45 Ivan Allen Jr Blvd NW
Atlanta, GA 30308
+1 (888) 808-7330
General: [email protected]
Sales: [email protected]
Support: [email protected]
What the 2026 data actually says about why organizations become susceptible to ransomware
Reading time: ~10 minutes | Audience: CISOs, security leadership, IT directors, MSP buyers
If you read the two most-cited security reports published this year, you would come away with opposite conclusions about how ransomware gets in.
Verizon's 2026 Data Breach Investigations Report — 22,000-plus confirmed breaches across 145 countries, the largest dataset in the report's nineteen-year history — found that exploitation of vulnerabilities became the most common initial access vector for the first time ever, at 31% of breaches, up from 20% the prior year. Credential abuse, the previous leader, fell to 13%.
Sophos's State of Ransomware 2026, a vendor-agnostic survey of 2,158 organizations that were actually hit by ransomware in the preceding twelve months, found the reverse. Exploited vulnerabilities fell fourteen percentage points to 18% and lost the top spot they had held for three years. Malicious email (26%) and phishing (24%) together accounted for half of all incidents. Compromised credentials held at 23%.
One dataset says patch faster. The other says patching is not your problem.
The instinct is to pick the more credible one. That is the wrong move, and the reason it is wrong turns out to be the most useful thing in either report.
These are not measurements of the same thing.
The DBIR counts confirmed breaches of every type, including espionage campaigns against edge infrastructure, which skew heavily toward exploitation. The Sophos survey counts self-reported root causes from ransomware victims specifically, which introduces a different bias: respondents are describing what they believe happened, and organizations reliably over-attribute to the failure they can name. Sophos's own incident response data — 661 IR and MDR cases in the 2026 Active Adversary Report — puts vulnerability exploitation at 16% and brute force at 15.6%, close enough to be indistinguishable, with 67% of root causes identity-related overall.
Both are also commercially situated. Sophos sells email security, identity threat detection, and MDR. Verizon's contributor base shapes what is included in the dataset. Neither fact invalidates the numbers; both should be kept in view while reading them.
But the disagreement is not really noise. Read together, the two datasets describe an adversary population that reallocates toward whichever control an organization has not finished implementing. When perimeter patching improves, entry moves to the inbox and the login page. Sophos's analysts note that the decline in vulnerabilities may prove temporary and caution that AI-assisted vulnerability discovery could push it back up next year.
Which reframes the question. Susceptibility is rarely the absence of a control. It is almost always the unfinished edge of one you already own.
The rest of this post is about the conditions that keep those edges unfinished.
The single most instructive number in this year's reporting is this: among ransomware victims for whom compromised credentials were the root cause, 97% had some form of multi-factor authentication enabled at the time of the attack.
MFA was present in nearly every environment that fell. It stopped almost none of them.
The Active Adversary data explains why. MFA was missing where it mattered in 59% of cases. The pattern Sophos's responders describe is consistent and recognizable: SaaS applications had MFA. VPNs, firewall administration consoles, and legacy applications frequently did not.
This is what a coverage gap looks like in practice. The control was purchased, deployed, reported to the board as complete, and audited as present. The rollout stalled on the systems that were hardest to migrate — which are, not coincidentally, the oldest, most privileged, and most exposed.
Sophos's mapping of where initial compromises actually occurred reinforces the point: exposed applications and systems (38%), user devices (30%), firewalls (21%), VPNs (8%), IoT (3%). And when a firewall vulnerability was the entry point, 59% of ransom demands exceeded $1 million, against a 48% baseline — because a compromised firewall confers position, not just access.
The measurement failure is treating deployment as a binary. An MFA program that covers 90% of authentication surfaces is not 90% effective. It is a map of where to attack.
The DBIR's vulnerability management analysis draws on more than 13,000 organizations and over 527 million vulnerability instances. The findings are uncomfortable:
That last point deserves more attention than it gets. If well-resourced programs and under-resourced ones produce similar day-seven numbers, the constraint is not diligence. It is structural: change control windows, vendor patch availability, availability requirements for the systems most exposed, and the fact that edge appliances are frequently the hardest things in the estate to take offline.
Verizon also observed ProxyShell and ProxyLogon access still in use two to three years after disclosure. The long tail is not an anomaly. It is the normal operating state of enterprise remediation.
Practical implication: a security strategy that depends on winning the patch race relies on something that aggregate data shows almost nobody wins. Compensating controls on unpatchable assets — segmentation, restricted management-plane access, monitoring tuned to exploitation behavior rather than signature — are not a fallback position. For edge infrastructure, they are in the primary position.
The DBIR's most operationally actionable finding this year concerns sequencing. Among ransomware victims, 73% had an associated infostealer or credential leak within the year preceding the attack. Half of those leaks occurred within 95 days of the ransomware event.
Small organizations experienced a median of seven credential leak events over the year. Large organizations, around twenty.
This is a supply line, not a coincidence. Infostealer malware — frequently on a personal device, a contractor's laptop, or an unmanaged endpoint outside any corporate control — harvests credentials. Those credentials are packaged and sold by initial access brokers. Verizon's analysis of broker listings found that 44% of known connection types were VPNs and 35% were remote desktops. Ransomware operators buy access and spend their effort on lateral movement, escalation, and extortion rather than intrusion.
