Ransom demands are down, email is the top way attackers get in

Posted: 20th Jul 2026

An employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later.

That chain now sits at the front of most ransomware cases. Malicious email and phishing together account for half of all incidents, based on a survey of 2,158 IT and security leaders whose organizations were hit in the past year. Sophos commissioned the research and gathered the answers early in 2026.

Stolen credentials sit close behind email as a way in. Close to eight in ten attacks opened with an identity-based move, taking a credential or using one already taken. Two-thirds of victims said their ransomware incident was the same event as their worst identity breach.

 

View Full Article

Related Articles

Popular Articles

Enterprises are in the midst of a pivotal 18- to 24-month disruption window. And Broadcom’s VM...
Companies are seeking more adaptable ways to run applications, govern data, and control costs as...
The difference between staying static and gaining lift often comes down to clarity; knowing where Co...
VMware released patches for various critical bugs affecting its multicloud application delivery plat...