
FOUR in five ransomware attacks today start the same way: with someone’s identity, not their servers.
That’s the headline finding from Sophos’ seventh annual State of Ransomware report, released this week, and it’s the kind of number that should worry anyone still treating ransomware as a purely technical problem. Of the attacks tracked in the report, 79 percent started with a compromised identity — a stolen password, a hijacked session or a login purchased on a criminal marketplace. Exploited software vulnerabilities had been the leading cause of ransomware attacks for three consecutive years. Not this year. Malicious email (26 percent) and phishing (24 percent) overtook exploited vulnerabilities as the most common entry points, while exploited vulnerabilities fell from 32 percent last year to 18 percent.
The survey, conducted by Vanson Bourne on Sophos’ behalf, polled 2,158 IT and cybersecurity leaders across 17 countries whose organizations had been hit by ransomware during the past year. The Philippines was not among them, but a separate Philippine report points to the same trend. Check Point’s Philippine Threat Landscape Report 2025, cited by the Philippine Star in February, found that ransomware attacks in the country nearly doubled, from nine in 2024 to 17 in 2025, while phishing websites surged 423 percent. Ritchelle Santos, a senior cyber threat intelligence analyst at Check Point, likewise identified identity, trust and mobile channels as “the new battleground.” What the Sophos data add is scale: Two-thirds of ransomware victims, or 67 percent, said the ransomware incident and their most significant identity attack were the same event.
Ross McKerchar, Sophos’ chief information security officer, framed the shift as a race that is only getting faster. Attackers, he said, are experimenting with artificial intelligence to “steal valuable assets, hold them hostage” at a pace beyond what they could manage before. McKerchar’s broader point, echoed in the report’s discussion of frontier AI, is that open-weight AI models are lowering the level of skill needed to find and exploit weaknesses, meaning defenders can no longer treat patching as their primary line of defense.
There’s a catch, though, and the report doesn’t bury it. Ninety-seven percent of incidents involving stolen credentials affected organizations that already had multi-factor authentication (MFA) enabled, in some form at least. That’s worth pausing on. The advice everyone in security keeps repeating — “just turn on MFA” — isn’t wrong. It just isn’t enough on its own. As for how attackers bypass it, the report doesn’t really say. It says only that the methods keep changing and that MFA coverage tends to have more gaps than organizations assume. For any Philippine company that treated its MFA rollout as a box already checked, this may be the report’s most important finding.
The report is not all bad news. The median ransom demand fell to $698,000 this year, a decline of 65 percent over two years, while the median payment came to $769,000. Victims are getting better at pushing back. Just over half paid less than the amount originally demanded. Backup-based recovery rose to 66 percent of encrypted-data cases, up from 54 percent last year, suggesting organizations are investing in tested, offline backups instead of hoping a ransom payment will restore their files. Recovery times also improved. More than half of victims, 55 percent, were back up and running within a week.
What has not improved is the toll on the people doing the defending. Ninety-nine percent of organizations whose data were encrypted said the attack directly affected their IT or cybersecurity teams, most commonly through anxiety about the next attack and pressure from senior leaders. More than one in five said their team’s leadership was replaced afterward. One figure moved in the right direction: recognition from senior leadership rose to 36 percent from 31 percent last year, suggesting that at least some executives are beginning to treat a breach as a resourcing problem rather than someone’s personal failure.
Where does that leave a Philippine business reading this over coffee on a Sunday? The report’s recommendations apply regardless of geography: audit every account with access to sensitive systems, not just the obvious ones; ensure MFA covers every entry point rather than most of them; and test backups before a crisis forces the issue. Firewalls still matter. The report found that 61 percent of victims had their firewall detect the attack before ransomware was deployed, and those organizations experienced markedly better outcomes than the 7 percent whose firewall failed to detect the attack — 50 percent encryption versus 71 percent.
A stolen password does not announce itself the way an unpatched server does. And an employee who clicks a convincing email is not a vulnerability that can be fixed with an update. It is a decision made in three seconds on a Monday morning by someone who has done the same thing safely a thousand times before. Securing that decision takes more than software. It takes an organization that has decided the person clicking the link is worth protecting, not blaming.
