81% of Ransomware Attacks in India Now Originate from Compromised Identities
Sophos, a global cybersecurity leader, reports India records a higher rate of identity-driven ransomware attacks, data encryption and ransom payment than the global average, as malicious email and phishing overtake exploited vulnerabilities as the leading root cause.
- Malicious email (28%) and phishing (26%) now account for more than half of all attacks.
- Exploited vulnerabilities in India have fallen to just 11% – a sharper drop than the global figure of 24%.
- Multi-factor authentication was already deployed in 98% of India incidents where compromised credentials were the root cause of the attack.
- When data was encrypted, 56% of Indian organizations paid the ransom and recovered their data – compared to 48% globally – while 67% used backups and 18% recovered through other means.
- Average cost to rectify a ransomware attack in India was $1.11 million, below the $1.7 million global average.
Sophos released India-specific findings from its seventh annual State of Ransomware report, The India data shows identity is the dominant initial access vector (IAV) for ransomware in the country, with more than four in five (81%) attacks starting with compromised identities – ahead of the 79% global average.
The vendor-agnostic survey of IT and cybersecurity leaders across 17 countries identifies the impact of ransomware on businesses and how prepared organizations are to defend against them.
Exploited vulnerabilities are no longer the leading root cause of ransomware attacks in India and the rest of the world. Malicious email (28%) and phishing (26%) now account for more than half of all attacks, while exploited vulnerabilities have fallen to just 11% – a sharper drop than the global figure of 24%, and consistent with the broader shift toward identity-based intrusion.
The report also found that, out of Indian organizations hit by ransomware, 60% had their data encrypted by attackers – higher than the 56% global rate, and including 16% where data was both encrypted and stolen, matching the global figure exactly.
Key findings
- 79% confirmed their ransomware incident was also their most significant identity attack of the year – well above the two-thirds (67%) reported globally, reinforcing identity compromise as the primary ransomware delivery mechanism in the country.
- When data was encrypted, 56% of Indian organizations paid the ransom and recovered their data – compared to 48% globally – while 67% used backups and 18% recovered through other means.
- Multi-factor authentication was already deployed in 98% of India incidents where compromised credentials were the root cause of the attack, almost identical to the 97% recorded globally – underscoring that MFA alone is not sufficient without full coverage gaps create exposure.
- The UK saw the highest median ransom demand recorded for any country at $2.5 million.
While organizations face prevention challenges as threat actors evolve their techniques, significant progress has been made to improve their ability to recover. Increased investment in backup infrastructure has likely contributed to organizations recovering faster following a ransomware attack; over half (58%) of Indian organizations manage to do so within one week, and 14% in less than a day.
While improved strategies have impacted the adversary’s ability to extract financial gain through ransom demands, the average cost to rectify a ransomware attack in India was $1.11 million, below the $1.7 million global average.
What stands out for India?
India stands out because it is more heavily affected by identity compromise than the global average, and it has a sharper shift away from vulnerability exploitation toward email- and phishing-based intrusion. It also appears more likely than the global average to face encryption and to pay ransom once encrypted data is involved.
The biggest standout is that India’s ransomware problem is framed less as a patching issue and more as an identity-security problem. That matters because the report argues that attackers are using stolen credentials and compromised identities as the main route in, even when MFA is already deployed, suggesting gaps in coverage and enforcement.
Another notable point is recovery: despite higher attack impact, Indian organizations seem relatively active on backup and recovery, with 58% recovering within a week. The report also links this to lower remediation cost than the global average, which suggests resilience investments may be paying off even though attack pressure remains high.
Why do Indian organizations fall victim to ransomware?
Data points: Exploited vulnerabilities were the most common technical root cause of attack, used in 29% of attacks. They are followed by compromised credentials, which were the start of 22% of attacks. Malicious emails were used in 21% of attacks.
Reasons: A lack of people / capacity and poor quality protection are the two most common operational root causes, both
cited by 41% of Indian respondents.
39% said that not having the necessary cybersecurity products and services in place played a factor in their organization falling victim to ransomware.
What happens to the data during these attacks?
