news.mlab.sh
Back to the feed
threat-intel

Identity Attacks Overtake Exploits as Top Ransomware Cause

High
Summary

Ransomware attacks are increasingly being delivered through identity-based attacks, specifically malicious emails and phishing, rather than exploiting vulnerabilities in software. Despite widespread deployment of MFA (97% in credential-based attacks), it failed to prevent many breaches, suggesting gaps in MFA implementation and the evolution of bypass techniques. Sophos recommends a shift from patching to identity protection, emphasizing proactive threat detection and response, and a layered defense-in-depth strategy.

Ransomware attacks are increasingly being delivered through identity-based attacks, specifically malicious emails and phishing, rather than exploiting vulnerabilities in software. According to a Sophos report, email attacks overtook vulnerability exploitation as the top ransomware root cause last year. The report, based on a survey of 2,158 IT and cybersecurity leaders, found that 26% of ransomware attacks were delivered via malicious email and 24% via phishing. Despite 97% of victims having MFA deployed when their credentials were compromised, it still wasn't enough to prevent the attacks. The report highlights a significant shift in the ransomware landscape, moving away from traditional vulnerability patching towards a focus on identity protection. Sophos recommends organizations prioritize identity threat detection and response (ITDR), enforce multifactor authentication across all access points, and regularly audit both human and non-human identity credentials. The vendor also suggests a layered defense-in-depth strategy, including using segmentation to slow down attackers and deploying zero-trust network access (ZTNA) to replace legacy VPNs. Chet Wisniewski, director and global field chief information security officer (CISO) at Sophos, notes that the best-performing organizations are practicing ‘aggressive defense-in-depth,’ utilizing multiple layers of security to slow down attackers and trigger threat hunts. The report emphasizes that MFA’s effectiveness hinges on complete deployment and a robust inventorying process, rather than being a standalone solution.

Read the full article at Dark Reading