Identity Attacks Overtake Exploits as Top Ransomware Cause
Identity-based attacks have displaced exploits as the leading ransomware entry point, and legacy MFA—deployed in 97% of credential attacks—failed to prevent compromise, highlighting an industry-wide authentication gap.
Summary written by editorial AI · Source link below
Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.
Editorial Analysis
If MFA is present in nearly all credential attacks yet still fails, European enterprises relying on legacy MFA for NIS2 and DORA compliance face both regulatory and operational risk.
Accelerate migration from legacy MFA to phishing-resistant authentication (FIDO2/passkeys) and implement continuous identity-threat detection.
Ransomware attackers now favour stolen credentials over software exploits, and conventional MFA is failing—phishing-resistant authentication must become a board-level priority.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.
More from the Security Desk
- Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted2d
- IDScan sued over alleged data breach affecting 153 million drivers3d
- Your Employee’s Password Appeared in an Infostealer Log. Now What?4d
- US and Canadian court data exposed in Thomson Reuters breach4d
- Health data of more than 9.5 million people leaked from Aesto record system5d