Source: Dark Reading
Author: Alexander Culafi
URL: https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause
ONE SENTENCE SUMMARY:
In 2025, email became ransomware’s leading entry vector, while MFA commonly existed yet still allowed credential-based compromises too often throughout.
MAIN POINTS:
- Email-based intrusions surpassed software exploits as ransomware’s primary root cause.
- Credential attacks frequently encountered MFA, indicating broad deployment across organizations.
- MFA presence alone did not stop account compromise in most credential-driven incidents.
- Attackers likely bypassed MFA using tactics like phishing, push fatigue, or session theft.
- Email security controls remain critical for preventing initial access and ransomware escalation.
- Reliance on MFA without additional hardening creates a false sense of protection.
- Compromised credentials can enable lateral movement, privilege escalation, and data encryption.
- Monitoring for suspicious logins and mailbox rule changes helps detect email-led compromises.
- Strong authentication methods (FIDO2, phishing-resistant MFA) reduce bypass opportunities.
- Incident trends suggest prioritizing user training, email filtering, and identity defenses together.
TAKEAWAYS:
- Treat email as the top ransomware gateway and prioritize layered email protections.
- Prefer phishing-resistant authentication over basic MFA to meaningfully reduce credential compromise.
- Add conditional access, device posture checks, and session management to strengthen identities.
- Improve detection around email accounts, including anomalous sign-ins and forwarding rules.
- Combine technical controls with security awareness to counter social engineering-driven ransomware entry.