Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Alomairi’s bronze delivers Saudi Arabia’s first fencing world championship medal

    July 28, 2026

    Municipalities Ministry issues over 34,000 building permits in first half of 2026

    July 28, 2026

    Saudi Arabia intercepts drones targeting oil facilities, blames Iran-backed militias in Iraq

    July 28, 2026
    Facebook X (Twitter) Instagram
    Riyadh Week
    • Home
    • KSA
    • Business
    • Technology
    • Sports
    • Lifestyle
    Facebook X (Twitter) Instagram YouTube
    Riyadh Week
    Home»Technology»79% of ransomware attacks now originate from compromised identities, says Sophos
    Technology

    79% of ransomware attacks now originate from compromised identities, says Sophos

    Editorial TeamBy Editorial TeamJuly 21, 2026
    Share Facebook Twitter Pinterest Copy Link LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email Copy Link

    Ross McKerchar, chief information security officer, Sophos.

    Exploited vulnerabilities are no longer the primary root cause of ransomware attacks, as cybercriminals prioritise malicious emails and phishing campaigns 

    Dubai — Sophos, a global cybersecurity leader, today released its seventh annual State of Ransomware report, a vendor-agnostic survey of IT and cybersecurity leaders across 17 countries including the UAE, identifying the impact of ransomware on businesses and how prepared organisations are to defend against them. This year’s report reveals that globally identity is the dominant initial access vector (IAV), with four in five (79%) of ransomware attacks starting with compromised identities. In the UAE, organisations that suffered ransomware attacks reported an average recovery cost of US$665,000, highlighting the significant financial impact of these incidents on businesses. 

     The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognise identity as a key component in ransomware delivery. Additionally, for the first time in four years, exploited vulnerabilities are no longer the most common root cause, with malicious email (26%) and phishing (24%) taking the top spot.  

     However, exploited vulnerabilities remain a high value target: 59% of ransom demands that start with an exploited vulnerability on the firewall are for $1M or more compared to 48% of all attacks. 

     “As we see ransomware criminals experiment with AI, it has the potential to accelerate their ability to steal valuable assets, hold them hostage and do it at a scale that exceeds their previous capability,” said Ross McKerchar, chief information security officer, Sophos.

    “This speed requires careful round-the-clock monitoring of the most exploited means of entry, which our data shows to be stolen and compromised valid accounts. However, the improvement of unguarded open-weight AI models will give attackers a growing advantage in finding and exploiting software vulnerabilities. Defenders cannot rely on patching alone to keep pace, so reducing external exposure and maintaining strong endpoint protection is essential.” 

     The report also found that, out of the organisations hit by ransomware, 56% had their data encrypted, an increase which has reversed a two-year downward trend.  

     Additional global findings highlight:  

    • Two-thirds of ransomware victims (67%) confirmed their ransomware incident was also their most significant identity attack, establishing identity compromise as a primary ransomware delivery mechanism. 
    • Over half of ransomware attacks (56%) succeeded in encrypting data, including 16% where data was both encrypted and stolen. That success rate is up from 50% in 2025, but below the 75% peak in 2023. In comparison, 38% of ransomware attacks in the UAE resulted in data encryption, including 13% where data was both encrypted and stolen. 
    • When data is encrypted, attackers have a 50-50 chance of receiving a ransom payment. 48% of organisations whose data was encrypted paid the ransom, bringing the four-year average payment rate to 50%. 
    • Only 34% of small organisations (100–250 employees) stopped attacks before encryption or extortion. This is significantly behind 3,001–5,000 employee organisations that stopped attacks 46% of the time. 
    • Multi-factor authentication (MFA) was deployed in some capacity for 97% of incidents where compromised credentials were the root cause of the ransomware attacks, making clear that MFA alone is not enough to stop ransomware, and that coverage gaps create exposure. 
    • The UK saw the highest median ransom demand recorded for any country at $2.5 million. 

     While organisations face prevention challenges as threat actors evolve their techniques, significant progress has been made to improve their ability to recover. Increased investment in backup infrastructure has likely contributed to organisations recovering faster following a ransomware attack; over half (55%) of organisations manage to do so within one week, and 16% in less than a day.  

