Identity Attacks Overtake Exploits as Top Ransomware Cause (Sophos State of Ransomware 2026)
Identity Attacks Overtake Exploits as Top Ransomware Cause (TL-2026-1398), also tracked as State of Ransomware 2026, is a info-severity tracked intrusion set, first published 2026-07-16. It is attributed to Storm-1567 with low confidence, affects Cross-industry Enterprise identity and access management (MFA, maps to 16 MITRE ATT&CK techniques (T1005, T1021, T1070), and is covered by 9 detection rules and 20 indicators of compromise.
Key facts for TL-2026-1398
- Threat ID
- TL-2026-1398
- Also known as
- State of Ransomware 2026, Sophos Active Adversary Report 2026, State of Identity Security 2026
- Severity
- INFO
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-07-16
- Last reviewed
- 2026-07-16
- Attribution
- Storm-1567
- Attribution confidence
- LOW
- Motivation
- FINANCIAL
- Target sectors
- government administration, energy, oil-and-gas, retail, finance, information-technology, cross-sector
- Target regions
- North America, Europe, united kingdom, switzerland, mexico, Global
- Detection rules
- 9
- Indicators of compromise
- 20
Malware and tooling in Identity Attacks Overtake Exploits as Top Ransomware Cause
Malware and tooling: AgendaCrypt, Akira, BitLocker abuse (living-off-the-land encryption), LockBit, MedusaLocker, Phobos, Sophos Central, SophosLabs Intelix
Sophos' State of Ransomware 2026 report (2,158 IT/security leaders, 17 countries, organizations hit by ransomware in the past 12 months) finds 79% of ransomware attacks now start with an identity-based approach — malicious email (26%) and phishing (24%) have displaced exploited vulnerabilities (18%, down from 32% in 2025) as the leading root causes for the first time in four years. Companion Sophos research (Active Adversary Report 2026, State of Identity Security 2026) corroborates the shift: 67% of 661 IR/MDR cases traced to identity weaknesses, MFA was absent in 59% of those cases, and 97% of credential-root-cause ransomware incidents had MFA deployed somewhere — pointing to incomplete MFA coverage (VPNs, firewall admin consoles, legacy apps) rather than MFA failure outright.
How Identity Attacks Overtake Exploits as Top Ransomware Cause works
Sophos' 2026 threat-intelligence portfolio — the State of Ransomware 2026 survey, the Active Adversary Report 2026, and the State of Identity Security 2026 report — collectively documents a structural shift in ransomware initial-access patterns away from vulnerability exploitation and toward identity compromise.
In the State of Ransomware 2026 survey (2,158 IT/cybersecurity leaders across 17 countries, all from organizations hit by ransomware in the prior 12 months), the top reported root causes were malicious email (26%, up from 19% in 2025), phishing (24%, up from 18%), and compromised credentials (23%), while exploited vulnerabilities fell to 18% (from 32% in 2025) and brute-force attacks accounted for 6%. Combined, these identity-adjacent vectors mean 79% of ransomware attacks now start with an identity-based approach. Attackers most often entered through exposed applications/systems (38%), user devices (30%), firewalls (21%), VPNs (8%), and IoT devices (3%).
Critically, 97% of victims whose root cause was compromised credentials had MFA deployed in some form at the time of attack — but coverage was uneven: SaaS applications were commonly protected while VPNs, firewall admin consoles, and legacy/on-prem applications frequently were not. Sophos CISO Ross McKerchar warned that AI-assisted reconnaissance will let attackers "enumerate identity misconfigurations far more cheaply and quickly than before," widening this gap further.
