Analysis of the 2026 Sophos "State of Ransomware" report reveals a fundamental shift in initial access vectors, with identity-based attacks now identified as the root cause in 79% of ransomware incidents. For the first time in four years, exploited vulnerabilities are not the top entry point. Instead, the leading causes are malicious email (T1566.001 - Spearphishing Attachment), phishing (T1566.002 - Spearphishing Link), and compromised credentials (T1078 - Valid Accounts). A critical finding is that in 97% of cases where compromised credentials were the cause, the victim organization had multi-factor authentication (MFA) deployed, suggesting attackers are routinely bypassing or evading these controls. This underscores the urgent need for organizations to move beyond basic MFA and adopt more advanced Identity Threat Detection and Response (ITDR) capabilities.
This data indicates a clear strategic shift by attackers. Instead of searching for a rare zero-day, they are focusing on the much larger and more vulnerable human attack surface. Attackers are becoming more adept at social engineering and technical methods to steal credentials and bypass security controls designed to protect them.
Attackers are successfully bypassing MFA through several methods:
The report highlights that defenders can no longer simply "set and forget" MFA. They must assume that determined attackers can find a way around it.
M1051 - Update Software) while underinvesting in identity security. While patching is crucial, it is no longer sufficient on its own.This is a trend report and contains no specific IOCs.
To detect identity-based attacks and MFA bypass, hunt for:
log_source"MfaDetail": "MFA completed in session" followed by suspicious activity, or sign-ins from geographically impossible locations.event_id500121user_agentotherGreatness PhaaS now offers device code phishing, a new AiTM technique abusing OAuth 2.0 to bypass MFA and steal Microsoft 365 tokens.
The report stresses the need for stronger, phishing-resistant MFA (like FIDO2) over traditional, bypassable methods.
Mapped D3FEND Techniques:
Training users to recognize sophisticated phishing and social engineering attacks is crucial to defend against identity-based threats.
Implementing Identity Threat Detection and Response (ITDR) to analyze user behavior and detect anomalies is key to spotting compromised identities.
Mapped D3FEND Techniques:
The Sophos report's most critical takeaway is that not all MFA is created equal. To counter the trend of MFA bypass, organizations must evolve their D3-MFA (Multi-factor Authentication) strategy. The immediate priority should be to migrate away from phishable MFA methods like SMS and simple push notifications. Instead, organizations must adopt phishing-resistant authenticators, with FIDO2/WebAuthn (using hardware security keys like YubiKeys or platform authenticators like Windows Hello) being the gold standard. This method binds the authentication to the hardware and the origin domain, making it immune to credential theft via adversary-in-the-middle (AiTM) phishing attacks. For services where FIDO2 is not supported, use number matching or other context-aware push notifications as an interim improvement. The finding that 97% of credential breach victims had MFA shows that simply having an MFA checkbox ticked is no longer a valid defense.
Since attackers are successfully bypassing preventative controls like MFA, detection becomes paramount. Organizations need to implement D3-UBA (User Behavior Analysis) through an Identity Threat Detection and Response (ITDR) solution. This involves creating a baseline of normal activity for every user account and alerting on deviations. Key patterns to monitor include: 'impossible travel' logins, access from new or unrecognized devices, unusual frequency of access, and privilege escalations. For example, if a user's account, which has never been used for administrative tasks, suddenly attempts to add a new user to a privileged group, this should trigger a high-severity alert and potentially an automated response, like account suspension. By analyzing behavior patterns, security teams can detect a compromised identity even if the attacker has valid credentials and has bypassed MFA, providing a crucial layer of defense against modern identity-based attacks.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.