見出し画像

[IT] Vol.36 | 80% of Ransomware Break-Ins Now Use Stolen Credentials — Patching Alone Won't Save You

Ransomware incidents in July 2026 surged to 964 cases, up 87% from a year earlier. The more important change is how attackers get in: roughly 80% of break-ins now come through stolen legitimate credentials, not holes in software.
This article explains, in about 3 minutes, how the entry point shifted and what you should do about it right now.

Background

According to research published in August 2026 by the security firm Check Point Research, 964 ransomware incidents — attacks that encrypt or steal data and demand a ransom — were reported in July 2026. That is a 49% jump from June and an 87% increase over July 2025.

By sector, business services accounted for the largest share at 32.5%, followed by industrial and manufacturing at 14.4% and consumer goods and services at 13.4%. No single industry is being singled out; the damage is spread broadly across the economy.

The most active attack groups were "The Gentlemen" and "Qilin," each responsible for 14% of publicly disclosed attacks.

But the biggest change is the entry point. Attackers used to rely mainly on exploiting software vulnerabilities — flaws in a program that function as security holes. Today, about 80% of intrusions come from logging in with legitimate IDs and passwords stolen from somewhere else.

Behind this shift are "infostealers," malware built to harvest credentials. Research suggests roughly 1.7 billion sets of credentials have leaked worldwide through them. Attackers buy those credentials and walk into corporate networks impersonating legitimate users.

Why Is This a Hot Topic Now?

The uncomfortable part is this: if someone enters with the correct key, the defending side cannot tell it's an intrusion.

Security work has traditionally centered on closing holes — applying patches, updating VPN appliances, and so on. But when an attacker logs in with stolen credentials, the system sees an ordinary employee arriving in the ordinary way. No alarm goes off.

AI is also lowering the bar for attackers. Check Point's Q2 2026 report finds that AI has reduced the barrier to entry for cybercrime and expanded the ransomware "ecosystem" — the marketplace where attackers buy and sell tools and information from one another. You no longer need advanced technical skill to operate on the attacking side.

The same pattern is showing up in Japan. On August 5, 2026, the sporting goods manufacturer Yonex disclosed that it had detected a credential-stuffing attack — where leaked IDs and passwords are tried in bulk across login forms — and that customer names and purchase histories may have been viewed.

So this is not only a problem for corporate IT departments. The password you reuse on some unrelated service can, by a roundabout path, become the way into your employer's network.

What Happens Next?

The center of gravity in defense is shifting from "close the holes" to "make identity verification stronger." In practice that means enforcing multi-factor authentication — pairing a password with something like a code on your phone — and deploying systems that detect and block logins from unusual locations or at unusual times.

What individuals can do is equally clear. Stop reusing passwords, and turn on multi-factor authentication for anything important. It sounds unglamorous, but in a world where 1.7 billion credentials are circulating, this is what actually works.

Email also remains a primary entry point, so the basics still apply: don't click links you weren't expecting.

What Do You Think?

Are you reusing the same password across several services right now?
The shift from "close the holes" to "verify identity harder" — do you think your workplace has caught up with it?

Editor's Note

Honestly, the part that chilled me was the idea that when someone enters with a legitimate ID, the defenders simply can't tell it's an intrusion. I used to reuse the same password across several services myself, so I can't pretend this is someone else's problem. I'm starting with my work accounts and redoing multi-factor authentication on all of them.


📂 Read more articles → note.com/news_translator


News Translator|Making complex news easy to understand.
Follow for weekly bilingual news articles.

いいなと思ったら応援しよう!