
Stolen logins have overtaken software flaws as the top way into a ransomware attack. Turn on MFA.
New Sophos figures show 79% of ransomware attacks now start with a stolen login, not an unpatched system.
For years the advice on ransomware led with patching. Fix your known flaws fast and you shut the front door. New figures from security firm Sophos show the front door has moved. In its analysis of real ransomware cases, 79% now start with a stolen or misused login rather than an unpatched system.
What changed
For the first time in four years, exploited software vulnerabilities are no longer the most common way in. Malicious email was the root cause in 26% of cases and phishing in 24%, while attacks that began with an exploited vulnerability fell to 18%, down from 32% a year earlier. The pattern is clear. Attackers would rather log in than break in.
How a stolen login gets used
Once a set of credentials is in hand, attackers use it wherever it still works. Sophos saw stolen logins turned against exposed business applications, remote-access tools, firewalls and VPNs. None of that needs a clever exploit. It needs a password that still works and no second factor to stop it.
The research, in short
The findings come from interviews with 2,158 IT and cyber-security leaders across 17 countries, including the UK, all at organisations that had been hit by ransomware in the previous year. So this is a picture of what actually happened to real businesses, not a lab test.
What actually helps
Multi-factor authentication (MFA) is the single control that turns most stolen passwords into dead ends. Turn it on everywhere that matters: email, remote access, VPNs, admin accounts and anything facing the internet. Back it with staff who can spot a phishing email, and review who has access to what, including service accounts that no person ever logs into. Ross McKerchar, Sophos' chief information security officer, put it plainly: defenders cannot rely on patching alone to keep pace.
What this means for your business
Patching still matters, but it is no longer where most attacks begin. If your team can log in from home or on the road, treat every one of those logins as a target. MFA on email and remote access, phishing training your staff will actually remember, and a periodic check of who can reach what will stop the majority of these attacks before they start. MFA is also a core Cyber Essentials control, so it counts twice. If you are not sure where MFA is missing across your systems, that is a short audit we can run for you.
#WEARECOBALT
Ready when you are.
Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.