Identity Attacks Overtake Exploits as Top Ransomware Cause
ID: 2d1d013e-fd12-58b1-9312-e4e220b8d3f7
STIX ID: report--2d1d013e-fd12-58b1-9312-e4e220b8d3f7
Feed Name: CosmicBytez Labs
**Sophos Active Adversary / State of Ransomware 2026:** Analysis of 661 IR/MDR cases shows ransomware has shifted to identity-first attacks—79% of incidents involve compromised identities and 50% of initial access comes from email/phishing—while MFA is frequently bypassed via AitM kits, MFA fatigue, token theft and social engineering; attackers operate rapidly (median 3 days to deploy ransomware, 3.4 hours to reach AD) and 51 ransomware families were active during the study. Recommended defenses include deploying phishing-resistant MFA (FIDO2/passkeys), Identity Threat Detection and Response (ITDR), auditing non-human identities, reducing internet-facing identity exposure, extended log retention, and continuous monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