The Active Adversary Report 2026 (661 incident-response/MDR cases across 70 countries and 34 industries) found 67% of incidents traced to identity-related weaknesses and MFA absent in 59% of those cases. Once inside, attackers reached Active Directory in a median of 3.4 hours, with overall median dwell time falling to 3 days (down year-over-year, reflecting both faster attacker tradecraft and faster defender response). Payload deployment (88%) and data exfiltration (79%) both occurred predominantly outside business hours, an evasion pattern that exploits reduced SOC staffing and, increasingly, thinner log retention: the report noted missing-log incidents (often due to 7-day or 24-hour firewall log retention defaults) doubled year-over-year. Sophos tracked 51 distinct ransomware brands (27 returning, 24 new) — the highest number of active groups in the report's history — with Akira (tracked as GOLD SAHARA) involved in 22% of incidents and only LockBit, MedusaLocker, Phobos, and BitLocker-abuse operations persisting continuously since 2020.
The companion State of Identity Security 2026 report (5,000 IT/security leaders, 17 countries, 14 industries) found 71% of organizations suffered at least one identity-related breach in the past 12 months (averaging three per affected organization), with Switzerland (89%) and Mexico (83%) hit hardest and the energy/oil/gas sector most exposed (80%). 67% of ransomware victims tied their attack directly to their most significant identity compromise. A major and emerging root cause is weak non-human identity (NHI) management — API keys, service accounts, and AI agents, which can outnumber human identities by ratios as high as 100:1 — implicated in 41% of successful identity breaches; only 34% of organizations regularly audit or rotate NHIs, and just 11.1% do so continuously. Organizations with weak NHI management saw 22% higher likelihood of financial theft and 24.4% higher likelihood of extortion, and averaged $147,178 higher recovery costs. Average identity-breach remediation cost was $1.64 million (median $750,000), with 73% of victims spending $250,000+ per incident.
On outcomes, 56% of ransomware attacks still succeeded in encrypting data despite these defenses; 48% of victims with encrypted data paid a ransom (roughly flat against the four-year average of 50%). Median ransom demands fell 65% over two years to $698,000, and median payments fell to $769,000 from $1 million previously, with 51% of paying organizations negotiating below the initial demand — a trend Sophos attributes to greater victim sophistication and broader availability of decryptors/backups rather than reduced attacker capability. Recovery-cost averages nonetheless rose 11% year-over-year to $1.7 million per incident, and backup-based recovery rose to 66% of encrypted-data cases (up 12 points), while 55% of organizations recovered within one week and 16% within a day. Payment behavior varied sharply by sector and geography: local/state government victims paid at the highest rate (72%) versus retail's lowest (32%), and the UK recorded the highest median ransom demand globally at $2.5 million. Smaller organizations (100-250 employees) detected and stopped attacks pre-encryption only 34% of the time versus 46% for mid-large organizations (3,001-5,000 employees), and were roughly twice as likely to miss identity attacks entirely versus organizations with 1,000+ employees.
Taken together, the three reports describe a maturing ransomware economy that has shifted its center of gravity from patching-cycle vulnerability exploitation to identity-perimeter exploitation — credential theft, phishing, MFA-coverage gaps, and unmanaged non-human identities — while ransom economics simultaneously compress (lower demands/payments) even as recovery costs and group proliferation increase.
