Identity-related weaknesses were responsible for 67 per cent of cyber security incidents investigated last year, as attackers increasingly exploited compromised credentials and weak authentication systems, according to a new report by cyber security firm Sophos.
The findings were published in the 2026 Sophos Active Adversary Report, which analysed incidents handled by Sophos Incident Response (IR) and Managed Detection and Response (MDR) teams.
The report said attackers are shifting away from exploiting technical vulnerabilities and are increasingly relying on stolen credentials, brute-force attacks and weak identity protection systems to gain access to networks.
It found that compromised credentials, weak or missing multi-factor authentication (MFA) and poorly protected identity infrastructure remain major entry points for cyber attackers.
Although the median dwell time — the period attackers remain undetected in a network — declined to three days, attackers are moving faster within networks and often reach Active Directory systems within hours of gaining access.
The report also found that ransomware deployment and data exfiltration frequently occur outside business hours when monitoring is weaker.
Inadequate log retention and missing telemetry further weaken organisations’ ability to detect and respond to cyber threats, the report said.
Sophos researchers also observed the highest number of active threat groups recorded in the report’s history.
Among ransomware operations, Akira and Qilin were identified as the most active brands, with Akira involved in 22 per cent of incidents analysed.
The report identified 51 ransomware brands across investigated cases, including 27 previously known groups and 24 newly emerging ones.
Only four ransomware brands or attack techniques — LockBit, MedusaLocker, Phobos and abuse of BitLocker — have consistently appeared in incidents since 2020.
Despite growing interest in artificial intelligence in cybercrime, the report found no evidence that generative AI has fundamentally changed attacker behaviour.
However, it noted that AI tools have made phishing and social engineering attacks faster and more sophisticated.
Based on the findings, Sophos advised organisations to strengthen security measures by deploying phishing-resistant MFA, reducing exposure of identity infrastructure, patching known vulnerabilities promptly and maintaining continuous security monitoring.
The report also stressed the importance of preserving security logs to support faster detection and investigation of cyber incidents.





