Threat Intel
Ransomware in 2026: the initial access broker changed the playbook
Most ransomware crews no longer break in. They buy the door key from someone who did it months ago — and that changes where your detection budget should go.
The economics of ransomware have quietly reorganised. The group that encrypts your estate is rarely the group that first got in. Access is a commodity, brokered in bulk, aged, and sold on when a buyer with the right tooling appears.
Why dwell time is misleading
We routinely investigate incidents where the initial compromise predates the encryption event by four to nine months. The broker gained access through a stale VPN account, validated it, and left it dormant. Nothing malicious ran. Nothing triggered an alert. The intrusion looked exactly like an employee logging in.
That gap is the opportunity. If your detection strategy is built around post-exploitation behaviour — encryption, mass file access, shadow copy deletion — you are competing on a timeline measured in minutes. If it is built around identity anomalies, you are competing on a timeline measured in months.
Where the access comes from
Across our incident response caseload this year, three sources dominate: credentials harvested by infostealer malware on unmanaged personal devices, exposed remote access services without phishing-resistant MFA, and unpatched edge appliances. None of these are novel. All of them remain effective because they are boring.
What actually reduces exposure
Enforce phishing-resistant authentication on every externally reachable service, without exception for legacy systems — the exception is the intrusion path. Audit for dormant accounts that suddenly become active. Treat edge appliance patching as an emergency-change process, not a monthly cycle. And monitor infostealer marketplaces for your own corporate domains, because your users authenticate to work systems from devices you do not manage.
The defensive advantage here is real. You are not racing an encryption routine. You are looking for a quiet login that does not fit — and you have months to find it.
Seeing something similar in your environment?
Talk to our team