< Back to all clusters
[TECHNOLOGY] · United States, Canada, Germany, United Kingdom, France · 8 sources

Ransomware attacks pivot to compromised identities in 2026

Sophos’ 2026 State of Ransomware report shows that 79 % of ransomware incidents now begin with stolen or compromised credentials, overtaking exploited vulnerabilities as the leading entry vector. Malicious email and phishing campaigns account for 50 % of all attacks, while vulnerabilities fell to 18 % of incidents. Although multi‑factor authentication (MFA) is present in 97 % of credential‑based cases, gaps in its coverage still allow attackers to succeed.

Average ransom demands have fallen, but recovery costs remain high – the mean post‑attack restoration expense is about $1.7 million, with small organisations (100‑250 staff) least able to prevent encryption. The UK recorded the highest median ransom demand at $2.5 million.

TrendAI’s Cyber Risk Report 2026 places Italy and Brazil among the world’s ten most‑affected nations for ransomware violations, with Italy ranking seventh (243 incidents) and Brazil entering the top‑ten for the first time (207 incidents). The report also notes a 236 % surge in confirmed ransomware violations globally.

Security researchers at ReliaQuest identified two new large‑scale phishing kits, “Jalisco” and “OmegaLord”, targeting Microsoft 365 accounts. Both exploit MFA weaknesses – Jalisco abuses Microsoft’s Device Code flow, while OmegaLord harvests phone numbers to intercept SMS codes. Once access is gained, attackers move laterally within six minutes, stealing data from services such as SharePoint.