded the highest regional median demand at $2.5 million. 48% of encrypted victims ultimately paid, consistent with the four-year average of roughly 50%, though payment behavior varies sharply by sector: local/state government paid in 72% of cases (highest), while retail paid in only 32% (lowest). Despite lower demands and payments, the average total recovery cost per incident rose 11% year-over-year to $1.7 million, reflecting downtime, remediation, and business-disruption costs that ransom-payment trends alone do not capture.
Sophos frames the core defensive takeaway as convergence: outcomes improve materially when identity, email, endpoint, and network defenses are operated as one integrated system rather than as isolated point controls -- a direct rebuttal to security programs still organized primarily around patch-and-perimeter vulnerability management for a threat that increasingly walks in through the identity plane.
Target sectors: local and state government, retail, cross-sector 2158 organizations surveyed
Target regions: united kingdom, North America, Europe, Global (17 countries surveyed)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
RANSOMWARE, MEDIUM, threat intelligence, cybersecurity, T1566, T1190, T1133, T1078, T1199, T1110, T1621, T1552, T1556, T1562