A new Sophos cybersecurity report reveals a significant shift in ransomware tactics: identity-based attacks have overtaken software vulnerabilities as the leading method for gaining initial access to victim networks.

According to the report, cybercriminals are increasingly targeting user identities through stolen credentials, compromised accounts, phishing campaigns, and Multi-Factor Authentication (MFA) fatigue attacks instead of relying solely on unpatched software flaws. Once attackers gain access to a legitimate account, they can move laterally across the network, escalate privileges, deploy ransomware, and exfiltrate sensitive data while blending in with normal user activity.

The findings reflect the growing importance of identity security as organizations adopt cloud services, remote work, and hybrid IT environments. Security experts recommend implementing phishing-resistant MFA, enforcing strong password policies, adopting the principle of least privilege, continuously monitoring user behavior, and deploying Identity Threat Detection and Response (ITDR) solutions to detect suspicious account activity.


Why It Matters

The report highlights that attackers are shifting from exploiting systems to exploiting people and identities. As credentials become the new security perimeter, protecting user accounts is just as critical as patching software vulnerabilities.


Conclusion

Sophos' latest findings reinforce that modern ransomware groups are prioritizing identity compromise over software exploitation. Organizations that strengthen identity protection, continuously monitor privileged accounts, and adopt Zero Trust security principles will be better positioned to defend against today's evolving ransomware threats.