Sophos Threat Research flags surge in identity-based ransomware

Ransomware attacks in India are changing course. According to Sophos threat research, compromised identities have become the leading entry point for attackers, replacing software vulnerabilities as the primary way cybercriminals gain access to enterprise environments.
The findings, based on Sophos' latest State of Ransomware report, point to a growing need for organisations to rethink cybersecurity strategies around identity protection rather than relying solely on traditional vulnerability management.
Sophos cybersecurity highlights a changing cyberattack initial access vector
The latest Sophos cybersecurity findings reveal that 81% of ransomware attacks in India began with compromised user credentials, higher than the global average of 79%. Malicious emails and phishing together accounted for more than half of all attacks, while exploited vulnerabilities dropped to just 11%.
The report suggests attackers are increasingly choosing identity-based intrusion over technical exploits, making the cyberattack initial access vector more dependent on stolen credentials than software flaws.
Sophos Active Adversary report calls for phishing-resistant MFA tokens
The findings reinforce why organisations need to strengthen identity security beyond conventional multi-factor authentication. Although 98% of affected organisations had MFA in place, Sophos notes that incomplete coverage still leaves gaps for attackers to exploit.
The company recommends adopting phishing-resistant MFA tokens, regularly auditing both human and non-human identities, improving backup strategies, and combining prevention, detection and response into a unified security approach.
Enterprise cybersecurity improves recovery, but costs remain high
While more organisations are recovering quickly from ransomware incidents through improved backup infrastructure, the financial impact remains significant. The report found the average recovery cost for Indian organisations was $1.11 million, even as recovery times continued to improve.
The findings suggest that enterprise cybersecurity investments are becoming more effective, but evolving identity-based attacks require organisations to continuously adapt their security strategies.
Read More:
Tenable One exposure management platform rethink cyber risk
Samsung 990 SSD Brings PCIe 4.0 Performance to Everyday PCs
HP showcases AI PCs and enterprise AI strategy with Delta IT Network
FUJIFILM India Launches Revoria Press PC2120 With AI-Driven Printing






