By Juliet Umeh

A new report by global cybersecurity leader Sophos shows that identity-related attacks continue to dominate the threat landscape, accounting for 67 per cent of all security incidents investigated by Sophos in 2025.

The 2026 Sophos Active Adversary Report reveals that attackers are increasingly exploiting stolen credentials, weak or missing multifactor authentication, MFA, and poorly protected identity systems to gain access, often without deploying new tools or techniques. Brute-force attacks now rival traditional vulnerability exploits as a primary method for initial access.

John Shier, Field CISO at Sophos and lead author of the report, said: “The dominance of identity-related root causes has been years in the making. Organizations must take a proactive approach to identity security to prevent breaches.”

The study also highlights how attackers are moving faster once inside networks, reaching Active Directory servers in just 3.4 hours on average. Ransomware attacks remain largely an off-hours activity, with 88 per cent deployed outside normal working hours.

Sophos noted the highest number of active threat groups in the report’s history, with 51 ransomware brands observed. While AI is improving the speed and sophistication of phishing attacks, it has not yet created fundamentally new techniques.

To defend against these threats, Sophos recommends deploying phishing-resistant MFA, reducing exposure of identity systems, ensuring 24/7 monitoring, patching vulnerabilities promptly, and preserving security logs for rapid detection.

The report analyzed 661 cases across 70 countries and 34 industries, underscoring the global reach and urgency of identity-focused cybersecurity measures.

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.