# Identity Attacks Overtake Exploits as Top Ransomware Cause—and MFA Isn't Stopping Them
Ransomware attackers have fundamentally changed their playbook. According to Sophos' latest State of Ransomware 2026 report, identity compromise has dethroned software vulnerabilities as the primary delivery mechanism for ransomware attacks, marking a significant shift in threat tactics that organizations are struggling to counter—especially despite widespread multifactor authentication (MFA) deployment.
## The Shift: Email and Phishing Dominate
The data reveals a striking transformation in how ransomware breaches begin. Email and phishing attacks now account for 50% of all ransomware root causes, with malicious email representing 26% of incidents and phishing 24%. This is a dramatic reversal from the conventional wisdom of the past three years, where unpatched software vulnerabilities dominated the ransomware landscape.
Vulnerability exploitation has plummeted from 32% three years ago to just 18% in 2026—a development that, on its surface, appears to reflect improved patching discipline across the industry. The reality, however, is more troubling: attackers have simply abandoned technical exploitation in favor of easier, more reliable human-centric approaches.
Compromised credentials, the third most common ransomware root cause at 23% of incidents, round out the identity-focused attack vector trifecta. Together, identity-based attacks account for roughly 73% of ransomware deliveries.
## Background and Context: The Cost-Benefit Analysis of Modern Attacks
Understanding this shift requires examining the economics of cybercriminal operations. Identifying and exploiting zero-day vulnerabilities or even patched-but-uninstalled flaws is expensive and unreliable—it requires research, tool development, and faces the constant risk of detection or patch deployment.
Social engineering, by contrast, scales efficiently. A single phishing campaign can reach thousands of employees in a single organization or across multiple targets, often requiring nothing more than a convincing email, stolen credentials from past breaches, or a credential-stuffing attack against password-reuse victims.
The Sophos survey included 2,158 IT and cybersecurity leaders across 17 countries, all representing organizations that suffered ransomware attacks over the past year. The breadth of data offers a rare window into how attackers actually breach networks—not in lab environments or proof-of-concept scenarios, but in real-world attacks against defended networks.
Notably, 67% of ransomware victims reported that the attack they suffered was their most significant identity attack over the past year, indicating that ransomware has become so deeply intertwined with identity compromise that the two are now virtually inseparable.
## Technical Details: The MFA Paradox
One finding stands out as particularly alarming: Multifactor authentication was deployed in 97% of the cases where compromised credentials were the root cause of ransomware attacks.
This statistic inverts the conventional narrative about MFA's effectiveness. MFA is widely promoted as the single most important defense against credential theft. Yet in this survey, it failed to prevent compromise in the vast majority of cases.
The mechanisms attackers encountered were varied:
| Authentication Method | Prevalence |
|---|---|
| One-Time Passwords (OTP) | Most common |
| Push-based applications | Second most common |
| Passkeys | Third most common |
| FIDO2 tokens | Fourth most common |
FIDO2 tokens represent the gold standard for phishing-resistant authentication—they cannot be fooled by fake login pages or man-in-the-middle attacks. Yet even these account for only a fourth of secondary authentication methods deployed, suggesting that most organizations have adopted more vulnerable MFA variants.
The implication is clear: attackers have developed effective workarounds for traditional MFA. Common tactics include:
## Implications for Organizations
This shift fundamentally challenges how organizations should approach ransomware defense. For years, the security community has emphasized patch management and vulnerability remediation as the cornerstone of ransomware prevention. Sophos' data suggests this approach is incomplete—and increasingly irrelevant against the current threat landscape.
The statistics indicate that:
Organizations cannot simply rely on MFA as a ransomware prevention tool. The technology alone is insufficient. The problem compounds when considering that many organizations deploy lower-assurance MFA methods (OTP and push notifications) rather than phishing-resistant approaches like FIDO2 or passwordless authentication.
## Recommendations: Layered Identity Defense
Sophos' recommendations provide a practical starting point, though organizations should consider them table stakes rather than comprehensive strategy:
Immediate Actions:
Medium-Term Improvements:
Strategic Shifts:
---
## HackWire Analysis
The uncomfortable truth: We've been winning the wrong battle. For three years, the security industry has celebrated record patching rates and vulnerability disclosure programs as if they were the antidote to ransomware. Sophos' data demolishes that narrative. Exploits have become a rounding error in ransomware attacks—a victim of their own success as a defense strategy.
What's actually happened is a wholesale market correction among attackers. Why spend months researching a zero-day vulnerability when you can rent a phishing kit, buy a list of credentials from the dark web, or simply call an employee pretending to be IT support? The attackers who dominate the ransomware ecosystem are rational economic actors; they follow the path of least resistance.
The MFA finding is the real story buried in this data. 97% deployment with high failure rates means that MFA has become security theater in most organizations. The industry has conflated "MFA adoption" with "MFA effectiveness," and attackers have exploited that conflation ruthlessly. Organizations deployed OTP and push notifications—the least phishing-resistant mechanisms—at scale, creating a false sense of security while leaving the door wide open to sophisticated adversaries.
This report suggests that 2026 represents an inflection point where traditional approaches to ransomware defense have reached the limits of their utility. Patching and MFA are no longer differentiators; they're baseline hygiene. Organizations that assume these controls are sufficient will be breached. Those that layer identity security with detection, response, and behavioral analytics—and that ruthlessly prioritize phishing-resistant authentication—will find themselves far less vulnerable.
The other implication: ransomware is no longer primarily a technical problem. It's a human-centered problem. Training, process discipline, and identity governance matter far more now than zero-day response times or patch deployment speeds. Organizations that still treat cybersecurity as primarily an IT problem rather than an organizational discipline will suffer accordingly.
— HackWire Editorial
---
## Related Coverage