Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.

July 15, 2026

So long, vulnerability exploitation — identity has become the dominant root cause of ransomware, according to a recent survey.

Sophos today published its State of Ransomware 2026 report, covering a survey Sophos conducted with 2,158 IT and cybersecurity leaders across 17 countries who worked in organizations hit by ransomware over the past year. While there are a number of fascinating findings — 56% of ransomware attacks successfully pulled off encryption against victim networks, ransom demands and payments are down — some of the most interesting data involves identity and the ways attackers are getting in.

Namely, identity compromise is the primary ransomware delivery mechanism.