Ransom demands are down, email is the top way attackers get in

An employee opens an email that looks like any other, clicks a link, and gives up a password without noticing. A stolen login opens a door deeper in the network. Files stop opening a few days later.
That chain now sits at the front of most ransomware cases. Malicious email and phishing together account for half of all incidents, based on a survey of 2,158 IT and security leaders whose organizations were hit in the past year. Sophos commissioned the research and gathered the answers early in 2026.
Stolen credentials sit close behind email as a way in. Close to eight in ten attacks opened with an identity-based move, taking a credential or using one already taken. Two-thirds of victims said their ransomware incident was the same event as their worst identity breach.
Related Articles


