Identity Attacks Overtake Exploits as Top Ransomware Cause
Identity-based attacks have displaced exploits as the leading ransomware entry point, and legacy MFA—deployed in 97% of credential attacks—failed to prevent compromise, highlighting an industry-wide authentication gap.
Summary written by editorial AI · Source link below
Email attacks overtook exploits as the top ransomware root cause last year. Multifactor authentication (MFA) was deployed in 97% of credential-based attacks but failed to prevent compromise.
Editorial Analysis
Framed for the Compliance & GRC desk
NIS2 and DORA mandate appropriate access-control measures; evidence that standard MFA fails 97% of the time when targeted challenges the adequacy of current controls.
Document MFA bypass risk in your risk register and update access-control policies to require phishing-resistant MFA for NIS2/DORA compliance.
Ransomware attackers now favour stolen credentials over software exploits, and conventional MFA is failing—phishing-resistant authentication must become a board-level priority.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Dark Reading in a new tab.