Sophos published its State of Ransomware 2026 report this week, based on responses from 2,158 IT and cybersecurity leaders across 17 countries whose organisations were hit by ransomware in the past year — and the headline number should worry any UK business owner who thinks “we’ve got MFA” means the login problem is solved. For the first time in four years, exploited software vulnerabilities are no longer the leading way ransomware gangs get in. Malicious email and phishing now top the list, and compromised credentials are close behind — together making stolen or tricked-out identity the starting point for 79% of all ransomware attacks. The UK, notably, recorded the highest median ransom demand of any country in the survey: $2.5 million.
The uncomfortable detail buried in that data is this: in cases where compromised credentials were the root cause, multi-factor authentication was already deployed in some form 97% of the time. The attackers got in anyway. MFA didn’t fail because businesses skipped it — it failed because switching it on isn’t the same as switching it on correctly, everywhere, for everyone.
Why “we have MFA” isn’t the reassurance it sounds like
There’s a specific reason this keeps happening: MFA rollouts routinely have gaps. A legacy admin account exempted “temporarily” during setup and never revisited. A third-party contractor login that predates the policy. A weaker SMS-based factor left in place because a senior team member found the authenticator app fiddly. Attackers don’t need every account protected — they need one that isn’t, and modern phishing kits are specifically built to harvest session tokens and one-time codes in real time, bypassing MFA that isn’t of the phishing-resistant kind.
This matters more for small businesses than it might first appear. Larger organisations tend to have IT teams whose job includes auditing MFA coverage for exactly these gaps. Smaller businesses more often set MFA up once, consider the job done, and move on — which is exactly the pattern this data suggests attackers are exploiting.
Closing the gap without an enterprise security budget
Start by checking coverage, not just existence: is MFA actually enforced on every account with access to email, finance systems, or customer data — including admin, shared, and third-party accounts, not just the ones staff log into daily? Where possible, move from SMS or app-code MFA to phishing-resistant methods like passkeys or hardware security keys for anyone with elevated access, since these can’t be phished the same way a six-digit code can.
Beyond that, the honest answer is that prevention alone won’t get you to zero — which is why detecting an intrusion quickly, rather than assuming it can’t happen, matters as much as the MFA policy itself. KeepSafe is built for exactly that gap, giving SMEs ongoing monitoring so a compromised login gets caught early rather than discovered when the ransom note appears. And if your current systems were set up ad hoc rather than properly configured, CoolCoding can audit and rebuild the technical foundations — including MFA enforcement — so the coverage gaps this report describes don’t exist in your setup in the first place.
The takeaway
If your business considers its login security handled because MFA is switched on somewhere, this week’s data is a prompt to check that assumption properly: audit every account with access to something valuable, close the exceptions, and move your highest-risk logins to phishing-resistant MFA. The gap between “we have MFA” and “we’re actually protected” is exactly where 2026’s ransomware attacks are getting in.