S annual State of Ransomware report, a vendor-agnostic survey of IT and cybersecurity leaders across 17 countries including the UAE, identifying the impact of ransomware on businesses and how prepared organizations are to defend against them. This year’ s report reveals that globally identity is the dominant initial access vector( IAV), with four in five( 79 %) of ransomware attacks starting with compromised identities. In the UAE, organisations that suffered ransomware attacks reported an average recovery cost of US $ 665,000, highlighting the significant financial impact of these incidents on businesses.
IDENTITY SECURITY
Compromised identities fuel 79 % of ransomware attacks
ophos has released its seventh
S annual State of Ransomware report, a vendor-agnostic survey of IT and cybersecurity leaders across 17 countries including the UAE, identifying the impact of ransomware on businesses and how prepared organizations are to defend against them. This year’ s report reveals that globally identity is the dominant initial access vector( IAV), with four in five( 79 %) of ransomware attacks starting with compromised identities. In the UAE, organisations that suffered ransomware attacks reported an average recovery cost of US $ 665,000, highlighting the significant financial impact of these incidents on businesses.
The prominence of identity attacks in ransomware indicates a shift in method, as attackers increasingly recognise identity as a key component in ransomware delivery. Additionally, for the first time in four years, exploited vulnerabilities are no longer the most common root cause, with malicious email( 26 %) and phishing( 24 %) taking the top spot.
However, exploited vulnerabilities remain a high value target: 59 % of ransom demands that start with an exploited vulnerability on the firewall are for $ 1M or more compared to 48 % of all attacks.
“ As we see ransomware criminals experiment with AI, it has the potential to accelerate their ability to steal valuable assets, hold them hostage and do it at a scale that exceeds their previous capability,” said Ross McKerchar, Chief Information Security officer, Sophos.“ This speed requires careful round-the-clock monitoring of the most exploited means of entry, which our data shows to be stolen and compromised valid accounts. However, the improvement of unguarded open-weight AI models will give attackers a growing advantage in finding and exploiting software vulnerabilities. Defenders cannot rely on patching alone to keep pace, so reducing external exposure and maintaining strong endpoint protection is essential.”
The report also found that, out of the organisations hit by ransomware, 56 % had their data encrypted, an increase which has reversed a two-year downward trend.
Additional global findings highlight:
• Two-thirds of ransomware victims( 67 %) confirmed their ransomware incident was also their most significant identity attack, establishing identity compromise as a primary ransomware delivery mechanism.
• Over half of ransomware attacks( 56 %) succeeded in encrypting data, including 16 % where data was both encrypted and stolen. That success rate is up from 50 % in 2025, but below the 75 % peak in 2023. In comparison, 38 % of ransomware attacks in the UAE resulted in data encryption, including 13 % where data was both encrypted and stolen.
Ross McKerchar, Chief Information Security officer, Sophos
For the first time in four years, exploited vulnerabilities are no longer the most common root cause.
• When data is encrypted, attackers have a 50-50 chance of receiving a ransom payment. 48 % of organisations whose data was encrypted paid the ransom, bringing the four-year average payment rate to 50 %.
• Only 34 % of small organisations( 100 – 250 employees) stopped attacks before encryption or extortion. This is significantly behind 3,001 – 5,000 employee organisations that stopped attacks 46 % of the time.
• Multi-factor authentication( MFA) was deployed in some capacity for 97 % of incidents where compromised credentials were the root cause of the ransomware attacks, making clear that MFA alone is not enough to stop ransomware, and that coverage gaps create exposure.
• The UK saw the highest median ransom demand recorded for any country at $ 2.5 million.
While organisations face prevention challenges as threat actors evolve their techniques, significant progress has been made to improve their ability to recover. Increased investment in backup infrastructure has likely contributed to organisations recovering faster following a ransomware attack; over half( 55 %) of organisations manage to do so within one week, and 16 % in less than a day.
30 WWW. INTELLIGENTCISO. COM / MIDDLE-EAST