Report by Sophos
The State of Identity Security 2026
Key Findings
67% of ransomware victims confirmed their ransomware incident stemmed from an identity attack.
Human error (employees tricked into providing credentials) was cited in nearly 43% of identity incidents.
Organizations with weak NHI management pay approximately $150,000 more to recover from incidents than average.
Organizations with weak NHI management are 22% more likely to experience financial theft.
71% of organizations suffered at least one identity-related breach in the past year.
Organizations reported an average of three separate identity-related incidents.
10% of organizations reported an identity breach that impacted their business in the last year.
Weak non-human identity (NHI) management was cited in 41% of identity incidents.
One-third of organizations regularly rotate or audit service accounts and non-human identities, while just 11% do so continuously.
Mean recovery cost for identity-related incidents reached $1.64 million, with a median of $750,000, and 73% of affected organizations facing costs of $250,000 or more.
When identity breaches impact business, the primary consequences are data theft (49%), ransomware (48%), and financial theft (47%).
Only 24% of organizations continually monitor for unusual login attempts.
14% of breached organizations cannot detect and stop their most significant identity attack before damage is done.
Energy, oil/gas, and utilities reported an 80% breach rate and federal/central government report a 78% breach rate, the highest across industries surveyed.
Organizations that find compliance requirements very challenging have a breach rate of 82.4%, which is 14 percentage points higher than organizations with lower compliance difficulty (68.3%).
More than 50% of organizations check for unusual login attempts every three months or less.
5% of organizations reported six or more identity-related breaches.