Cybercriminals are now more likely to break into company systems by stealing employee login details than by exploiting software flaws, according to the latest State of Ransomware 2026 report from Sophos.
The cybersecurity company found that 79% of ransomware attacks now start with stolen or compromised user accounts, making usernames and passwords the hackers’ favorite way into business networks. The shift shows that cybercriminals are increasingly targeting people, not just technology.
Sophos also found that malicious emails (26%) and phishing attacks (24%) have become the leading causes of ransomware attacks, replacing software vulnerabilities for the first time in four years. Instead of looking for weaknesses in software, attackers are finding it easier to trick employees into giving away their login credentials.
The findings are particularly relevant for businesses in the Philippines, where ransomware continues to threaten government agencies, financial institutions, hospitals, and private companies. Protecting employee accounts is becoming just as important as keeping software up to date.
“As we see ransomware criminals experiment with AI, it has the potential to accelerate their ability to steal valuable assets, hold them hostage and do it at a scale that exceeds their previous capability,” said Ross McKerchar, chief information security officer, Sophos. “This speed requires careful round-the-clock monitoring of the most exploited means of entry, which our data shows to be stolen and compromised valid accounts.”
McKerchar added that advances in open AI models could help attackers find software weaknesses much faster. That means organizations can no longer rely on software updates alone. They also need to limit online exposure and strengthen security on employee devices.
The survey found that 56% of organizations hit by ransomware had their data locked by attackers, reversing a two-year decline. Nearly half (48%) paid the ransom to regain access to their files or systems.
The report also showed how closely ransomware is now tied to stolen identities. About 67% of victims said the ransomware attack was also the biggest identity-related security incident they had experienced, highlighting the growing importance of protecting employee accounts.
Even organizations using multi-factor authentication (MFA) were not fully protected. Sophos found that MFA was in place in 97% of attacks involving stolen credentials, suggesting that attackers are finding ways around it through weak configurations, phishing, or stolen login sessions. The company said MFA remains important but should be part of a broader security strategy.
There is some good news. More than half (55%) of organizations recovered from a ransomware attack within a week, while 16% restored operations in less than a day. Sophos said improved backup systems are helping businesses recover faster and avoid lengthy disruptions.
Still, ransomware remains costly. The average recovery cost has risen to $1.7 million per attack, even though ransom demands have fallen over the past two years.
Based on the findings, Sophos recommends that organizations focus on protecting user accounts, regularly test backup systems, reduce unnecessary internet-facing services, and combine prevention, detection, and response into one cybersecurity strategy. As attackers use AI to work faster, businesses will also need smarter tools to keep pace.