Skip to main content

Cybersecurity statistics / Multi-Factor Authentication

Multi-factor authentication (MFA) is missing where it matters in 59% of IR and MDR cases.

PublisherSophos
ReportThe State of Ransomware 2026
Published15 July 2026
TopicsMulti-Factor Authentication, Identity

Published by Sophos in The State of Ransomware 2026, 15 July 2026. The figure is taken from the report as published; the full methodology is in the source.

View the original report

Related statistics

97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.
Sophos, 18/07/2026
Session hijacking incidents increased by 23% over a 180-day period.
Guardz, 27/05/2026
Compromised credentials accounted for 23% of ransomware incidents.
Sophos, 18/07/2026
67% of ransomware victims confirmed their ransomware incident was the same event as their most significant identity attack.
Sophos, 18/07/2026
67% of root causes across 661 incident response and managed detection and response (MDR) cases are identity-related.
Sophos, 18/07/2026
79% of ransomware attacks start with an identity-based approach.
Sophos, 18/07/2026

Get the newsletter

Weekly cybersecurity statistics by email.