Skip to content

Identity Attacks Displace Exploits as Leading Cause of Ransomware Incidents

At a glance: Identity attacks have become the leading ransomware cause, yet MFA failed to prevent compromise in 97 % of these cases despite being deployed.

Email-based identity attacks have risen to become the most common entry vector for ransomware infections, displacing vulnerability exploits from first place. Even multi-factor authentication (MFA) failed to prevent compromise in 97 % of cases.

According to current findings, email-based identity attacks have replaced vulnerability exploits as the primary attack vector in ransomware campaigns. This significantly shifts security management priorities: while technical patches and exploit mitigations have long been the focus, it now becomes clear that the compromise of user accounts represents the more direct and successful path into enterprise networks.

Particularly striking is that in 97 % of tracked cases involving compromised credentials, multi-factor authentication (MFA) was in place, yet it still failed to prevent the compromise. This points to weaknesses in the practical implementation, configuration or enforcement of MFA measures—or to advanced attacker bypass tactics such as MFA bridge attacks and phishing relay attacks.

For CISOs, this means that MFA deployments alone without additional control mechanisms create a false sense of security. More comprehensive strategies are needed: risk-based authentication, detection of anomalous login patterns, Privileged Access Management (PAM), and training to prevent phishing and credential harvesting. Technical controls must be complemented by organizational and behavioral protection measures.


Source: www.darkreading.com · Published July 15, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: