Identity Attacks Overtake Exploits as Top Ransomware Cause (Sophos State of Ransomware 2026) — Threadlinqs Intelligence
As of 2026-07-16, Identity Attacks Overtake Exploits as Top Ransomware Cause (Sophos State of Ransomware 2026) is a info-severity threat intel threat attributed to Multiple ransomware-as-a-service groups (Akira, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1398 · Severity: INFO · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Multiple ransomware-as-a-service groups (Akira · FINANCIAL
Sophos' State of Ransomware 2026 report (2,158 IT/security leaders, 17 countries, organizations hit by ransomware in the past 12 months) finds 79% of ransomware attacks now start with an
Sophos' 2026 threat-intelligence portfolio — the State of Ransomware 2026 survey, the Active Adversary Report 2026, and the State of Identity Security 2026 report — collectively documents a structural shift in ransomware initial-access patterns away from vulnerability exploitation and toward identity compromise.
In the State of Ransomware 2026 survey (2,158 IT/cybersecurity leaders across 17 countries, all from organizations hit by ransomware in the prior 12 months), the top reported root causes were malicious email (26%, up from 19% in 2025), phishing (24%, up from 18%), and compromised credentials (23%), while exploited vulnerabilities fell to 18% (from 32% in 2025) and brute-force attacks accounted for 6%. Combined, these identity-adjacent vectors mean 79% of ransomware attacks now start with an identity-based approach. Attackers most often entered through exposed applications/systems (38%), user devices (30%), firewalls (21%), VPNs (8%), and IoT devices (3%).
Critically, 97% of victims whose root cause was compromised credentials had MFA deployed in some form at the time of attack — but coverage was uneven: SaaS applications were commonly protected while VPNs, firewall admin consoles, and legacy/on-prem applications frequently were not. Sophos CISO Ross McKerchar warned that AI-assisted reconnaissance will let attackers "enumerate identity misconfigurations far more cheaply and quickly than before," widening this gap further.
The Active Adversary Report 2026 (661 incident-response/MDR cases across 70 countries and 34 industries) found 67% of incidents traced to identity-related weaknesses and MFA absent in 59% of those cases. Once inside, attackers reached Active Directory in a median of 3.4 hours, with overall median dwell time falling to 3 days (down year-over-year, reflecting both faster attacker tradecraft and faster defender response). Payload deployment (88%) and data exfiltration (79%) both occurred predominantly outside business hours, an evasion pattern that exploits reduced SOC staffing and, increasingly, thinner log retention: the report noted missing-log incidents (often due to 7-day or 24-hour firewall log retention defaults) doubled year-over-year. Sophos tracked 51 distinct ransomware brands (27 returning, 24 new) — the highest number of active groups in the report's history — with Akira (tracked as GOLD SAHARA) involved in 22% of incidents and only LockBit, MedusaLocker, Phobos, and BitLocker-abuse operations persisting continuously since 2020.
The companion State of Identity Security 2026 report (5,000 IT/security leaders, 17 countries, 14 industries) found 71% of organizations suffered at least one identity-related breach in the past 12 months (averaging three per affected organization), with Switzerland (89%) and Mexico (83%) hit hardest and the energy/oil/gas sector most exposed (80%). 67% of ransomware victims tied their attack directly to their most significant identity compromise. A major and emerging root cause is weak non-human identity (NHI) management — API keys, service accounts, and AI agents, which can outnumber human identities by ratios as high as 100:1 — implicated in 41% of successful identity breaches; only 34% of organizations regularly audit or rotate NHIs, and just 11.1% do so continuously. Organizations with weak NHI management saw 22% higher likelihood of financial theft and 24.4% higher likelihood of extortion, and averaged $147,178 higher recovery costs. Average identity-breach remediation cost was $1.64 million (median $750,000), with 73% of victims spending $250,000+ per incident.
On outcomes, 56% of ransomware attacks still succeeded in encrypting data despite these defenses; 48% of victims with encrypted data paid a ransom (roughly flat against the four-year average of 50%). Median ransom demands fell 65% over two years to $698,000, and median payments fell to $769,000 from $1 million previously, with 51% of paying organizations negotiating below the initial demand — a tre
Target sectors: government administration, energy, oil-and-gas, retail, finance, information-technology, cross-sector
Target regions: North America, Europe, united kingdom, switzerland, mexico, Global
Related threats
- Sophos State of Ransomware 2026: Payments Drop as Encryption Success Climbs, Identity-Based Attacks Now Dominant Vector
- US Treasury (OFAC) and UK Sanction First VPN Service (1VPNS), Administrator Dmytro Rashevskyi, and Cryptor Seller Yevgeniy Silayev for Enabling Anubis and Sinobi Ransomware Operations
- Duplicate Ransomware Leak-Site Claims: RaaS Cartels, Affiliate Re-Extortion, Access-Broker Resale, and Fabrication (Bitdefender 'Claimed Twice')
- Ransomware Attack on Coca-Cola's Fairlife Dairy Halts U.S. Production Systems
- Ransomware Attack Suspends Coca-Cola Fairlife U.S. Milk Production
- AI Agent Identities Emerge as the Enterprise's Fastest-Growing Attack Surface: OAuth Tokens, Shadow AI, and AI-Driven EDR Evasion (STAC6994, UNC6395, NadMesh)
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, INFO, threat intelligence, cybersecurity, T1566, T1078, T1190, T1133, T1110, T1556, T1552, T1098, T1136, T1482