Site navigation

Seven in 10 Orgs Suffered An Identity Breach This Year

Elizabeth Greenberg

,

identity breach
“Identity has become the primary attack surface in modern cybersecurity, and this data shows most organisations are losing ground,” said Ross McKerchar, chief information security officer, Sophos.

About seven in ten (71%) of organisations suffered at least one identity-related breach in the past year, and on average organisations reported three separate incidents.

This is according to new research from Sophos, which surveyed 5,000 IT and cybersecurity leaders across 17 countries.

Repeat victimisation reached a notable level, with 5% even reporting six or more breaches. These attacks are driven primarily by human error and weak management of non-human identities (NHIs), a challenge that is accelerating rapidly as agentic AI accelerates attack processes.

Two thirds of the ransomware victims (67%) responding to this survey confirmed their ransomware incident stemmed from an identity attack, establishing identity compromise as a primary delivery mechanism for ransomware.

Sophos X-Ops researchers have observed this consistently over the past year. The financial consequences are steep: the mean recovery cost reached $1.64 million, with a median of $750,000, and 73% of those affected faced costs of $250,000 or more.

“Identity has become the primary attack surface in modern cybersecurity, and this data shows most organisations are losing ground,” said Ross McKerchar, chief information security officer, Sophos.

“The non-human identity problem is particularly urgent. AI agents are being granted privileges faster than security teams can track them, and organisations that fail to get ahead of this will find it an increasingly costly gap to close.”

Data and financial theft dominate breach fallout, with 10% of organisations reporting an identity breach that impacted their business in the last year with the primary consequences being data theft (49%) and ransomware (48%), and financial theft (47%).

Visibility has remained a critical weakness, with only 24% of organisations continually monitoring for unusual login attempts, and more than half checking every three months or less.

Detection gaps persist, with 14% of breached organisations unable to detect and stop their most significant identity attack before damage was done. Smaller organisations (100–250 employees) were nearly twice as likely to fail at detection as mid-sized peers.

Energy, oil/gas, and utilities (80%) and federal/central government (78%) reported the highest breach rates across all industries surveyed.


Recommended reading


Organisations that found compliance requirements very challenging had a breach rate of 82.4%, a full 14% points higher than those with lower compliance difficulty (68.3%).

Human error (employees tricked into providing credentials) was cited in nearly 43% of incidents. Weak NHI management, including API keys stored in code, static credentials, and orphaned service accounts, was cited in 41%. Organisations with weak NHI management are 22% more likely to experience financial theft and pay approximately $150,000 more to recover than average.

The NHI management problem is intensifying. AI agents can autonomously spin up sub-agents, each generating new credentials with broad, persistent access and inconsistent human oversight.

Existing identity frameworks were not built for this, and organizations are already behind: only 1 in 3 organisations regularly rotate or audits service accounts and non-human identities, and just 11% do so continuously.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data