Threat feed liveUpdated — 03.08.2026 08:58 CET79 dossiersMITRE ATT&CK mappingThreat feed liveUpdated — 03.08.2026 08:58 CET79 dossiersMITRE ATT&CK mapping

An independent survey of the ransomware ecosystem, not of a specific grouphigh

Ransomware no longer comes through holes: it comes through accounts, in four cases out of five

The seventh edition of Sophos's annual ransomware survey, run by Vanson Bourne across 2,158 IT and security leaders in 17 countries, shifts the centre of gravity of the problem. 79% of attacks start from a compromised identity; vulnerability exploitation as the initial technical cause falls to 18%. Malicious email (26%) and phishing (24%) together explain half of all incidents, with compromised credentials a further 23%. Ransoms are falling — median demand USD 698,000, median payment USD 769,000 — while the average recovery cost climbs to USD 1.7 million. It is a self-reported survey, and should be read knowing that.

The number that changes priorities

For years the conversation about ransomware had an implicit shape: there is a hole, somebody finds it, they get in. Everything else followed from that — the race to patch, the CVSS score as a measure of urgency, the idea that the attack surface was a list of software to keep updated.

The seventh edition of Sophos's annual ransomware survey describes a different ecosystem. According to the data collected, 79% of ransomware attacks originate from a compromised identity, while vulnerability exploitation as the initial technical cause falls to 18%.

This is not news that makes patching pointless. It is news about where the marginal effort should go, which is a different and more useful question.

79%
attacks from a compromised identity
the most common starting point, per the survey
18%
vulnerability exploitation
as initial technical cause
USD 1.7m
average recovery cost
ransom excluded

How the survey was built, before the numbers

This comes first, not last, because it changes the weight of everything else.

The survey was run by Vanson Bourne on behalf of Sophos in Q1 2026 — answers gathered between January and March, covering the previous twelve months. Participants number 2,158 IT and security directors, senior managers and board members across 17 countries: the United States, Brazil, Chile, Colombia, Mexico, the United Kingdom, France, Germany, Italy, Spain, Switzerland, Australia, India, Japan, Singapore, South Africa and the UAE. Organisations range from 100 to 5,000 employees, a band that has stayed proportionally stable across the survey's seven-year history.

From this follow the limits, which are real and worth holding in mind while reading the percentages.

It is self-reported, not telemetry. Respondents report what they know or believe about the initial cause of their own incident. Anyone who suffered an attack without a full forensic investigation attributes the root cause as best they can.

The size band excludes both extremes. Below 100 employees and above 5,000 the picture might differ, and for Italian micro-enterprises — the bulk of the country's productive fabric — these numbers do not transfer automatically.

It is a vendor publishing into its own market. The survey describes itself as independent and vendor-agnostic, and is conducted by a third-party research firm; it remains true that whoever commissions it sells security. That is not a reason to discard it — the methodology is disclosed, which is more than many reports offer — but it is a reason to read it alongside other sources rather than on its own.

Entry routes, in order

The individual reported vectors compose a picture consistent with the headline:

  1. 01
    Malicious email
    26% of incidents
  2. 02
    Phishing
    24% of incidents
  3. 03
    Compromised credentials
    23% of incidents
  4. 04
    Vulnerability exploitation
    18% as initial technical cause

Malicious email and phishing together explain half of all incidents. They are adjacent but not identical categories: the first covers the attachment or link that leads to execution, the second the deception aimed at getting something handed over — typically credentials.

The 23% for compromised credentials deserves attention because there is not even a deception involved: the credentials were already circulating. Bought, reused from an earlier breach, harvested by an infostealer on a personal laptop.

Adding up: most entries come through something that looks like a legitimate login. Which is why the headline 79% does not contradict the individual vectors — it summarises them.

And this changes the detection problem substantially. An exploit makes noise: an anomalous request, a process spawning where it should not, a crash. A correct login does not. It arrives with the right password, often clears a second factor too if that factor is a code or a prompt to approve, and from the system's point of view it is indistinguishable from everyday work. What remains as a signal is no longer "this should not have happened" but "this is odd for this user": an unusual hour, a new location, access to data that person never touches.

The money moves the other way

USD 698,000
median demand
falling
USD 769,000
median payment
when payment happens
56%
attacks reaching encryption
rising

The counterintuitive finding of this edition is that ransoms are falling while total cost is rising. The median demand sits at USD 698,000 and the median payment at USD 769,000, while the average recovery cost — a separate line, and one that excludes the ransom — reaches USD 1.7 million. In parallel, the share of attacks that actually reach encryption rises to 56%.

If both movements are real, the simplest reading is that demands are adjusting downwards to raise the probability of being paid, while the operational damage — downtime, rebuilding, overtime, consultants, litigation — stays independent of the sum asked. The ransom is the line everyone talks about; it is not the line that weighs most.

It should be said that this is an interpretation, not a claim made by the survey. The correlation between the two movements is visible in the numbers; the cause is not.

What follows, concretely

Treat identity the way the perimeter was treated. If four attacks in five start from a login, the inventory that matters is not only the server list: it is the account list. How many exist, how many belong to people who no longer work here, how many are service accounts with passwords nobody ever rotated, how many carry privileges nobody ever reviewed.

Prefer factors that phishing cannot relay. A six-digit code and a push prompt beat a password alone, but both can be handed to an attacker by a person convinced they are doing the right thing. Hardware keys and domain-bound passkeys cannot, because the factor is tied to the real site.

Watch the session, not just the login. Many modern attacks do not steal the password: they steal the already-authenticated session token. The useful control is not at the gate, it is after it: where is this session coming from, how long does it last, does it cross continents mid-morning.

Do not stop patching. 18% is still 18%, and actively exploited CVEs on edge devices remain one of the fastest routes into a network. The point is not to move attention: it is to add it where there was none.

Rehearse recovery, do not just perform it. If the average recovery cost is what it is, the variable you can actually move is how fast you get back to work. An untested backup is a hope, not a control.

The point

For a decade defence organised itself around the idea of closing entrances. The most-used entrance today, if these numbers hold, cannot be closed: it is used, and whoever uses it holds the right keys.

Which moves the question from how do I stop them getting in to how long does it take me to notice that whoever got in is not who they claim to be. A more uncomfortable question, because no patch resolves it.

More dossiers