iTnews Asia
  • Home
  • News
  • Security

Sophos: Identity attacks have overtaken software flaws as entry point of ransomware

Sophos: Identity attacks have overtaken software flaws as entry point of ransomware

Exploited vulnerabilities are no longer the leading cause of ransomware incidents.

By iTnews Asia Team on Aug 13, 2026 12:43PM


Artificial intelligence is rapidly changing the cybersecurity landscape, not by creating entirely new attack techniques, but by making existing ones faster, more scalable and increasingly difficult to detect.

That is one of the key findings from Sophos' latest threat intelligence, which reveals that identity-based attacks have now overtaken software vulnerabilities as the primary entry point for ransomware.

In a briefing with Asia Pacific tech media, Rafe Pilling, Director of Threat Intelligence at Sophos, said modern attacks increasingly span on-premises, cloud and hybrid environments, with AI helping adversaries shorten the time between initial access and business impact.

Citing the State of Ransomware report, Pilling said latest research indicates a significant shift in how ransomware operators gain access to organisations. For the first time in recent years, exploited vulnerabilities are no longer the leading cause of ransomware incidents.

Instead, malicious email has become the leading attack vector, accounting for 26 percent of ransomware attacks, followed by phishing at 24 percent and compromised credentials at 23 percent.

"Four out of five ransomware attacks now begin with identity in one form or another," Pilling said.

He added that two out of three percent ransomware victims reported that the ransomware incident stemmed from what had already become their most significant identity attack.

"Identity is no longer just part of the ransomware story. It is increasingly how ransomware operators are gaining access in the first place."

Pilling added that cybercriminal ecosystems are now heavily centred on stolen credentials, and are reusing compromised accounts.

AI is speeding up familiar attack techniques

While concerns around AI-generated cyber threats continue to grow, Sophos says today's attackers are largely using AI to accelerate familiar techniques rather than invent entirely new ones.

One campaign tracked by the firm also demonstrated how attackers coordinated around a dozen AI agents through a commercial coding assistant to write, test and refine malware against endpoint security products.

According to Pilling, the operation tested nearly 80 malware modules and multiple evasion techniques in what he described as a virtual laboratory.

"The significance isn't necessarily what they built; it's the speed at which they built it. Work that would previously have taken a human operator weeks was completed in a matter of days,” he explained.

The rush to AI is creating a new security risk

As enterprises rush to deploy generative AI and autonomous AI agents, Sophos warns that organisations are simultaneously creating a new category of security risk.

Threat actors are increasingly targeting credentials associated with AI platforms and business applications. Pilling cited incidents where chatbot access tokens were used to compromise enterprise environments, while stolen ChatGPT credentials continue appearing on underground criminal marketplaces.

At the same time, enterprise adoption is moving faster than governance.

Pilling referenced industry research showing that 71 percent of large enterprises are already running AI agents against core business systems, while only 16 percent have governance controls in place.

"As we're on the ground floor of an AI revolution... We're at the perfect point to build in effective governance and security, rather than making it a bolt-on, as has happened with prior technological paradigm shifts,” said Pilling.

Connected defences can improve resilience

While ransomware continues to impose significant costs, Pilling said organisations with stronger security operations are improving their resilience.

The research found:

● Average recovery costs remain around US$1.7 million.

● 56 percent of ransomware attacks still result in data encryption.

● However, ransomware demands have fallen by 65 percent compared with two years ago.

● Actual ransom payments have dropped by 62 percent over the same period.

The company attributes these improvements to better security operations and earlier detection across multiple control points.

"The conclusion here is fairly clear... firewall telemetry on its own has value, but when it's combined with endpoint, email and identity signals through an XDR platform or managed service, organisations are significantly better positioned to stop attacks before encryption occurs,” Pilling said.

Looking ahead, he believes organisations need to rethink how security operations are designed as cyberattacks become increasingly automated and interconnected.

The common thread across everything we're seeing is that attacks are becoming faster, more automated and more capable across multiple parts of an environment at the same time.

- Rafe Pilling, Director of Threat Intelligence, Sophos

As AI continues reshaping both enterprise technology and cybercrime, he argued that future cyber resilience will depend less on deploying more security products and more on building connected security operations capable of seeing and responding to the entire attack chain as one coordinated event.

To reach the editorial team on your feedback, story ideas and pitches, contact them here.
© iTnews Asia
Tags:
security sophos

Related Articles

  • Strategies to mitigate against the real world impact of identity attacks
  • How can the Agentic AI workspace remain secure for APAC organisations?
  • AI-fuelled attacks forcing enterprises to rethink security architecture
  • Malicious AI agents can severely disrupt APAC enterprises
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Strategies to mitigate against the real world impact of identity attacks

Strategies to mitigate against the real world impact of identity attacks

Identity is now the new cybersecurity battlefield

Identity is now the new cybersecurity battlefield

A data-first AI strategy is critical to managing security threats in 2026

A data-first AI strategy is critical to managing security threats in 2026

Malicious AI inputs are creating a new and critical security threat

Malicious AI inputs are creating a new and critical security threat

All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of Lighthouse Independent Media's Privacy Policy and Terms & Conditions.