MALAYSIA< 27 AUGUST 2026 – Global cybersecurity leader Sophos has released its seventh annual State of Ransomware report, uncovering a major shift in cybercriminal tactics. Based on an independent survey of 2,158 IT and cybersecurity decision-makers across 17 countries, the study shows that identity has become the dominant initial access vector, driving 79% of ransomware incidents.
For the first time in four years, software vulnerability exploitation lost its spot as the leading root cause of attacks. Instead, malicious email (26%) and phishing (24%) emerged as the top vectors. However, exploiting vulnerabilities remains a high-value tactic; 59% of ransom demands resulting from exploited firewall vulnerabilities exceeded $1 million, compared to 48% across all attack types.
Data encryption rates rose to 56%, reversing a two-year downward trend. Smaller organizations with 100 to 250 employees struggled the most, with only 34% stopping attacks before encryption or extortion took place, compared to 46% of larger organizations. Notably, 97% of incidents caused by compromised credentials had multi-factor authentication (MFA) deployed in some capacity, highlighting critical coverage gaps.
Ross McKerchar, Chief Information Security Officer at Sophos, warned that attackers are increasingly experimenting with AI to accelerate asset theft and exploit software flaws at scale. He emphasized that organizations must move beyond patching to reduce external exposure and maintain round-the-clock monitoring.
Despite rising attack complexity, organizational resilience has improved. Over half (55%) of affected businesses recovered within a week, backed by stronger backup infrastructure. Furthermore, 51% of victims who chose to pay successfully negotiated lower settlements, contributing to a 65% drop in median ransom demands over two years. The UK recorded the highest median ransom demand globally at $2.5 million.
Despite lower ransom payments, overall recovery costs continue to climb, averaging $1.7 million per incident. Sophos recommends treating identity as a foundational security layer, enforcing phishing-resistant MFA, maintaining rigorous exposure management, and integrating firewall telemetry with extended detection and response solutions.
