Compromised Credentials drive most Ransomware Attacks as new Cyber Threat groups continue to Emerge

Compromised user credentials remain the leading cause of ransomware attacks, with cybercriminals increasingly exploiting stolen login information to infiltrate corporate networks. According to recent research conducted by cybersecurity firm Sophos, nearly 79% of ransomware incidents originate from compromised credentials. Attackers typically gain unauthorized access by using stolen employee usernames and passwords to enter enterprise systems through vulnerable firewalls, remote access applications, VPNs, system software, and even Internet of Things (IoT) devices.

Once inside a network, threat actors can move laterally, escalate privileges, disable security controls, and deploy ransomware with minimal resistance. This approach has become more effective than relying solely on software vulnerabilities because stolen credentials often allow attackers to appear as legitimate users, making their activities harder to detect. The findings highlight the growing importance of strong password policies, multi-factor authentication (MFA), and continuous monitoring of privileged accounts to reduce the risk of credential-based attacks.

Meanwhile, another study, The Black Kite Ransomware Report 2026, reveals that the ransomware ecosystem continues to expand at a rapid pace. The report notes that a new ransomware group is emerging almost every week, demonstrating how cybercriminals are constantly reorganizing and launching fresh operations. In June 2026 alone, researchers identified 146 active ransomware groups, underscoring the increasing complexity of the global cyber threat landscape.

Despite this surge in new ransomware operators, the report offers a positive insight. More than 70% of newly formed ransomware groups disappear shortly after emerging. Their short lifespan is attributed to several factors, including successful law enforcement actions, internal conflicts among gang members, failed partnerships, financial disputes, and operational challenges. Many of these groups struggle to establish themselves in the highly competitive cybercrime ecosystem, leading to their quick dissolution.

However, while many newcomers fail to survive, well-established ransomware organizations continue to strengthen their operations. Black Kite’s research indicates that these experienced groups are responsible for a growing share of ransomware attacks worldwide. Equipped with sophisticated attack techniques, extensive affiliate networks, and proven extortion strategies, they remain a major concern for businesses and government organizations alike.

Among the most active cybercriminal groups identified in the report is the Qilin ransomware group, which is alleged to have carried out more than 1,358 cyberattacks globally. The group is known for employing advanced extortion tactics that go beyond encrypting victims’ files. In addition to locking critical data, attackers steal sensitive information before encryption, enabling them to conduct double extortion by threatening to leak stolen data if ransom demands are not met. In some cases, they also employ triple extortion, placing additional pressure on victims by targeting customers, business partners, or other stakeholders.

These evolving tactics significantly increase both the financial and reputational impact of ransomware incidents. As attackers continue to refine their methods, organizations must prioritize identity security, strengthen access controls, implement regular security awareness training, and maintain robust backup and incident response strategies. Cybersecurity experts emphasize that preventing credential theft and detecting unauthorized access early remain among the most effective defenses against the growing ransomware threat.

Join our LinkedIn group Information Security Community!

Naveen Goud
Naveen Goud is a writer at Cybersecurity Insiders covering topics such as Mergers & Acquisitions, Startups, Cyber Attacks, Cloud Security and Mobile Security

No posts to display