97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.
| Publisher | Sophos |
| Report | The State of Ransomware 2026 |
| Published | 15 July 2026 |
| Topics | Multi-Factor Authentication, Identity |
Published by Sophos in The State of Ransomware 2026, 15 July 2026. The figure is taken from the report as published; the full methodology is in the source.