Your Password Isn't the Weak Link Anymore โ Your Login Is: Why 79% of Ransomware Attacks Now Start With a Stolen Identity
Published July 16, 2026

If you've spent the last few years patching software and updating firewalls to keep ransomware out, new research suggests you've been guarding the wrong door. A report published by Sophos on July 15, 2026 found that 79% of ransomware attacks now trace back to a compromised identity โ a stolen password, a phished login, or credentials guessed through brute force โ not a software vulnerability. For small and mid-sized businesses across Hayward, San Leandro, Castro Valley, and San Lorenzo, that shift changes what "good security" actually looks like in 2026.
The Shift From Software Bugs to Stolen Logins
For years, cybersecurity advice centered on patching: keep your software updated, close the known vulnerabilities, and attackers can't get in. That advice isn't wrong, but it's increasingly incomplete. According to Sophos's State of Ransomware 2026 report, the percentage of ransomware attacks that started with attackers exploiting a known software vulnerability dropped from 32% in 2025 to just 18% this year.
Identity-based attacks filled the gap, and then some. The report breaks down the shift:
- Malicious email was the entry point in 26% of incidents
- Phishing attacks aimed at stealing login credentials caused 24% of incidents
- Compromised credentials held steady at 23%
- Brute-force attacks โ automated password guessing against weak or reused passwords โ accounted for 6%
Combined, these identity-based methods โ malicious email, phishing, compromised credentials, and brute force โ account for 79% of all ransomware intrusions. Sophos CISO Ross McKerchar has pointed to a shift toward "easier" attacks that use compromised identities as the primary way in, with AI increasingly used to polish phishing emails and run "ClickFix" campaigns designed to trick even trained employees into bypassing multi-factor authentication.
Why "Just Enable MFA" Isn't the Full Answer Anymore
Here's the detail that should give every East Bay business owner pause: in Sophos's companion State of Ransomware 2026 report, 97% of victims whose breach was rooted in compromised credentials already had some form of MFA enabled at the time of the attack.
MFA isn't failing because it doesn't work โ it's failing because not all MFA is equal. Basic forms of MFA, like SMS codes or simple app-based push notifications, can be defeated through social engineering: attackers flood an employee with push notifications until they approve one out of frustration ("push bombing"), or use ClickFix-style phishing pages that walk a victim through approving a fraudulent login in real time.
This is exactly why the Cybersecurity and Infrastructure Security Agency (CISA) specifically recommends phishing-resistant MFA โ methods like security keys or certificate-based authentication that can't be approved by mistake or social engineering โ as the standard businesses should be working toward, not basic MFA as a checkbox exercise. CISA's small business guidance is direct about this: not every MFA method offers the same protection, and businesses should know the difference.
What Happens Once an Attacker Has Your Login
Once identity-based attackers gain a foothold, the Sophos data shows a clear pattern in how they move: exposed applications or systems (38% of cases), remote device logins like RDP (30%), firewalls (21%), exposed VPNs (8%), and even IoT devices (3%). For a small business, this typically means one compromised employee login โ often on a personal device or a system without full monitoring โ becomes the pivot point for access to your entire network, including file servers, backups, and financial systems.
This is precisely the mechanism behind a pattern we covered in our post on why ransomware gangs are now hitting the same victims twice: stolen credentials don't just enable one attack. They get sold and resold on criminal marketplaces, meaning the same compromised login can open the door for multiple ransomware groups over time, often months apart.
The Small Business Ransom Math
There's an uncomfortable nuance buried in the Sophos numbers that matters specifically for smaller organizations. The median ransom demand has fallen to $698,000 this year, down from $2 million just two years ago โ but that's not because attackers have gotten more generous. It's because they've gotten more strategic: ransomware groups increasingly tailor demands to what a victim can plausibly pay. A demand that's "reasonable" relative to a business's size is more likely to actually get paid than one that forces a flat refusal.
Of organizations that had data encrypted, 48% paid the ransom, while 66% relied at least partly on their own backups to recover โ up from 54% the year before, a sign that backup discipline is improving but still isn't universal. For a small business in the East Bay without tested, immutable backups, a "reasonably priced" ransom demand can look like the only fast way back to operating โ which is exactly the outcome attackers are counting on.
