Seven in every 10 (71%) of organisations globally suffered at least one identity-related breach in the past year, and on average organisations reported three separate incidents, according to Sophos.
This is based on a vendor-agnostic survey conducted in the first quarter of 2026 which covered 5,000 IT and cybersecurity leaders across 17 countries, including the United States, the United Kingdom, Germany, France, Australia, Japan, India, Brazil and Singapore, in organisations with 100 to 5,000 employees across 14 industries.
The survey found that identity attacks are rarely one-off events with repeat victimisation reaching a notable level, with 5% of global respondents reporting six or more breaches. These attacks are driven primarily by human error and weak management of non-human identities (NHIs), a challenge that is accelerating rapidly as agentic AI accelerates attack processes.
Two thirds of the ransomware victims (67%) responding to this survey confirmed their ransomware incident stemmed from an identity attack, establishing identity compromise as a primary delivery mechanism for ransomware. Sophos X-Ops researchers have observed this consistently over the past year.
The financial consequences are steep: the mean recovery cost reached US$1.64 million, with a median of US$750,000, and 73% of those affected faced costs of $250,000 or more.
Read Full Article At Source





