Manila Standard reports that identity is the dominant initial access vector in ransomware attacks, according to a new report from Sophos:
Sophos, a global cybersecurity leader, released its seventh annual State of Ransomware report, a vendor-agnostic survey of IT and cybersecurity leaders across 17 countries identifying the impact of ransomware on businesses and how prepared organizations are to defend against them.
This year’s report reveals that identity is the dominant initial access vector (IAV), with four in five (79%) of ransomware attacks starting with compromised identities.
The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognize identity as a key component in ransomware delivery. Additionally, for the first time in four years, exploited vulnerabilities are no longer the most common root cause, with malicious email (26%) and phishing (24%) taking the top spot.
However, exploited vulnerabilities remain a high value target: 59% of ransom demands that start with an exploited vulnerability on the firewall are for $1M or more compared to 48% of all attacks.
Read more at Manila Standard.