MITRE ATT&CK techniques used in TL-2026-1398
Collection
Lateral Movement
Defense Evasion
Initial Access
T1078 Valid Accounts; T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1566 Phishing
Discovery
T1087 Account Discovery; T1482 Domain Trust Discovery
Persistence
T1098 Account Manipulation; T1136 Create Account
Credential Access
T1110 Brute Force; T1552 Unsecured Credentials; T1556 Modify Authentication Process
Impact
T1486 Data Encrypted for Impact
Exfiltration
Affected products and versions in Identity Attacks Overtake Exploits as Top Ransomware Cause
- Cross-industry — Enterprise identity and access management (MFA deployment, VPN/firewall admin authentication, non-human identity/service-account management)
Vulnerable versions: Organizations with incomplete MFA coverage across VPNs, firewalls, and legacy apps; Organizations with unmanaged/unrotated non-human identities
Fixed in: N/A - organizational/process control gap, not a software version
Remediation for Identity Attacks Overtake Exploits as Top Ransomware Cause
Immediate actions
- Extend MFA enforcement to VPNs, firewall/network-device admin consoles, and legacy/on-prem applications, not just SaaS
- Increase firewall/edge-device log retention beyond the common 7-day/24-hour defaults to preserve identity-attack forensic evidence
- Inventory and rotate non-human identities (API keys, service accounts, AI-agent credentials) as a first-priority hardening step
- Monitor for after-hours authentication, lateral movement toward Active Directory, and mass data staging given the 88%/79% off-hours deployment/exfiltration pattern
Workarounds
- Where full MFA coverage cannot be immediately achieved, prioritize VPN and firewall/network admin-console MFA first, since these were the most common uncovered gaps behind credential-root-cause ransomware
Longer-term hardening
- Adopt Zero Trust identity architecture with continuous, not periodic (quarterly or less), login-anomaly and identity-governance review
- Establish continuous NHI auditing/rotation programs; organizations doing weekly-or-more NHI rotation and 34%+ regular auditing saw materially lower breach rates and costs
- Build immutable, tested, offline backup capability given 66% of encrypted-data recoveries now rely on backups over decryption/payment
- Right-size detection capability for small/mid organizations (100-1,000 employees), which detect and stop pre-encryption attacks at roughly half the rate of larger peers
Timeline of Identity Attacks Overtake Exploits as Top Ransomware Cause
- Sophos Incident Response and Managed Detection and Response teams begin the analysis window (through 2025-10-31) later published as the Active Adversary Report 2026, drawing on 661 IR/MDR cases across 70 countries and 34 industries out of 625,000+ organizations defended by Sophos.
- Sophos publishes the Active Adversary Report 2026 (lead author John Shier, Field CISO), finding 67% of 661 IR/MDR cases traced to identity-related weaknesses and MFA absent in 59% of those cases; Qilin (tracked as GOLD FEATHER) identified alongside Akira (GOLD SAHARA) as a named active ransomware brand.
- Help Net Security and Cybersecurity Insiders publish coverage of the Sophos identity-breach cost findings, highlighting the $1.64M average remediation cost and non-human-identity risk data.
- Sophos publishes the State of Identity Security 2026 report (5,000 respondents, 17 countries), finding 71% of organizations suffered at least one identity-related breach in the past 12 months.
- Sophos publishes the State of Ransomware 2026 report (2,158 respondents, 17 countries), finding 79% of ransomware attacks now begin with an identity-based approach and exploited-vulnerability root causes fell to 18% from 32% in 2025.
- GlobeNewswire/Manila Times syndicate the Sophos press release on the 79% identity-based ransomware finding to a broader business/news audience.
- Dark Reading publishes 'Identity Attacks Overtake Exploits as Top Ransomware Cause,' summarizing the Sophos State of Ransomware 2026 findings for a security-practitioner audience.
- TL-Intel Harness captures the Dark Reading coverage as an INFORMATIONAL/THREAT_INTEL trend record for downstream analysis rather than a standard exploit-driven pipeline.
Sources cited for Identity Attacks Overtake Exploits as Top Ransomware Cause
- Identity Attacks Overtake Exploits as Top Ransomware Cause
- The State of Ransomware 2026: Payments Drop as Encryption Climbs
- Sophos Active Adversary Report 2026: Identity attacks dominate as threat groups proliferate
- Sophos State of Identity Security 2026
- Over 70% of organizations hit by identity breaches
- Identity-Related Breach Hit 71% of Enterprises, Sophos Survey Finds
- 79% of Ransomware Attacks Now Originate from Compromised Identities, Sophos Report Finds
Threats related to Identity Attacks Overtake Exploits as Top Ransomware Cause
Detection coverage for TL-2026-1398
As of 2026-07-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1398 across Splunk SPL, Microsoft KQL and Sigma, covering 20 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.