Real-World Warning Signs Your Identity Security Has a Gap
Most businesses don't realize their credentials are exposed until an attack is already underway. Watch for:
- MFA prompts employees didn't request โ a strong signal someone else already has their password and is trying to complete a login
- Basic SMS or push-notification MFA as your only protection on email, VPN, or remote access โ exactly the type Sophos and CISA warn can be socially engineered
- Shared or reused passwords across business systems, especially on accounts without individual MFA
- Remote Desktop Protocol (RDP) or VPN access exposed directly to the internet without additional identity verification layers
- No process for immediately disabling former employees' credentials, leaving stale accounts as an open door
- Security alerts about login attempts from unfamiliar locations that get dismissed rather than investigated
If any of these describe your current setup, treat it as a live gap โ not a someday project.
How CMIT Solutions of Hayward Closes the Identity Gap
Identity-based ransomware is exactly the threat that modern managed cybersecurity is built to close. At CMIT Solutions of Hayward, we help small businesses across Hayward, San Leandro, Castro Valley, and San Lorenzo move from basic, easily-bypassed MFA to real identity protection.
Phishing-resistant MFA rollout. We deploy and manage MFA methods that meet CISA's recommended standard, not just the minimum checkbox version most off-the-shelf tools default to. Our guide on how multi-factor authentication enhances security for your business covers what strong MFA actually requires.
Identity threat detection and response (ITDR). Sophos's report specifically recommends ITDR as a foundational control. Combined with the monitoring tools we cover in our breakdown of MDR, EDR, and SIEM, continuous identity monitoring catches anomalous logins and credential misuse before they become a full breach.
Credential audits. We regularly review both human and non-human (service account, API key) credentials across your environment โ closing the stale-account and shared-password gaps that attackers rely on.
Email and phishing defense. Since malicious email and phishing together account for half of all ransomware entry points, our email security best practices guide covers the controls that stop credential-theft attempts before an employee ever sees them.
Layered defense, not a single control. As we outlined in our post on multi-layered cybersecurity as the best strategy for business protection, no single tool โ including MFA โ is sufficient on its own. Identity protection has to work alongside monitoring, backup, and response planning.
It's also worth noting that identity controls aren't just good practice anymore โ they're increasingly a condition of coverage. Our recent post on cyber insurance mandates explains how insurers are now requiring MFA and monitoring as a condition of paying claims at all.
The Takeaway for East Bay Small Businesses
The message from the 2026 Sophos data is clear: the front door to your network is no longer a software vulnerability โ it's a login. For businesses in Hayward, San Leandro, Castro Valley, and San Lorenzo, that means identity protection โ real, phishing-resistant MFA, credential monitoring, and fast deprovisioning โ deserves the same priority as patching and antivirus once did.
If you're not certain your current MFA setup would hold up against the social-engineering tactics attackers are using right now, that's worth finding out before an attacker does. Contact CMIT Solutions of Hayward for a free identity security assessment.
Frequently Asked Questions
Why are stolen logins now the top cause of ransomware attacks instead of software vulnerabilities?
Attackers have shifted toward what Sophos researchers describe as "easier" attacks. Exploiting a software vulnerability requires finding an unpatched system and a working exploit. Stealing a login only requires a convincing phishing email, a guessable password, or credentials purchased from a criminal marketplace โ and AI tools have made phishing emails far more convincing. As a result, identity-based methods (malicious email, phishing, compromised credentials, and brute force) now account for 79% of ransomware intrusions, while vulnerability exploitation has dropped to 18%.
If we already have MFA, are we protected?
Not necessarily. Sophos found that 97% of victims whose breach started with compromised credentials already had some form of MFA enabled. Basic MFA methods like SMS codes or simple push notifications can be bypassed through social engineering tactics like push-bombing or ClickFix-style phishing. CISA specifically recommends phishing-resistant MFA โ such as security keys โ for meaningful protection, rather than treating any MFA as sufficient.
How does a stolen employee login turn into a full ransomware attack?
Once attackers have valid credentials, they use them to access exposed applications and systems, remote logins like RDP, firewalls, and VPNs โ moving from one compromised account to broader network access, including file servers and backups. Stolen credentials are also frequently resold on criminal marketplaces, meaning a single compromised login can enable multiple attacks by different groups over time, sometimes months apart.
What should a small business in Hayward or the East Bay do first to reduce this risk?
Start with an honest audit of your current MFA: is it phishing-resistant, or just a checkbox? From there, prioritize credential monitoring (to catch stolen logins before they're used), a fast process for disabling former employees' access, and layered defenses like endpoint monitoring so a single stolen login can't turn into full network access. A managed IT provider can assess your current identity security gaps and prioritize fixes based on actual risk.