In India, ransomware begins with stolen identities
More than four in five ransomware attacks in India start with a compromised identity, according to Sophos's seventh annual State of Ransomware report
And more firms pay up than the global average
More than four in five ransomware attacks in India now start with a compromised identity rather than a technical flaw, according to Sophos's seventh annual State of Ransomware report: and when Indian organisations are hit, they pay the ransom more often than their global peers.
The report found that 81% of ransomware attacks in India began with stolen or compromised identities, ahead of the 79% global average. Malicious email (28%) and phishing (26%) together now account for more than half of all attacks, while exploited software vulnerabilities, long the classic entry point, have fallen to just 11%.
"Attackers are no longer breaking down the door, they're using stolen keys," said Sunil Sharma, managing director for India and SAARC at Sophos, adding that as AI lowers the cost of large-scale phishing and credential theft, Indian firms should treat identity as their primary line of defence.
The financial findings are more uncomfortable. Of the Indian organisations that had data encrypted (60%, against 56% globally), 56% paid the ransom to recover it, well above the 48% global rate. The average cost of rectifying an attack in India was USD 1.11 million, below the USD 1.7 million global figure, though the report noted 67% of firms restored from backups rather than paying.
One finding cuts against conventional wisdom: multi-factor authentication was already in place at 98% of Indian organisations breached through compromised credentials, underlining that MFA alone does not close the gap when its coverage is incomplete.
Diwakar Dayal, managing director & area vice president, SentinelOne India & SAARC
"While multi-factor authentication remains a critical security control, it is no longer sufficient on its own. Attackers are using techniques such as session hijacking, token theft, and MFA fatigue attacks to bypass traditional authentication mechanisms. This is why organisations need to move beyond static identity verification and adopt continuous monitoring in real time"
Dayal was more circumspect on why Indian firms pay more often, declining to engage with the payment decision itself and arguing the priority should instead be reducing the chance that attackers gain or keep access at all. He attributed the wider shift to the economics of intrusion: stolen credentials are a faster and more reliable route in than hunting for software bugs, and generative AI has made convincing phishing emails, fake login pages and impersonation campaigns cheap to produce at scale.
A second survey published on 23 July supports that reading, and is blunter about payment. Proofpoint's 2026 AI-Era Ransomware Report, based on 953 security professionals across 12 countries surveyed in March and April, found 62% of affected Indian organisations said AI had made the attack against them more effective. It put the share of affected Indian firms that paid at 64%, against 54% globally (again above the international average), and found that 48% of Indian payers were hit with a further demand afterwards. Data was stolen in 71% of Indian incidents, though on the narrower measure of confirmed sensitive-data theft the figure was 33%. India also recorded one of the highest rates in the study of employees interacting with malicious content, alongside Japan and Singapore. Proofpoint does not disclose how many of its respondents were Indian, or how many of those had been attacked, so its India figures rest on a narrower base than the Sophos data.
Sophos has since put a figure on the speed at which AI-assisted attackers now operate. Its AI Security 2026 report, released on 22 July, describes a campaign its researchers track as STAC6994 in which a threat actor ran roughly a dozen AI agents inside a customer's network to write and test attacks against endpoint security products, producing close to 80 modules and more than 70 evasion techniques, work the company says would have taken a human weeks. The same report flags a newer exposure that maps onto SentinelOne's token-theft warning: OAuth tokens, AI service credentials and developer tools are themselves becoming targets, making enterprise AI adoption an identity and governance problem rather than only a model-security one.
There was better news on recovery. Helped by investment in backup infrastructure, 58% of affected Indian firms recovered within a week and 14% within a day. Compliance is also climbing the agenda, with DPDP Act readiness now a stated priority for nearly a third of Indian organisations, the Sophos report said. That deadline is no longer distant: the Consent Manager framework is due around November and full compliance with the DPDP Rules is required by 13 May 2027, carrying penalties of up to INR 250 crore per contravention.
The India findings are drawn from 500 IT and cybersecurity decision-makers surveyed by Vanson Bourne for Sophos in the first quarter of 2026, part of a 17-country study; 240 of those Indian organisations had been hit by ransomware in the previous year. As with any vendor-commissioned research, the figures come from companies that sell security software; Sophos describes its survey as vendor-agnostic, and SentinelOne, like Sophos, sells the identity and endpoint protection its comment recommends.