Compromised identities have become the leading entry point for ransomware attacks, overtaking exploited software vulnerabilities as cybercriminals increasingly rely on malicious email and phishing campaigns to gain access to organisations, according to Sophos’ State of Ransomware 2026 report.
Based on a survey of 2,158 IT and cybersecurity decision-makers across 17 countries, including the UAE, the report found that 79 percent of ransomware attacks globally now originate from compromised identities. For the first time in four years, exploited vulnerabilities are no longer the most common root cause of ransomware incidents, with malicious email accounting for 26 percent of attacks and phishing a further 24 percent.
The findings also highlight the financial impact of ransomware on organisations in the UAE. Businesses that suffered ransomware attacks reported an average recovery cost of US$665,000. Meanwhile, 38 percent of ransomware incidents in the country resulted in data encryption, including 13 percent where data was both encrypted and stolen.
“As we see ransomware criminals experiment with AI, it has the potential to accelerate their ability to steal valuable assets, hold them hostage and do it at a scale that exceeds their previous capability,” said Ross McKerchar, Chief Information Security Officer at Sophos. “This speed requires careful round-the-clock monitoring of the most exploited means of entry, which our data shows to be stolen and compromised valid accounts. However, the improvement of unguarded open-weight AI models will give attackers a growing advantage in finding and exploiting software vulnerabilities. Defenders cannot rely on patching alone to keep pace, so reducing external exposure and maintaining strong endpoint protection is essential.”
Globally, 56 percent of ransomware attacks resulted in data encryption, reversing a two-year downward trend. The report also found that 67 percent of ransomware victims identified the incident as their most significant identity attack, reinforcing identity compromise as the primary ransomware delivery mechanism.
While recovery capabilities have improved, ransomware continues to impose significant costs on organisations. Sophos found that 55 percent of organisations recovered from ransomware incidents within one week, while 16 percent restored operations in less than a day. The company recommends strengthening identity security, investing in resilient backup infrastructure, maintaining exposure management programmes and integrating prevention, detection and response as part of a unified cybersecurity strategy.




Discussion about this post