Desk live·
ForensicPost
Ransomware/Method/File 25-0421b

Compromised Credentials Led the Root Causes at 41%, Against 22% for Exploits

Sophos analysed 413 incident response and managed detection cases from 2024. Compromised credentials were the leading root cause for the second year running at 41%; exploited vulnerabilities accounted for 22%.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetIncident response caseload
ActorMultiple
D. Kennedy12 min readConfidence: medium2 sources reviewed

The 2025 Sophos Active Adversary Report, published on 2 April 2025, drew on 413 cases handled during 2024 by the vendor’s incident response team and by the team covering critical cases among its managed detection customers. Compromised credentials were the leading root cause at 41% of cases, the second consecutive year in that position; exploited vulnerabilities accounted for 22%. Separately, the report gives external remote services — edge devices, firewalls and VPNs — as the initial access route in 56% of cases.

It Is The Corpus’s Largest Theme, Measured

The identity theme in this database holds that intrusion increasingly means legitimate credentials used by the wrong party: the service desk at 25-0512, recruited support agents at 25-0514, consent grants at 25-0806, a compromised account performing 300,000 permitted downloads at 25-0612, HR impersonation at 25-0806b.

Every one of those was reasoned from individual incidents. A leading root cause across a whole caseload is the closest thing to a base rate the corpus has found — and 41% is a plurality, not a majority, which is a weaker claim than this file previously made and a more defensible one.

Which Reframes What The Other Half Is

The 22% attributed to exploited vulnerabilities is the share this corpus covers most heavily — ToolShell at 25-0719, CitrixBleed 2 at 25-0624, the Oracle campaign at 25-1007, the SimpleHelp chain at 25-0601b.

Those files are longer, more technical and more numerous here, because a named CVE produces vendor advisories and research write-ups while a stolen password produces nothing. The corpus has been over-weighting the minority route because the minority route generates documentation.

And It Explains Why Prevention Spending Underperforms

Vulnerability management, patching cadence and exploit prevention address the 22%. Nothing in that stack engages an adversary who authenticates correctly.

This desk filed at 25-0810 that the best-resourced organisation in this database was reached by a conversation, and at 25-1022 that voice phishing engaged no technical control at any point across five sectors. Credentials leading the root causes two years running is what that looks like across a whole caseload.

Graded medium: one vendor’s engagements, which over-represent organisations that called for help.

This is an analysis file

Built on the 2025 Sophos Active Adversary Report, published 2 April 2025 and listed below. Figures are the vendor’s own: 413 cases handled in 2024 by its incident response team and by the team covering critical cases among managed detection customers. The population is a vendor caseload — organisations that engaged a responder — and is not representative of anything wider. Revised 2026: this file previously reported that adversaries logged in with valid credentials in 56% of engagements, and was built on the accompanying press release rather than the report itself. That was wrong. The report gives compromised credentials as the leading root cause at 41% and exploited vulnerabilities at 22%; the 56% figure refers to external remote services as the initial access route, which includes exploiting edge devices rather than excluding exploitation. The citation now points at the report. Corrections: corrections@forensicpost.com.

Sources
  1. It takes two: The 2025 Sophos Active Adversary ReportSophos
  2. What is MTTD (mean time to detect) in cybersecurity?DeepStrike
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary