Stolen Account Credentials Are the New Key in Ransomware
A new report from Sophos reveals that 79% of ransomware attacks now begin with stolen or compromised user credentials, indicating a shift where attackers focus more on the human element than on security vulnerabilities.
What Happened
The dynamics in the world of cybersecurity are shifting. The once-favored tactic of ransomware attackers, exploiting software security vulnerabilities, has given way to a much simpler yet equally effective strategy: stolen user credentials. A new report published by cybersecurity firm Sophos on July 15, 2026, quantifies this alarming trend. Based on an analysis of real-world incidents, the report states that a staggering 79% of ransomware attacks are traced back to compromised identities and legitimate user logins.
This finding indicates that cybercriminals are now targeting the weakest link—the human—instead of grappling with complex code and system vulnerabilities. Obtaining a legitimate user's password to infiltrate a corporate network is often easier and more cost-effective than finding an unpatched server. This situation clearly necessitates that corporate cybersecurity strategies be reshaped to focus on identity and access management. This tactical shift by cyberattackers has visibly increased over the past year, compelling organizations to strengthen their defense mechanisms by considering human error and social engineering tactics.
How Did the Attack Happen
The Sophos report details how attackers obtain these compromised credentials and use them as their primary infiltration tool. Attacks are no longer based on a single method but are a combination of techniques targeting the human factor. This new-generation attack chain can easily bypass traditional defense lines.
Identity-Based Attacks: The New Norm (79%)
According to the report, in 79% of the analyzed ransomware cases, the initial point of entry was the abuse of credentials. This means an attacker uses a valid username and password to access the network. These credentials are obtained through various sub-methods. Once inside, attackers appear as legitimate users, often allowing them to move laterally within the network, conduct reconnaissance, and plan their attacks for extended periods without detection. This dramatically increases the impact and potential damage of the attack.
Phishing and Malicious Emails: Exploiting Human Weakness
One of the main sources of compromised credentials is email-based attacks. The report notes that in 26% of incidents, the initial entry point was malicious emails. This figure is a significant increase from 19% in 2025. These emails may contain phishing links that redirect users to fake websites to steal their login information or malicious attachments that download the ransomware onto the system.
Phishing attacks, in particular, stand out as the root cause of 24% of all incidents, a substantial rise from 18% in 2025. Attackers are now using AI-powered tools to craft highly convincing and personalized phishing emails, free of grammatical errors. This increases the risk of even the most well-trained users falling into the trap.
Brute Force Attacks: The Cost of Weak Passwords
Another common method employed by attackers is brute force attacks. This method was identified in 23% of the analyzed incidents, a figure very close to last year's 22%. In brute force attacks, automation software is used to guess a user's password by trying millions of possible combinations. Passwords that are weak, commonly used, or easily guessable (e.g., "123456", "password", "qwerty") are extremely vulnerable to these attacks. This method provides another effective way for attackers to obtain credentials.
Security Vulnerabilities: A Declining Vector
One of the most striking findings of the report is the dramatic decline in the exploitation of software security vulnerabilities. This method, once the most common cause of ransomware attacks, accounted for 32% of cases in 2025 but dropped to just 18% in 2026. This decline proves that attackers have shifted their focus. Increased corporate awareness of patch management and vulnerability scanning has pushed attackers towards easier targets: the users themselves. However, this does not mean that vulnerabilities are no longer a threat; it simply shows that attackers prefer paths of less resistance.
What Data Was Leaked
The Sophos report is a broad study analyzing global ransomware attack trends, not a specific data breach. Therefore, the report does not contain specific details about what types of data were stolen or encrypted as a result of the attacks. However, given the general nature of ransomware attacks, it is known that attackers target all types of critical data, such as financial records, customer information, personal identifiable information, and corporate trade secrets.
Who Was Affected
This report does not target specific companies or industries. Its findings were compiled from numerous real-world incidents across various sectors and geographies. Consequently, this trend of targeting credentials poses a valid threat to any network-connected organization, from small businesses to large corporations, and from public institutions to healthcare providers. Any organization with weak passwords or untrained staff is a potential target.
What You Can Do
In this new threat landscape, there are measures that both individuals and organizations must take. Defense strategies must center on the human factor in addition to technological controls.
- Strong and Unique Passwords: Use different, complex, and long passwords for each account. Password managers can help with this. This is the most basic defense against brute force attacks.
- Multi-Factor Authentication (MFA): Enable MFA wherever possible. This provides an additional layer of security that prevents an attacker from accessing your account even if your password is stolen.
- User Training: Regularly train your staff on phishing attacks and social engineering tactics. Foster a culture of awareness for recognizing and reporting suspicious emails.
- Access Control: Adopt the principle of "least privilege." Ensure that each user has only the minimum permissions necessary to do their job. This limits an attacker's ability to move within the network if an account is compromised.
- Patch Management: Although vulnerability exploitation has decreased, it is still a threat. Protect against known vulnerabilities by regularly updating all your systems and software.
- Breach Monitoring: You can use a Data Breach Search tool to find out if your information has been exposed in past data breaches. Stolen credentials are often sold on the dark web and used in these types of attacks.
You can stay informed about the latest threats by following our Data Breach News page for the latest developments in the cybersecurity world.
What the Company Says
Sophos CISO Ross McKerchar highlighted this shift when discussing the report's findings with Infosecurity Magazine. "Over the last 12 months across the ransomware landscape we’ve seen attackers rely on ‘easier’ attacks, using compromised identities as the primary initial access vector," McKerchar said. This statement shows that attackers are shifting their efforts from highly technical vulnerability exploitation to the more predictable and repeatable hunt for human targets.
McKerchar also pointed to developments in social engineering: "Not to mention the developments in social engineering, with AI routinely deployed to polish phishing emails and sophisticated ClickFix campaigns designed to trick even the most trained users into bypassing MFA. This year's trend shows they are focused on targeting humans." This comment emphasizes that the threat is not only technological but also psychological, and that defense mechanisms must be prepared for this new generation of intelligent and persuasive attacks.
Source
https://www.infosecurity-magazine.com/news/compromised-logins-ransomware-entry/
This content was generated with AI assistance through our Argus Flow application. We are continuously working to improve Argus Flow; if you encounter any issues such as translation errors, incorrect sources, or unverified information, you can report them using the button below. We appreciate your feedback.