- 42% of attacks resulted in data being encrypted. This is below the global average of 50% and a drop from the 62% reported by Indian respondents in 2024.
- Data was also stolen in 31% of attacks where data was encrypted, a drop from the 34% reported last year.
- 95% of Indian organizations that had data encrypted were able to get it back, just below the global average.
- 53% of Indian organizations paid the ransom and got data back, a considerable drop from the 65% reported last year.
- 51% of Indian organizations used backups to recover encrypted data, a small drop from the 52% reported last year.
Why is the median for Indian ransomware demand dropping?
The median Indian ransom demand in the last year was $961,289, which is a 52% drop from the $2 million reported in our 2024 survey.
- 49% of ransom demands were for $1 million or more, down from 62% in 2024.
- The median Indian ransom payment in the last year was $481,636, a 79% drop from the $2 million reported last year.
Indian organizations typically paid 88% of the ransom demand, slightly above the global average of 85%.
- 41% paid LESS THAN the initial ransom demand (global average: 53%).
- 46% paid THE SAME as the initial ransom demand (global average: 29%).
- 12% paid MORE THAN the initial ransom demand (global average: 18%).
The drop in median ransom demands in India—from $2 million in 2024 to $961,000 in 2025 (a 52% decrease)—can be attributed to several factors highlighted in the report:
- Improved Cyber Defenses
- Organizations have strengthened their security measures, making it harder for attackers to achieve large-scale data encryption or theft, which reduces their leverage to demand higher ransoms.
- Increased Use of Backups
- 51% of organizations used backups to recover encrypted data, reducing the necessity to pay high ransoms and signaling to attackers that exorbitant demands are less likely to be met.
- Lower Willingness to Pay
- Only 53% of affected organizations paid the ransom in 2025, down from 65% the previous year. This trend discourages attackers from making high initial demands.
- Market Dynamics
- With fewer organizations paying large ransoms and more negotiating or refusing to pay, attackers are adjusting their demands downward to increase the likelihood of payment.
- Regulatory and Awareness Pressure
- Increased awareness, regulatory scrutiny, and organizational preparedness have contributed to a more cautious approach to ransom negotiations and payments.
These combined factors have led to a significant reduction in both ransom demands and actual payments in India.
Sophos Recommendations
Sophos recommends the following best practices to help Indian organizations build integrated, AI-driven defenses that bring together technology, people and process:
- Treat identity as a foundational security layer – Prioritize identity threat detection and response (ITDR), enforce phishing-resistant multi-factor authentication across all access points, and regularly audit both human and non-human identities.
- Invest in backup and recovery infrastructure – Test backups regularly, store them offline or in immutable formats, and integrate them into a documented incident response plan that can be executed under pressure.
- Maintain exposure management programs – Keep rigorous patching schedules, prioritize internet-facing assets, and evaluate how AI-assisted tools can accelerate vulnerability identification and remediation.
- Reduce exposure via the firewall and use firewall telemetry to detect attacks early – Ensure firewalls receive rapid, ideally automated, updates and minimize internet-facing services like admin access and user portals. Connect firewalls to XDR and MDR solutions so telemetry can help detect ransomware before payloads are deployed.
- Align security investment to local regulatory pressure – With DPDP Act compliance now a stated priority for nearly a third of Indian organizations, security and compliance teams should treat identity and data-protection controls as shared infrastructure rather than separate workstreams.
This regional analysis is based on the 500 IT and cybersecurity decision-makers in India who took part in the broader Sophos State of Ransomware 2026 study, conducted by Vanson Bourne on behalf of Sophos in Q1 2026. Of those 500, 240 organizations had been hit by ransomware in the previous 12 months. Globally, 5,000 IT and cybersecurity decision-makers were surveyed across 17 countries: USA, Brazil, Chile, Colombia, Mexico, UK, France, Germany, Italy, Spain, Switzerland, Australia, India, Japan, Singapore, South Africa, and UAE. Respondents came from organizations with 100 to 5,000 employees across 15 industry sectors.
Download the full State of Ransomware 2026 report on Sophos.com.


