Compromised credentials have become the most common way worldwide for ransomware attackers to compromise an organisation’s systems, displacing software vulnerabilities for the first time in four years, according to 2025 figures from Sophos.
The study, carried out by Vanson Bourne in the first quarter of this year, found that 79 percent of ransomware accounts began with compromised user logins, with 24 percent involving phishing attacks and 2 percent involving malicious emails.
The attacks succeeded in spite of nearly all of the organisations affected – 97 percent – having some form of multi-factor authentication in place.
Image credit: Unsplash
Identity compromise










