Identity Attacks Overtake Exploits as Top Ransomware Cause
Identity-based attacks have displaced exploits as the leading ransomware entry point, and legacy MFA—deployed in 97% of credential attacks—failed to prevent compromise, highlighting an industry-wide authentication gap.
Summary written by editorial AI · Source link below
Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.
Editorial Analysis
If MFA is present in nearly all credential attacks yet still fails, European enterprises relying on legacy MFA for NIS2 and DORA compliance face both regulatory and operational risk.
Accelerate migration from legacy MFA to phishing-resistant authentication (FIDO2/passkeys) and implement continuous identity-threat detection.
Ransomware attackers now favour stolen credentials over software exploits, and conventional MFA is failing—phishing-resistant authentication must become a board-level priority.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.