79% of ransomware attacks happen because your password is the weakest link

Stolen credentials drove 79% of ransomware attacks in 2026, Sophos finds. Recovery costs: $1.7 million per incident.

Contributed Content

ransomware attacks passwords new report
Sophos surveyed 2,158 IT and cybersecurity leaders across 17 countries for its seventh annual ransomware report. Image illustration created with TechNation's TN:AI Workflow.

Topics: 

Sharing is caring! 

Ransomware criminals have shifted their primary method of entry: stolen and compromised login credentials now account for 79% of attacks, according to Sophos’s seventh annual State of Ransomware report, published on 20 July 2026[1].

The report is based on a vendor-agnostic survey of 2,158 IT and cybersecurity leaders across 17 countries, including South Africa, whose organisations were all hit by ransomware in the previous 12 months. Vanson Bourne conducted the survey on behalf of Sophos in Q1 2026.

Ransomware report findings

For the first time in four years, exploited vulnerabilities are no longer the leading root cause of ransomware attacks. Their share fell from 32% in the 2025 report to 18% this year.

Malicious email (26%) and phishing (24%) are now the two most common entry points, together accounting for half of all incidents.

The identity angle is sharper than those headline numbers suggest.

Two-thirds of ransomware victims (67%) confirmed that their ransomware incident was the same event as their most significant identity attack, establishing credential compromise as the dominant delivery mechanism, not a secondary concern.

How it impacts SA businesses

That context matters for South African organisations navigating a threat environment that has traditionally leaned on perimeter defences and patch cycles. The data makes clear that a stolen password can do more damage than an unpatched firewall.

MFA alone is not the answer, either. Among organisations where compromised credentials were the root cause, 97% had multi-factor authentication (MFA) enabled in some capacity at the time of the attack. Ross McKerchar, chief information security officer at Sophos, said:

“This speed requires careful round-the-clock monitoring of the most exploited means of entry, which our data shows to be stolen and compromised valid accounts.”

MFA is multi-factor authentication, meaning a login system that requires more than just a password, typically a one-time code or push notification. The finding suggests that gaps in MFA coverage, rather than its absence entirely, are what attackers are exploiting.

The deal with encryption

The encryption picture has also moved in the wrong direction after two years of improvement. Over half of ransomware attacks (56%) succeeded in encrypting data in the past year, up from 50% in the 2025 report, though still well below the 76% peak recorded in 2023.

Of that 56%, 16% involved data that was both encrypted and stolen, giving attackers two separate points of leverage.

Smaller organisations are bearing that risk disproportionately. Only 34% of organisations with 100 to 250 employees stopped attacks before encryption or extortion. For organisations with 3,001 to 5,000 employees, the stop rate was 46%.

Show us the money

On the payment side, there is genuine movement. The median ransom demand fell to $698,000 (about R12.7 million at current rates), down 65% over two years. The median actual payment dropped to $769,000 (about R14 million), and 51% of organisations that paid negotiated the amount below the initial demand.

Recovery costs tell a different story: the average bill to restore operations, excluding any ransom paid, rose 11% to $1.7 million (about R31 million) per incident.

McKerchar said organisations have strengthened their ransomware resilience but warned that AI is changing the calculus for attackers.

“As AI becomes more capable, attackers will be able to enumerate identity misconfigurations and weak points across organisations far more cheaply and quickly than before,” he said.

Over half of organisations (55%) recovered within one week of an attack, with 16% back up in under a day. Backup-based recovery climbed to 66% of cases where data was encrypted, up from 54% in 2025.

The recovery progress is real. The $1.7 million average cleanup bill is not.

Sources
[1] Sophos. “The State of Ransomware 2026.” Sophos, July 20, 2026.

Before you @ us:

No, AI did not “write this article.” Calm down. This piece was produced using our TN:AI newsroom workflow. The opinions and typos belong to a human who has algorithmic side quests. (Hi!) We even wrote an AI policy so nobody panics.

🧠 AI-assisted research + summarisation 📝 Human edited + fact-checked

Sharing is caring! 

Featured reads: