What the Sophos Report Found About Compromised Identities
A newly published Sophos report puts a hard number on something security teams have suspected for years: ransomware gangs are no longer breaking down the front door, they're walking in with a stolen key. According to the findings, 79% of ransomware attacks now originate from compromised identities, meaning the initial access point in most cases is a valid username and password rather than a software exploit or malicious attachment.
The report also highlights a stark gap in how organizations of different sizes respond once an attack begins. Only 34% of small organizations managed to stop an attack before encryption or extortion occurred. Compare that to organizations with 3,001 to 5,000 employees, which stopped attacks 46% of the time. That gap suggests resourcing, staffing, and detection maturity still matter a great deal, even when the attacker's entry method looks similar across company sizes.
Geographically, the report notes that the UK recorded the highest median ransom demand of any region covered in the study. While the full breakdown of figures wasn't detailed, the pattern reinforces a broader trend: ransom demands are being calibrated based on perceived ability to pay, not just the value of the data itself.
Why MFA Alone Isn't Stopping Ransomware
Here's the finding that should reshape a lot of security budgets: multi-factor authentication was deployed in some capacity in 97% of incidents where compromised credentials were the root cause. In other words, nearly every organization that got breached through stolen credentials already had MFA turned on somewhere in their environment.
This doesn't mean MFA is useless. It means MFA is not a complete solution when it's inconsistently applied. Coverage gaps, such as legacy systems that don't support modern authentication, service accounts excluded from MFA policies, or remote access tools configured with weaker verification, give attackers exactly the opening they need. A determined attacker doesn't need to defeat MFA everywhere; they just need to find the one login path where it was never enforced.
This is the core tension the Sophos data exposes. Security teams have spent years treating MFA as a checkbox, but ransomware operators have adapted by hunting for the accounts, systems, and integrations that fall outside that checkbox. The result is a defense strategy that looks strong on paper but has real holes in practice.
Practical Identity Hygiene Steps Beyond MFA
If credential compromise is the dominant entry point, then identity hygiene deserves the same operational attention that patch management or endpoint detection typically get. A few practical steps stand out based on the report's implications:
- Audit MFA coverage, not just MFA existence. Confirm that every remote access point, admin account, and third-party integration actually enforces MFA, not just the primary login screen.
- Prioritize phishing-resistant authentication where possible, since traditional one-time codes can still be intercepted or socially engineered.
- Monitor for credential reuse and stale accounts. Dormant accounts and shared logins are common blind spots that attackers exploit long after employees have moved on or changed roles.
- Segment access by role and necessity. Even a compromised credential is far less useful to an attacker if it doesn't grant broad lateral movement across the network.
- Build faster detection and response capacity, especially for smaller organizations. The gap between 34% and 46% containment rates suggests that speed of detection, not just prevention, is where resource-constrained teams are losing ground.
None of these steps require exotic tools. They require discipline, visibility, and a willingness to treat identity as a living system that needs regular auditing rather than a one-time setup task.
Where Encrypted Tools and VPNs Fit Into Layered Defense
VPNs and encrypted access tools remain a useful layer in a broader identity protection strategy, particularly for securing remote logins and reducing exposure on untrusted networks. But the Sophos findings are a reminder that no single tool, whether it's a VPN, MFA, or endpoint protection, can substitute for consistent identity governance across an entire organization. Attackers look for the gap between tools, not the tools themselves.
This is also a good moment to think about how access controls and internet policy intersect more broadly. Just as governments are increasingly scrutinizing how VPN providers handle access restrictions, organizations are being asked to scrutinize how their own access tools are configured and monitored. Understanding how layered restriction systems work, similar to how national internet censorship systems are built with multiple enforcement layers rather than a single gate, offers a useful analogy for why ransomware defense also requires multiple, overlapping controls rather than reliance on any one safeguard.
What This Means For You
If you manage IT security at any size of organization, this report is a signal to revisit assumptions. Having MFA enabled is not the same as having MFA enforced everywhere it matters. Credential theft ransomware defense in 2026 requires treating identity as an ongoing operational discipline, not a project that was finished once MFA rollout was marked complete.
For smaller organizations especially, the containment rate gap is worth taking seriously. It suggests that investment in detection and response capability, even modest improvements, can meaningfully change the outcome of an attack that has already gained initial access.
Key Takeaways
- 79% of ransomware attacks now start with compromised credentials, according to Sophos.
- MFA was present in 97% of credential-based ransomware incidents, showing that coverage gaps, not MFA's absence, are the real problem.
- Small organizations stopped attacks only 34% of the time, compared to 46% for larger organizations with 3,001 to 5,000 employees.
- The UK recorded the highest median ransom demand in the report.
- Effective credential theft ransomware defense requires auditing MFA coverage, monitoring for stale or reused credentials, segmenting access, and building faster detection capacity, not relying on any single security tool.




