Ransomware attacks are accelerating and changing the way criminals target victims, according to recent security research. Instead of relying mainly on software vulnerabilities, criminal groups are now focusing more on identity-based attacks—using stolen passwords and compromised accounts to break into company networks.
This shift represents a major change in how ransomware gangs operate. Previously, hackers would search for unpatched software flaws and zero-day vulnerabilities to gain entry into computer systems. Now, researchers have found that attacking user identities and access credentials has become the top method ransomware groups use to establish footholds in target organizations.
The change matters because it means companies need to defend themselves differently. Instead of just keeping software up to date, organizations must focus more heavily on protecting passwords, implementing stronger authentication systems, and monitoring for suspicious account activity.
Recent incidents highlight these shifting tactics. Security researchers documented how the Inc ransomware gang exploited previously unknown vulnerabilities in SonicWall SMA appliances—devices that companies use to allow remote workers secure access to their networks. However, this represents just one example of ongoing threats in the broader landscape.
The criminal organization known as "The Gentlemen" represents another example of organized ransomware operations that continue to evolve their methods. These groups operate as structured criminal enterprises, constantly adapting their techniques to bypass security defenses and maximize their profits from ransom payments.
Notably, security experts emphasize that the acceleration in ransomware attacks is not primarily driven by artificial intelligence technology, despite widespread concerns about AI-powered threats. Instead, the growth stems from improved criminal organization, better targeting methods, and the continued vulnerability of identity-based access systems across organizations.
The trend creates serious challenges for companies of all sizes. Small and medium-sized businesses often struggle with identity protection because it requires ongoing attention and investment in tools like multi-factor authentication and password managers. Larger organizations face complexity managing millions of user accounts across distributed systems.
Cybersecurity professionals recommend that organizations prioritize identity protection by enforcing strong password policies, enabling multi-factor authentication, monitoring for unusual login attempts, and training employees to recognize social engineering attacks that target credentials. Companies should also maintain regular backups of critical data and develop incident response plans.
As ransomware groups continue evolving their tactics, the security industry expects identity-based attacks to remain the dominant entry method for years to come, making credential protection a top priority for any organization seeking to defend against these costly attacks.