Desk live·
ForensicPost
Ransomware/Analysis/File 26-0703

Seventy-three per Cent of Intrusions Came Through the Remote-Access Box

Reporting puts legacy VPNs at the entry point in 73% of verified ransomware intrusions in 2025, up from 38% in 2023. A single control category now accounts for most of the problem.

Constructed geometry · not a chart of case data
TargetEnterprise remote access
ActorMultiple
D. Kennedy10 min readConfidence: medium2 sources reviewed

Published analysis places legacy VPNs as the entry point in 73% of verified ransomware intrusions in 2025, against 38% in 2023. Treat the precise figures with the caution any vendor-derived statistic deserves; the direction is stark enough to act on regardless.

Concentration Cuts Both Ways

A threat landscape where most intrusions share one entry category is, in one sense, good news. Defensive effort has an obvious focus, and an organisation that fixes one control class addresses the majority of its realistic exposure.

It is also an indictment. The category has been known, discussed and advised on for years, and its share has roughly doubled in two.

Why The Box Is Still There

Remote-access appliances persist because replacing one is a project, not a purchase. It touches every remote worker, every site-to-site link and frequently a set of legacy applications that only work through it.

Meanwhile the appliance keeps working. There is no operational signal prompting replacement — no outage, no user complaint, no failing metric. It quietly ages out of support while continuing to authenticate people successfully every morning.

The Awkward Part For Vendors

Several of the appliances in this category are sold by security companies. That is not hypocrisy — building software that terminates untrusted connections is genuinely difficult — but it does undercut a common assumption that a security vendor’s product is inherently a safer place to put a control.

The practical question for anyone reading this: what is the support status of the device terminating your remote access, and when was its management interface last reachable from the internet?

How we reported this

This is an analysis file built on published research, listed below. Figures are vendor-derived and methodology varies between sources; we treat the trend as the finding. Corrections: corrections@forensicpost.com.

Sources
  1. Legacy VPN end-of-life 2026: the remote-access watchlistJimber
  2. Ransomware gangs attack Palo Alto, Fortinet, Citrix and Check Point VPNsCybersecurity News
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary