Skip to content
L&M Cybersecurity

Threat Intel

Ransomware in 2026: the initial access broker changed the playbook

Most ransomware crews no longer break in. They buy the door key from someone who did it months ago — and that changes where your detection budget should go.

L&M Threat Research 7 min read

The economics of ransomware have quietly reorganised. The group that encrypts your estate is rarely the group that first got in. Access is a commodity, brokered in bulk, aged, and sold on when a buyer with the right tooling appears.

Why dwell time is misleading

We routinely investigate incidents where the initial compromise predates the encryption event by four to nine months. The broker gained access through a stale VPN account, validated it, and left it dormant. Nothing malicious ran. Nothing triggered an alert. The intrusion looked exactly like an employee logging in.

That gap is the opportunity. If your detection strategy is built around post-exploitation behaviour — encryption, mass file access, shadow copy deletion — you are competing on a timeline measured in minutes. If it is built around identity anomalies, you are competing on a timeline measured in months.

Where the access comes from

Across our incident response caseload this year, three sources dominate: credentials harvested by infostealer malware on unmanaged personal devices, exposed remote access services without phishing-resistant MFA, and unpatched edge appliances. None of these are novel. All of them remain effective because they are boring.

What actually reduces exposure

Enforce phishing-resistant authentication on every externally reachable service, without exception for legacy systems — the exception is the intrusion path. Audit for dormant accounts that suddenly become active. Treat edge appliance patching as an emergency-change process, not a monthly cycle. And monitor infostealer marketplaces for your own corporate domains, because your users authenticate to work systems from devices you do not manage.

The defensive advantage here is real. You are not racing an encryption routine. You are looking for a quiet login that does not fit — and you have months to find it.

Seeing something similar in your environment?

Talk to our team

Next step

Find out what an attacker sees before they show you.

Book a scoping call with a senior consultant. No sales engineer, no slide deck — a technical conversation about your actual exposure.