Sophos has today published its seventh annual State of Ransomware report, an independent study based on consultations with IT and cybersecurity managers from 17 countries (including Spain) that identifies the impact of ransomware on companies and the degree of preparation of organizations to defend themselves.

This year’s report by Sophos reveals that identity is the predominant initial access vector: eight out of ten ransomware attacks in Spain (82%) begin with compromised identities. This signals a shift in strategy, as attackers increasingly recognize identity as a key component in ransomware distribution. Furthermore, exploited vulnerabilities (17%) are no longer the most common root cause of ransomware success in Spain: malicious email (29%) and phishing (24%) take the top spot.

“As cybercriminals using ransomware experiment with artificial intelligence, they have the potential to accelerate their ability to steal valuable assets, hold them hostage, and do so at a scale that exceeds their previous ability,” said Ross McKerchar, CIO at Sophos. “This speed requires close 24×7 monitoring of the most exploited access paths, which our data shows are stolen and compromised valid accounts. However, improving AI models will give attackers an increasing advantage in finding and exploiting software vulnerabilities. Defenders cannot rely solely on patches to keep pace, so it is essential to reduce external exposure and maintain strong endpoint protection.”

The report also reveals that 56% of Spanish companies affected by ransomware suffered data encryption, an increase that has reversed a downward trend (47% in 2025). Other notable conclusions are:

Seven in ten ransomware victims in Spain (73%) say that the ransomware incident was also their most serious identity attack, confirming that identity theft is the main distribution mechanism for ransomware.

More than half of ransomware attacks in Spain (56%) managed to encrypt data, including 18% in which data was both encrypted and stolen.

When data is encrypted, attackers are one-third more likely to receive ransom payments from Spanish companies. 33% of Spanish organizations whose data was encrypted paid the ransom to recover their data (36% in 2025 and 56% the previous year), while 70% used backup copies (70% in 2025).

Only 40% of Spanish organizations were able to stop attacks before encryption or extortion (45% in 2025).

Multi-factor authentication (MFA) was implemented in some form in 92% of incidents where compromised credentials were the primary cause of ransomware attacks, making it clear that MFA alone is not enough to stop ransomware and that gaps in coverage create vulnerability.

In Spain, the average ransom demand stood at 1.8 million dollars ($911,600 in 2025 and 4.24 million dollars reported in the 2024 report), only surpassed this year in Europe by the United Kingdom (2.5 million dollars).

Recovery on the rise

Although organizations face various prevention challenges as attackers refine their techniques, significant progress has been made to improve their resilience. Increased investment in backup infrastructure has likely helped organizations recover more quickly after a ransomware attack; Half of Spanish organizations (50%) manage to recover within a week, and 18% in less than a day. In 2025, 49% fully recovered within a week.

Spanish organizations also continue to be effective when negotiating with ransomware operators. Of those who chose to pay, almost half (46%) successfully negotiated a settlement for less than the attackers’ initial ransom demand, 36% paid what was asked of them, and 18% ended up paying more.

Globally, the average ransom demands made by attackers have fallen by 65% ​​in the last two years, and the proportion of organizations paying the ransom to recover data has fallen to 48%, the second lowest rate on record after 2023 (46%).

Rising costs

Although improved strategies have reduced the ability of attackers to obtain financial benefits through ransom demands, the average recovery costs after an attack have increased, now standing in Spain at $2.3 million per incident (1.15 million in 2025 and $3.43 million the previous year). On a global scale, costs per incident stand at 1.7 million dollars (1.5 million in 2025).

“Organizations have strengthened their resilience against ransomware over the past year, and those investments are paying off in a big way,” McKerchar continues. “Yet, ransomware continues to cost organizations millions. As artificial intelligence becomes more powerful, attackers will be able to identify identity misconfigurations and weaknesses in organizations much more cheaply and quickly than before. That same technology also gives defenders the opportunity to detect and remediate those gaps more quickly, but only if prevention, detection and response work together as part of a unified cybersecurity strategy.”

Sophos recommends the following practices to help organizations create integrated, AI-driven defenses that combine technology, people and processes:

Consider identity a critical security layer: Organizations should prioritize identity threat detection and response (ITDR), enforce phishing-resistant multi-factor authentication on all access points, and regularly audit both human and non-human identities.

Invest in backup and recovery infrastructure: Backups should be regularly tested, stored offline or in immutable formats, and integrated into a documented incident response plan that can be carried out under pressure.

Maintain exposure management programs: Organizations should maintain rigorous patching schedules, prioritize Internet-exposed assets, and consider how new AI-assisted tools can accelerate vulnerability identification and remediation.

Reduce exposure through the firewall and leverage its telemetry to detect attacks early. Ensure your firewall receives prompt updates – ideally automated – and minimize services exposed to the Internet, such as administrator access and user portals. Connect firewalls to XDR and MDR solutions so that firewall telemetry helps detect ransomware attacks before payloads are deployed.