Identity Is Now the Top Ransomware Cause. Your Budget Probably Isn’t.
- Jul 21
- 6 min read

By Yonatan Hoorizadeh, CISSP, CISM, CRISC, AAISM
Published By: Purple Shield Security
Published: July 21, 2026
The short version: Identity-based attacks have overtaken software vulnerabilities as the leading cause of ransomware, according to Sophos. Malicious email (26%) and phishing (24%) now top the list, while exploited vulnerabilities fell to 18%. Yet most security budgets still center on patching. That gap is the real exposure.
For four straight years, the honest answer to “how do ransomware crews get in?” was: they exploit an unpatched system. Security teams built their calendars, their tooling, and their spending around that answer. This month, Sophos published data that quietly retires it.
What did the Sophos report actually find?
The Sophos State of Ransomware 2026 report found that 79% of ransomware attacks now begin with a compromised identity, and for the first time in four years, exploited vulnerabilities are no longer the top root cause. Malicious email accounted for 26% of attacks and phishing for 24%, while vulnerability exploitation fell to 18%, down from 32% the year before.
The report is worth trusting on the numbers because of how it was built. Sophos commissioned Vanson Bourne to survey 2,158 IT and cybersecurity decision-makers across 17 countries in the first quarter of 2026, all from organizations that had actually been hit by ransomware in the prior 12 months. Respondents came from companies with 100 to 5,000 employees. This is not vendor telemetry from one product line. It is a vendor-agnostic survey of victims.
One finding stands out for anyone who has sat in an incident response call: two-thirds of victims (67%) said the ransomware attack was also their single most significant identity attack of the year. Identity compromise was not a side door. It was the main event.
Why does this break the way most companies budget for security?
Because most security budgets were built to win the last fight. Vulnerability management, patch cycles, and firewall hardening still absorb the largest share of many mid-market security programs. Those controls address the 18% root cause that is shrinking, not the 50% that malicious email and phishing now represent together. The spending map and the threat map have quietly drifted apart.
This is the part the news coverage mostly isn’t saying. When a threat vector reorders itself this sharply, the reflex is to add a new tool. The harder question for a CFO is where the existing dollars are pointed. If a company spends heavily on patching and edge-device scanning but has never funded identity monitoring, credential hygiene, or a real look at where MFA is bypassed, its budget is defending a door attackers are increasingly walking past.
That is not an argument to stop patching. Vulnerabilities are still the expensive door: Sophos found that 59% of ransom demands starting with an exploited firewall vulnerability were for $1 million or more, versus 48% across all attacks. The exploit path is lower volume but higher severity. The point is that a program funded almost entirely against exploits is now mismatched against how most attacks actually start.
This is where vCISO services earn their keep. The job is not to buy the newest identity product. It is to look at where the money already goes, compare it against how attacks are actually landing, and move spend to close the widest gap first. A good virtual CISO reads the budget like a portfolio, not a shopping list. For most mid-market firms right now, the underweight position is identity.
Why didn’t MFA stop these attacks?
Because MFA was already there and attackers got in anyway. The most uncomfortable number in the report: multi-factor authentication was deployed in some capacity for 97% of the incidents where compromised credentials were the root cause. MFA is necessary. The data shows it is not, by itself, sufficient.
The reasons are well understood by anyone who runs identity defense. Attackers wear down users with repeated push prompts until someone approves one. Legacy protocols and misconfigured apps quietly skip the second factor. Session tokens get stolen after authentication, so the attacker never faces the MFA prompt at all. “We have MFA” and “our identity layer is defensible” are two different statements, and the gap between them is where these attacks live.
Sophos CISO Ross McKerchar framed the underlying shift plainly: “Over the last 12 months across the ransomware landscape we’ve seen attackers rely on ‘easier’ attacks, using compromised identities as the primary initial access vector.” Logging in is easier than breaking in, and the data now reflects that.
What should a business do?
Start by comparing your security spend against how attacks are actually starting, then close the identity gap you find. The goal for this week is not a new platform purchase. It is an honest inventory and two or three concrete moves that a mid-market team can execute without a six-figure project.
Map your MFA coverage for real. Not “is MFA on,” but where it is bypassed: legacy authentication protocols, service accounts, third-party app logins, and VPN paths that skip the second factor. The 97% figure means coverage gaps, not absence, are the problem.
Move a phishing-resistant method to your highest risk accounts. FIDO2 security keys and passkeys defeat the push-fatigue and token-theft tricks that ordinary MFA does not. Admins, finance, and executives first.
Watch for identity abuse, not just malware. Impossible-travel logins, mass push requests, and new mailbox rules are the early signals of a credential-driven intrusion. Someone or something needs to be looking at them.
Re-point part of the budget. If your program spends heavily on exploit defense and almost nothing on identity monitoring, that ratio no longer matches the threat. Reallocation, not just addition, is the move.
Smaller organizations have the least room for error here. Sophos found that only 34% of companies with 100 to 250 employees stopped an attack before encryption or extortion, compared with 46% of firms in the 3,001 to 5,000 range. Fewer people watching identity signals means attacks run longer before anyone notices.
Frequently asked questions
Does this mean patching no longer matters?
No. Patching still matters, and the exploit path is more expensive when it hits: Sophos found 59% of ransom demands starting with an exploited firewall vulnerability were for $1 million or more. The shift is one of proportion. Exploits are now the lower-volume, higher-severity path, while identity is the high-volume path most programs underfund. Keep patching. Fund identity too.
We already have MFA everywhere. Are we covered?
Probably less than you think. MFA was deployed in 97% of the credential-based incidents Sophos studied, and attackers still got in through push fatigue, legacy protocols that bypass the second factor, and stolen session tokens. “MFA is on” is a starting point, not a finish line. The real question is where your MFA is bypassable, which is a coverage audit, not a checkbox.
We are a 60-person company. Where do we start?
Start with an MFA coverage audit and a phishing-resistant method (FIDO2 keys or passkeys) for your admin, finance, and executive accounts. Smaller firms are the most exposed here: only 34% of companies with 100 to 250 employees in the Sophos data stopped an attack before encryption. If you have no one watching identity signals day to day, that monitoring gap is the first thing to close, and it is exactly the kind of work fractional CISO services exist to cover without the cost of a full-time hire.
How is identity budget different from what we already spend?
Most existing security budgets fund exploit defense: patching, vulnerability scanning, firewall hardening. Identity budget funds a different set of controls: credential monitoring, phishing-resistant MFA, identity threat detection, and audits of where authentication is bypassed. Many mid-market programs spend heavily on the first category and almost nothing on the second, which is exactly the mismatch this report exposes.
The report is a prompt to check one thing: does your security spend still match how attacks actually start? If your program was built to fight exploits and your identity layer has never had a hard look, that is worth an outside set of eyes. Purple Shield Security provides vCISO services and fractional CISO services to small, mid-market, and regulated firms as an independent, vendor neutral advisor. No products to sell, no tool to push. If you want a candid read on whether your budget matches your real risk, that is a conversation worth having.



