Compromised user credentials remain the leading cause of ransomware attacks, with cybercriminals increasingly exploiting stolen login information to infiltrate corporate networks. According to recent research conducted by cybersecurity firm Sophos, nearly 79% of ransomware incidents originate from compromised credentials. Attackers typically gain unauthorized access by using stolen employee usernames and passwords to enter enterprise systems through vulnerable firewalls, remote access applications, VPNs, system software, and even Internet of Things (IoT) devices. Once inside a network, threat actors can move laterally, escalate privileges, disable security controls, and deploy ransomware with minimal resistance. This approach has become more effective than relying solely on software vulnerabilities because stolen credentials often allow attackers to appear as legitimate users, making their activities harder to detect. The findings highlight the growing importance of strong password policies, multi-factor authentication (MFA), and continuous monitoring of privileged accounts to reduce the risk of credential-based attacks. Meanwhile, another study, The Black Kite Ransomware Report 2026, reveals that the ransomware ecosystem continues to expand at a rapid pace. The report notes that a new ransomware group is emerging almost every week, demonstrating how cybercriminals are constantly reorganizing and launching fresh operations. In June 2026 alone, researchers identified 146 active ransomware groups, underscoring the increasing complexity of the global cyber threat landscape. Despite this surge in new ransomware operators, the report offers a positive insight. More than 70% of newly formed ransomware groups disappear shortly after emerging. Their short lifespan is attributed to several factors, including successful law enforcement actions, internal conflicts among gang members, failed partnerships, financial disputes, and operational challenges. Many of these groups struggle to establish themselves in the highly competitive cybercrime ecosystem, leading to their quick dissolution. However, while many newcomers fail to survive, well-established ransomware organizations continue to strengthen their operations. Black Kite’s research indicates that these
Compromised Credentials drive most Ransomware Attacks as new Cyber Threat groups ...
Read the original article
cybersecurity-insiders.com →