Identity Attacks Overtake Exploits as Top Ransomware Cause
For years, ransomware gangs were best known for exploiting unpatched software, the kind of vulnerability that keeps IT teams scrambling to apply security updates. That's no longer the primary way these attacks begin. According to new findings reported by Dark Reading, phishing and malicious email now account for half of all ransomware attacks, officially overtaking software vulnerabilities as the leading entry point.
Even more notable: multi-factor authentication (MFA), long considered one of the strongest defenses against stolen credentials, was already in place in 97% of the credential-based attacks studied. In other words, attackers aren't succeeding because organizations skipped basic security hygiene. They're succeeding because they've found ways around it.
This shift matters because it changes where the real risk sits. Patching servers and closing software holes remains important, but the data suggests attackers have shifted their energy toward tricking people rather than breaking code. A convincing email, a fake login page, or a well-timed phone call can now do what a zero-day exploit used to do.
Why MFA Alone Isn't Stopping Attackers
MFA has been marketed for years as a near-foolproof safeguard against credential theft. The idea is simple: even if a password is stolen, an attacker still needs a second factor, like a code sent to a phone or an authentication app, to get in. That logic holds up against basic password-guessing attacks. It holds up much less well against modern phishing kits.
Attackers have adapted with techniques designed specifically to defeat MFA. Real-time phishing proxies can intercept both a password and a one-time code the moment a victim enters them, then relay that information to the real login system before the code expires. Other methods target session tokens directly, allowing attackers to hijack an already-authenticated session without ever needing the second factor at all. The fact that MFA was present in 97% of credential-based ransomware attacks in this dataset shows that having MFA turned on is no longer enough on its own. How it's implemented, and whether it resists phishing specifically, matters just as much as whether it exists.
This doesn't mean MFA is worthless. It still blocks a large volume of automated and low-effort attacks. But organizations and individuals relying on it as a single silver bullet are working from an outdated threat model.
How This Compares to the Broader Breach Picture
This ransomware-specific trend sits alongside a related but distinct shift documented elsewhere in the industry. As covered in vpn.social's look at the Verizon 2026 Data Breach Investigations Report, software flaws have overtaken stolen or weak passwords as the top entry point for breaches broadly. At first glance, that seems to contradict the ransomware findings, but the two data sets are measuring different things. The DBIR looks at breaches across all categories and industries, while this ransomware research zeroes in specifically on how ransomware operators get their initial foothold.
Taken together, the picture that emerges is one of specialization. Some attackers are refining automated exploitation of software vulnerabilities at scale, while ransomware crews in particular are doubling down on human-targeted social engineering, likely because it offers a faster, more reliable path to the kind of privileged access needed to deploy ransomware across a network. Both trends can be true simultaneously, and both point to the same underlying reality: attackers go wherever the path of least resistance leads, and that path shifts constantly.
What This Means For You
If you use email at all, whether for work or personal accounts, this trend directly affects you. Ransomware doesn't just target large corporations with dedicated IT departments; small businesses, healthcare providers, schools, and individual professionals are all regularly targeted through the same phishing tactics. A single convincing email opened at the wrong moment can be the entry point for an attack that encrypts an entire organization's files.
The practical takeaway isn't to abandon MFA. It's to recognize that MFA is one layer in a broader defense, not a finish line. Phishing-resistant authentication methods, careful scrutiny of unexpected login prompts, and basic skepticism toward urgent-sounding emails all remain essential, even for accounts already protected by MFA.
Actionable Takeaways
- Treat MFA prompts you didn't request as a red flag, not a routine notification, and never approve one you didn't initiate.
- Where possible, use phishing-resistant authentication methods such as hardware security keys instead of SMS or app-based codes alone.
- Be cautious of urgency in emails asking you to log in, reset a password, or verify an account, these are classic ransomware entry tactics.
- Keep software patched even though identity attacks now lead ransomware causes; exploit-based attacks haven't disappeared, they've just been overtaken in frequency.
- If you manage a team or organization, invest in phishing awareness training alongside technical defenses, since the data shows people, not just systems, are now the primary target.
As ransomware tactics continue to shift toward identity and social engineering, staying informed about how these attacks actually unfold is one of the most effective defenses available. Understanding where the real risk lies today is the first step toward closing that gap before attackers can exploit it.




