
According to Sophos's seventh annual State of Ransomware report, 79% of ransomware attacks now originate from compromised identities, marking a fundamental shift in attack methodology. This represents a significant departure from the traditional vulnerability-based approach, as cybercriminals increasingly prioritise malicious emails and phishing campaigns over exploited software weaknesses. The report, based on surveys of 2,158 IT and cybersecurity decision-makers across 17 countries including India, reveals that identity is now the dominant initial access vector for ransomware attacks. In the UAE specifically, organisations that suffered ransomware attacks reported an average recovery cost of US$665,000, highlighting the significant financial impact of these incidents on businesses. However, the latest Sophos report reveals an even more concerning trend - 97% of organizations compromised through stolen credentials already had multi-factor authentication (MFA) enabled, suggesting attackers are increasingly bypassing MFA through phishing-resistant weaknesses, session hijacking, adversary-in-the-middle attacks, or incomplete deployment of stronger authentication methods such as FIDO2 security keys.
According to Kaspersky's latest data, ransomware detections among Indian small and medium businesses increased from 3.18% in Q1 2025 to 4.07% during the same period in 2026. As reported by Business Standard, Jaydeep Singh, General Manager for India at Kaspersky, noted that these detection numbers likely understate the real exposure since they only capture the final encryption stage of attacks, not earlier stages like initial access or lateral movement. The actual threat could be significantly larger than these statistics suggest, as many attacks are caught in time before reaching the encryption phase. The surge in attacks is driven by two converging factors - the rapid expansion of India's digital economy has made small businesses increasingly reliant on cloud applications, connected manufacturing systems, digital payments and online supply chains, while the growing sophistication of the ransomware ecosystem has lowered the technical barrier for launching attacks and attracted more cybercriminal groups into the ecosystem.
Symantec's Threat Hunter Team recently uncovered a new ransomware family called GodDamn, first detected in May 2026, highlighting the evolution of modern ransomware tactics. Rather than introducing sophisticated encryption techniques, the malware stands out for its ability to disable security protections before launching its ransomware payload. At the heart of the campaign is PoisonX, a malicious kernel-level driver carrying a valid Microsoft digital signature. Unlike traditional "Bring Your Own Vulnerable Driver" (BYOVD) attacks that abuse legitimate drivers, PoisonX is believed to have been specifically created for malicious purposes while still obtaining a trusted signature. This enables it to bypass Windows security mechanisms and operate with elevated privileges. During an attack investigated by Symantec, threat actors deployed PoisonX alongside a fake symantec.exe file to disable Microsoft Defender. They then leveraged tools such as PsExec and AnyDesk to move laterally across the network, establishing persistent access to multiple systems several days before deploying the ransomware. Researchers also found that PoisonX is now being shared among other ransomware groups, indicating wider adoption of this attack technique.
According to Kaspersky's SMB Threat Report, attacks disguised as popular AI services surged nearly five-fold during the first four months of 2026 compared with the same period last year. More than 33,300 such attacks targeted SMBs, while globally researchers detected over 92,000 malware attacks disguised as AI agents and services, with fake ChatGPT installers accounting for roughly half. Singh explained that attackers are exploiting growing trust in AI tools faster than SMBs are learning to question it, making recognising fake AI applications as important as identifying phishing emails as businesses integrate AI tools into everyday operations.
Despite increasingly sophisticated ransomware campaigns, Singh believes the biggest weaknesses among Indian SMBs remain surprisingly basic. Many Indian SMBs still lack dedicated security teams, structured patch management, and reliable backup strategies, with many businesses continuing to believe backups alone provide adequate protection. The other recurring blind spot is visibility into outbound traffic and lateral movement, as most SMB security investment still goes toward basic endpoint protection rather than the detection and response layer needed to catch attacks before final encryption. Additionally, more than 83% of Indian organisations are yet to begin comprehensive DPDP implementation, leaving many SMBs unprepared for both security and regulatory fallout of an incident. However, the latest Sophos report shows 55% of organisations manage to recover within one week following a ransomware attack, with 16% recovering in less than a day, indicating improved recovery capabilities despite persistent security gaps. The message for defenders is clear - vulnerability management and patching remain essential, but they are no longer enough. Organizations must strengthen identity security through phishing-resistant authentication, continuously monitor privileged access, detect unauthorized driver installations, restrict remote administration tools, and adopt behavioral analytics capable of identifying suspicious activity even when attackers appear to be legitimate users.