Identity Attacks Overtake Exploits as Top Ransomware Cause

Source: Dark Reading

Author: Alexander Culafi

URL: https://www.darkreading.com/identity-access-management-security/identity-attacks-overtake-exploits-top-ransomware-cause

ONE SENTENCE SUMMARY:

In 2025, email became ransomware’s leading entry vector, while MFA commonly existed yet still allowed credential-based compromises too often throughout.

MAIN POINTS:

  1. Email-based intrusions surpassed software exploits as ransomware’s primary root cause.
  2. Credential attacks frequently encountered MFA, indicating broad deployment across organizations.
  3. MFA presence alone did not stop account compromise in most credential-driven incidents.
  4. Attackers likely bypassed MFA using tactics like phishing, push fatigue, or session theft.
  5. Email security controls remain critical for preventing initial access and ransomware escalation.
  6. Reliance on MFA without additional hardening creates a false sense of protection.
  7. Compromised credentials can enable lateral movement, privilege escalation, and data encryption.
  8. Monitoring for suspicious logins and mailbox rule changes helps detect email-led compromises.
  9. Strong authentication methods (FIDO2, phishing-resistant MFA) reduce bypass opportunities.
  10. Incident trends suggest prioritizing user training, email filtering, and identity defenses together.

TAKEAWAYS:

  1. Treat email as the top ransomware gateway and prioritize layered email protections.
  2. Prefer phishing-resistant authentication over basic MFA to meaningfully reduce credential compromise.
  3. Add conditional access, device posture checks, and session management to strengthen identities.
  4. Improve detection around email accounts, including anomalous sign-ins and forwarding rules.
  5. Combine technical controls with security awareness to counter social engineering-driven ransomware entry.