Compromised Credentials Now the Leading Entry Point for Ransomware, Sophos Research Finds

Identity-based attacks have overtaken software vulnerabilities as the primary method ransomware actors use to gain initial access.

AI-generated illustration depicting incident for the story: Compromised Credentials Now the Leading Entry Point for Ransomware, Sophos Research Finds

Identity-based attacks have overtaken software vulnerabilities as the primary method ransomware actors use to gain initial access.

Summary

  • Sophos incident research shows compromised logins have surpassed software exploits as the top ransomware entry point.
  • Phishing, brute force attacks, and other identity-based techniques are the dominant delivery mechanisms.
  • The shift signals that perimeter patching alone is no longer sufficient as a primary defence posture.
  • Credential hygiene, multi-factor authentication, and identity monitoring are now front-line ransomware controls.
  • CISOs should reassess whether their ransomware risk models still weight vulnerability management above identity security.

The Attack Surface Has Shifted

For years, the dominant ransomware narrative centred on unpatched systems — a known vulnerability left exposed long enough for a threat actor to exploit it. New research from Sophos, drawn from real-world incident investigations, challenges that framing. Compromised credentials have now overtaken software vulnerabilities as the most common means by which ransomware operators gain their initial foothold.

What the Data Shows

Sophos found that identity-based threats — including phishing, brute force attacks, and other techniques targeting login credentials — are now the primary entry vector across ransomware incidents the firm investigated. The finding represents a meaningful shift in how adversaries are choosing to begin their attacks, and it has direct implications for how organisations should be allocating their defensive resources.

Why Credentials Are an Attractive Target

The logic for attackers is straightforward. A valid set of credentials allows an adversary to walk through the front door rather than pick the lock. Once inside, they can operate with the appearance of a legitimate user, which complicates detection and extends the window of dwell time before any alert is triggered. Phishing campaigns and brute force tools are also relatively low-cost to operate at scale, making credential theft an efficient first step for ransomware groups.

Brute Force Remains a Persistent Problem

Brute force attacks, in particular, continue to be a viable technique precisely because many organisations still expose remote access services — such as RDP — to the internet without adequate controls. When an account lacks multi-factor authentication or uses a weak or previously breached password, brute force becomes less a sophisticated attack and more a matter of patience and automation. The Sophos findings suggest this remains a meaningful proportion of successful intrusions.

Phishing Keeps Evolving

Phishing is not a new threat, but its persistence at the top of the initial access charts reflects how consistently it works. Credential-harvesting phishing — where users are directed to convincing login pages designed to capture their usernames and passwords — has become increasingly targeted and polished. The volume of phishing attempts, combined with the inevitable rate of human error, means even organisations with solid security awareness programmes are not immune.

Implications for Security Architecture

The shift from vulnerability-led to identity-led initial access does not mean patching becomes less important — unpatched systems remain a serious risk and opportunistic actors will continue to exploit them. However, it does suggest that organisations whose ransomware defences are weighted heavily toward vulnerability management may be under-investing in identity security controls. Detection logic, access policies, and monitoring programmes that were designed around an exploit-first model may need recalibration.

A Note on Source Limitations

The Sophos research is based on incidents the firm investigated directly, which may skew toward organisations of a particular size, sector, or geography depending on Sophos’s customer base. No corroborating research was available at the time of publication. The directional finding — that credential compromise is leading over vulnerability exploitation — is consistent with broader industry observations, but CISOs should weigh it accordingly and consider how representative it is of their own threat environment.

Why it matters

Ransomware response programmes built on a vulnerability-first model are increasingly misaligned with how attacks actually begin. If the majority of ransomware intrusions now start with a stolen or guessed login, then controls such as MFA coverage, password policy enforcement, exposed service reduction, and credential monitoring are no longer complementary measures — they are primary defences. CISOs should be asking their teams whether current detection capabilities would catch a threat actor operating with valid credentials, and whether identity-related risks feature prominently enough in ransomware tabletop exercises and board-level risk reporting.

What to do now

  • Audit MFA coverage across all remote access services, privileged accounts, and externally facing applications, prioritising any gaps as high-risk remediation items.
  • Review exposure of remote access services such as RDP to the public internet and restrict or require strong authentication where exposure is unavoidable.
  • Incorporate credential-based initial access scenarios into ransomware tabletop exercises and incident response playbooks.
  • Implement or review monitoring for anomalous authentication behaviour, including unusual login times, locations, or repeated failed attempts indicative of brute force activity.
  • Ensure phishing-resistant authentication options are evaluated for high-value accounts, moving beyond SMS-based MFA where feasible.
  • Cross-reference active user credentials against known breach databases to identify accounts at elevated risk of credential stuffing attacks.

Sources