     Organisations are continuing to be effective at negotiating with ransomware operators. Among those that chose to pay, 51% successfully negotiated a settlement below the attackers’ initial ransom demand. The median ransom demands made by attackers have dropped by 65% over the last two years, and the proportion of organisations paying the ransom to recover data has fallen to 48%, the second-lowest rate on record after 2023 (46%). 

     While improved strategies have impacted the adversary’s ability to extract financial gain through ransom demands, the average recovery costs following an attack has increased, now at $1.7 million per incident. 

     “Organisations have strengthened their ransomware resilience in the past year, and those investments are largely paying off,” said McKerchar at Sophos.

    “However, ransomware continues to cost organisations millions. As AI becomes more capable, attackers will be able to enumerate identity misconfigurations and weak points across organisations far more cheaply and quickly than before. Organisations can no longer rely on complexity or obscurity to hide gaps in their environment. The same technology also gives defenders an opportunity to find and fix those gaps faster, but only if prevention, detection, and response work together as part of a unified cybersecurity strategy.” 

     Sophos recommends the following best practices to help organisations build integrated, AI-driven defenses that bring together technology, people and processes: 

    • Treat identity as a foundational security layer – Organisations should prioritise ITDR, enforce phishing-resistant multi-factor authentication across all access points, and regularly audit both human and non-human identities. 
    • Invest in backup and recovery infrastructure – Backups should be tested regularly, stored offline or in immutable formats, and integrated into a documented incident response plan that can be executed under pressure. 
    • Maintain exposure management programs – Organisations should maintain rigorous patching schedules, prioritise internet-facing assets, and consider how emerging AI-assisted tools can accelerate vulnerability identification and remediation. 
    • Reduce exposure via the firewall and leverage firewall telemetry to detect attacks early. Ensure your firewall receives rapid – ideally automated – updates and minimise internet-facing services like admin access and user portals. Connect firewalls to XDR and MDR solutions to enable firewall telemetry to help detect ransomware attacks before payloads are deployed.  

     This survey was conducted by Vanson Bourne on behalf of Sophos in Q1 2026. 2,158 IT and cybersecurity decision-makers from organisations that had been hit by ransomware in the previous 12 months were interviewed across 17 countries: USA, Brazil, Chile, Colombia, Mexico, UK, France, Germany, Italy, Spain, Switzerland, Australia, India, Japan, Singapore, South Africa, and UAE. Respondents came from organisations with 100 to 5,000 employees across 15 industry sectors. 


    Source: Tahawul Tech

    Related Posts

    Meta debuts a standalone sellers app

    July 27, 2026

    Optro overhauls partner programme with tiered, AI-driven model, says Scott Whitlock

    July 27, 2026

    HONOR X7e Plus 5G: Big battery, rugged build and AI tools at accessible price

    July 27, 2026
    Top Posts

    Alomairi’s bronze delivers Saudi Arabia’s first fencing world championship medal

    July 28, 2026

    QBS Software Middle East embeds AI into core operations

    April 1, 2026

    Bosnia’s Barbarez cool as ice after reaching World Cup in shootout with Italy

    April 1, 2026

    Kuwaiti tanker hit by Iranian drone attack in Dubai waters

    April 1, 2026
    Don't Miss

    Alomairi’s bronze delivers Saudi Arabia’s first fencing world championship medal

    By Editorial TeamJuly 28, 2026

    HONG KONG — Saudi fencer Khalifah Alomairi won the bronze medal in the Senior Men’s…

    Municipalities Ministry issues over 34,000 building permits in first half of 2026

    July 28, 2026

    Saudi Arabia intercepts drones targeting oil facilities, blames Iran-backed militias in Iraq

    July 28, 2026

    “Al Rashid Properties”: Integrated communities shape the future of urban development in Saudi Arabia

    July 28, 2026
    • KSA
    • Business
    • Technology
    • Lifestyle
    • Sports
    • Contact us
    2026. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.