Vulnerabilities used to be ransomware’s favorite way in. Now it’s your inbox. And even organizations with MFA aren’t safe.


by Tim Leogrande, BSIT, MSCP, Ed.S.

🗓  AUG 20 2026 • 3 MIN READ

📰  NEWS


Email attacks surpassed vulnerability exploits as the leading cause of ransomware during the past year. Even though multi-factor authentication (MFA) was in use in 97% of the credential-based attacks, it didn't stop the ransomware, according to Sophos. Its State of Ransomware 2026 report includes a survey of 2,158 IT and cybersecurity leaders across 17 countries who work in organizations that fell prey to ransomware.

There are a lot of interesting takeaways: 56% of ransomware attacks resulted in successful encryption of victim networks, and ransom demands and payments declined. Malicious emails (26%) and phishing (24%) have overtaken vulnerability exploitation as the leading cause of ransomware, ending a three-year run in which vulnerabilities held the top spot (now down to 18% from 32%). In fact, 67% of respondents reported that their latest ransomware attack was also their worst identity attack during the past year.

Since phishing and malicious email now account for half of all ransomware root causes, organizations need to use advanced email filtering, enforce DMARC/DKIM/SPF, and roll out regular phishing training. The increase in email attacks shows that fixing vulnerabilities isn't enough on its own to protect an organization. The third most prevalent source of ransomware was also tied to identity, as the abuse of stolen credentials accounted for 23% of ransomware cases.

<aside> 💡

The big takeaway is that organizations relied on MFA 97% of the time when the ransomware was delivered via compromised credentials.

</aside>

One-time passwords, push-based applications, and passkeys were the most common secondary authentication methods. FIDO2 tokens, the industry standard for phishing-resistant authentication, were the fourth most commonly used MFA method.

The fact that such a high proportion of ransomware victims had MFA in place when they were attacked implies that it wasn’t fully implemented everywhere, so attackers could still find a way in. It also indicates that although MFA is still a key component of successful cybersecurity, it alone will not be enough to prevent credential attacks since attackers are finding new ways around it.

<aside> 💡

Organizations should prioritize identity threat detection and response (ITDR), mandate MFA for all accounts, and regularly audit credentials. The research doesn't single out any specific form of MFA as the culprit. This indicates the issue might not be MFA per se, but instead the lack of complete rollout or even adequate tracking.

</aside>

The most effective approaches rely on advanced defense in depth, a security strategy that uses multiple layers of controls to protect assets. Each layer, even if it's not foolproof, slows things down or raises an alert, which can help flag the intrusion. Most often, this is accomplished through network segmentation to impede attacker movement, the use of zero-trust network access (ZTNA) to substitute for legacy VPNs to limit app exploits, and around-the-clock threat monitoring and response.

These best practices mirror the advice given to businesses worried about the attack vectors introduced by the rise of AI-driven cybercrime platforms.


© 2026 Tim Leogrande. The opinions expressed herein are solely those of the author and don’t necessarily reflect the views, policies, or positions of any affiliated organizations or individuals.