Almost half of companies — 48 per cent — whose data has been encrypted in a ransomware attack choose to pay the ransom to recover their critical data, according to Sophos' The State of Ransomware 2026, a survey of 2,158 IT and cybersecurity leaders across 17 countries. The four-year average ransom payment rate after encryption now stands at 50 per cent.
Identity compromise overtakes software flaws as the primary attack vector
A significant shift is underway in how ransomware reaches its victims. Malicious emails now account for 26 per cent of ransomware root causes, with phishing close behind at 24 per cent — making identity compromise the dominant delivery mechanism. This marks a stark reversal from the three previous years, when exploited software vulnerabilities held the top spot. Vulnerability exploitation has dropped 14 percentage points year-on-year, falling to just 18 per cent.
MFA alone is no longer enough
The Sophos report makes clear that traditional identity protection safeguards are no longer keeping pace with attacker sophistication. Multi-factor authentication (MFA) was deployed in some capacity in 97 per cent of incidents where compromised credentials were the root cause — yet the attacks still succeeded. Phishing campaigns have grown more selective and technically advanced, bypassing MFA by targeting users at the moment of credential entry rather than attempting to crack authentication systems head-on.
Ransomware actors are moving down the org chart
Ransomware actors are increasingly setting their sights on middle management rather than the C-suite. New research from Zscaler's ThreatLabz unit found that nearly two-thirds of ransomware victims (62 per cent) held managerial titles or above, with an average victim age of 46. Over a single month, ThreatLabz tracked 351 victims spread across 334 organisations, revealing a deliberate and data-driven targeting strategy that prioritises breadth of access over seniority of title.
Mid-level managers carry substantial business access without the same level of security scrutiny applied to executives. As ThreatLabz put it: "The value of a compromised managerial account lies in the breadth of business access associated with the position. Managers may approve payments, oversee budgets and vendors, review contracts, access sensitive records, or co-ordinate work across business units." For ransomware operators, that combination of access and lower scrutiny makes middle managers a high-value, lower-resistance target.
Ransom payments are falling — but remain substantial
There is one piece of good news in the Sophos findings: the median ransom payment has dropped to $769,000, a considerable decline from the $1 million reported the previous year. Almost half (51 per cent) of organisations that paid a ransom also paid less than the initially demanded amount, suggesting that negotiation is increasingly part of the response playbook. Even so, payments of this scale represent a significant financial and reputational cost — and paying does not guarantee full data recovery or prevent future attacks.