The consequence for defenders is that the window in which susceptibility could have been addressed opens well before anything appears in your telemetry. Credential exposure monitoring — dark web and infostealer market coverage, tied to enforced rotation — serves here as an early-warning layer, not a threat-intelligence luxury. A leak event involving a VPN credential is a countdown, and the median distance to detonation is under three months.
Third-party involvement appeared in 48% of confirmed breaches in the 2026 DBIR, up from 30% — a 60% year-over-year increase, following a prior year in which the figure had already doubled.
The remediation data behind that number is the part worth carrying into vendor conversations. Verizon collected observations from inside third-party cloud environments and found that only 23% of third-party organizations had fully remediated missing or improperly secured MFA on cloud accounts. Weak passwords and permission misconfigurations took a median of eight months to resolve half of the findings.
Eight months is longer than most vendor risk review cycles. It is considerably longer than the interval between a questionnaire being returned and a breach occurring.
The structural point: your susceptibility is partly a function of remediation velocity in organizations whose security programs you do not run, cannot observe, and are typically assessed via an annual document exchange. A questionnaire that confirms policy language without confirming control implementation measures, paper, and exposure.
Initial access determines whether an intrusion occurs. Internal topology determines whether it becomes an enterprise-wide encryption event.
Verizon's attack graph analysis found that 16% of organizations had roughly 80% exposure — meaning that an attacker with low-privilege access had an 80% or better chance of reaching a key administrative account or critical infrastructure element. In the System Intrusion pattern, which now accounts for 60% of breaches, ransomware appears in 77%.
The timeline compressed as well. Median dwell time in Sophos's 2026 IR cases fell to three days. That reflects both faster attackers and faster defenders, but the direction of travel for response planning is one-way: runbooks calibrated to multi-day detection windows are calibrated to a threat model that has moved.
This is why privilege topology — service account sprawl, nested group inheritance, standing administrative rights, flat network segments between user devices and identity infrastructure — is a ransomware control and not a hygiene project. It is the difference between an incident and an outage.
Only 34% of organizations with 100–250 employees stopped an attack before encryption or extortion, against 46% at organizations with 3,001–5,000 employees.
Sophos's respondents were candid about why. Asked what left them exposed, victims cited security gaps — known or unknown — at 62%, lack of people or skills at 58%, and lack of or poor-quality protection at 57%, for the second consecutive year. Respondents averaged multiple contributing factors, not one.
Note the phrasing: known or unknown. A meaningful share of victims were aware of the gap that was used against them. Susceptibility in those cases was not an intelligence failure. It was a capacity and prioritization failure — which is a different problem with different solutions, and one that no additional tool purchase resolves.
For organizations below the size at which a 24/7 detection function is economically viable, that coverage has to be sourced rather than built. That is a budget-line conclusion, not a moral one.
IBM's 2026 Cost of a Data Breach report found AI-driven attacks accounted for roughly a quarter of malicious incidents, up 56% year over year, and that AI-assisted breaches carried higher costs. Those findings are real and worth tracking.
They are also not what made most organizations susceptible this year. Sophos's incident responders were direct about it: this year's attackers used substantially the same tools, techniques, and procedures they have used for years — abuse of legitimate administrative tooling, missing telemetry, and the absence of phishing-resistant MFA. The DBIR's own incident data shows that phishing as an initial access vector barely moved year over year, suggesting AI is raising the floor on lure quality rather than creating a new category of intrusion.
The honest summary: AI is making existing tradecraft cheaper and faster to scale. It has not yet changed which weakness gets exploited. Budget accordingly — the conditions listed above are still the ones doing the damage.
If susceptibility is coverage rather than absence, then most security metrics are measuring the wrong axis. A shortlist of replacements:
Why Organizations Choose Zaxtron
Organizations face increasingly sophisticated ransomware campaigns that exploit unpatched systems, stolen credentials, exposed remote access, and third-party weaknesses. To stay protected, they need actionable intelligence, not just alerts, to identify and reduce cyber risks before disruption occurs. Zaxtron provides Cybersecurity Risk Management, AI Risk Management, and Cyber Threat Intelligence services that deliver continuous visibility and risk-based insights. By combining attack surface intelligence, vulnerability data, threat and breach intelligence, and third-party risk analysis, Zaxtron offers a complete view of cyber exposure. This helps security leaders respond to threats, improve vendor security, and make informed decisions. Contact Zaxtron to strengthen cyber resilience today.
Organizations did not become susceptible to ransomware this year because they failed to buy something. Most victims owned the relevant control. In the credential-compromise cases, 97% of them had MFA.
They became susceptible because coverage stopped short of the systems that were hardest to change, because remediation capacity has a structural ceiling that effort does not raise, because credentials leaked months earlier through devices outside their control, because trust extended to vendors was not verifiable, and because internal privilege topology converted a single foothold into an enterprise event.
None of that is exotic. All of it is measurable. The organizations that fare best are not the ones with the most controls — they are the ones that know precisely where each control stops.
Cookie preferences