The 2025 Sophos Active Adversary Report, published on 2 April 2025, drew on 413 cases handled during 2024 by the vendor’s incident response team and by the team covering critical cases among its managed detection customers. Compromised credentials were the leading root cause at 41% of cases, the second consecutive year in that position; exploited vulnerabilities accounted for 22%. Separately, the report gives external remote services — edge devices, firewalls and VPNs — as the initial access route in 56% of cases.
It Is The Corpus’s Largest Theme, Measured
The identity theme in this database holds that intrusion increasingly means legitimate credentials used by the wrong party: the service desk at 25-0512, recruited support agents at 25-0514, consent grants at 25-0806, a compromised account performing 300,000 permitted downloads at 25-0612, HR impersonation at 25-0806b.
Every one of those was reasoned from individual incidents. A leading root cause across a whole caseload is the closest thing to a base rate the corpus has found — and 41% is a plurality, not a majority, which is a weaker claim than this file previously made and a more defensible one.
Which Reframes What The Other Half Is
The 22% attributed to exploited vulnerabilities is the share this corpus covers most heavily — ToolShell at 25-0719, CitrixBleed 2 at 25-0624, the Oracle campaign at 25-1007, the SimpleHelp chain at 25-0601b.
Those files are longer, more technical and more numerous here, because a named CVE produces vendor advisories and research write-ups while a stolen password produces nothing. The corpus has been over-weighting the minority route because the minority route generates documentation.
And It Explains Why Prevention Spending Underperforms
Vulnerability management, patching cadence and exploit prevention address the 22%. Nothing in that stack engages an adversary who authenticates correctly.
This desk filed at 25-0810 that the best-resourced organisation in this database was reached by a conversation, and at 25-1022 that voice phishing engaged no technical control at any point across five sectors. Credentials leading the root causes two years running is what that looks like across a whole caseload.
Graded medium: one vendor’s engagements, which over-represent organisations that called for help.
Built on the 2025 Sophos Active Adversary Report, published 2 April 2025 and listed below. Figures are the vendor’s own: 413 cases handled in 2024 by its incident response team and by the team covering critical cases among managed detection customers. The population is a vendor caseload — organisations that engaged a responder — and is not representative of anything wider. Revised 2026: this file previously reported that adversaries logged in with valid credentials in 56% of engagements, and was built on the accompanying press release rather than the report itself. That was wrong. The report gives compromised credentials as the leading root cause at 41% and exploited vulnerabilities at 22%; the 56% figure refers to external remote services as the initial access route, which includes exploiting edge devices rather than excluding exploitation. The citation now points at the report. Corrections: corrections@forensicpost.com.