71% of organisations suffered an identity breach

May 2026 News & Events, Information Security

Sophos has released the State of Identity Security 2026, a vendor-agnostic survey of 5000 IT and cybersecurity leaders across 17 countries. The survey found that 71% of organisations suffered at least one identity-related breach in the past year, and on average, organisations reported three separate incidents. Repeat victimisation reached a notable level, with 5% even reporting six or more breaches. These attacks are driven primarily by human error and weak management of non-human identities (NHIs), a challenge that is rapidly accelerating as agentic AI speeds up attack processes.

Two-thirds of ransomware victims (67%) in this survey confirmed that their ransomware incident stemmed from an identity attack, establishing identity compromise as a primary delivery mechanism for ransomware. Sophos X-Ops researchers have observed this consistently over the past year. The financial consequences are steep: the mean recovery cost reached $1.64 million, with a median of $750 000, and 73% of those affected faced costs of $250 000 or more.

“Identity has become the primary attack surface in modern cybersecurity, and this data shows most organisations are losing ground,” said Ross McKerchar, chief information security officer, Sophos. “The non-human identity problem is particularly urgent. AI agents are being granted privileges faster than security teams can track them, and organisations that fail to get ahead of this will find it an increasingly costly gap to close.”

Additional Key Findings from the State of Identity Security 2026:

Data and financial theft dominate breach fallout: Overall, 10% of organisations reported an identity breach that impacted their business in the last year, with the primary consequences being data theft (49%), ransomware (48%), and financial theft (47%).

Visibility remains a critical weakness: Only 24% of organisations continually monitor for unusual login attempts, and more than half check every three months or less.

Detection gaps persist: 14% of breached organisations could not detect and stop their most significant identity attack before damage was done. Smaller organisations (100–250 employees) were nearly twice as likely to fail at detection as mid-sized peers.

Critical infrastructure most exposed: Energy, oil/gas, and utilities (80%) and federal/central government (78%) reported the highest breach rates across all industries surveyed.

Compliance struggles signal broader risk: Organisations that found compliance requirements very challenging had a breach rate of 82.4%, a full 14 percentage points higher than those with lower compliance difficulty (68.3%).

Human error (employees tricked into providing credentials) was cited in nearly 43% of incidents. Weak NHI management, including API keys stored in code, static credentials, and orphaned service accounts, was cited in 41%. Organisations with weak NHI management are 22% more likely to experience financial theft and pay approximately $150 000 more to recover than the average organisation.

The NHI management problem is intensifying. AI agents can autonomously spin up sub-agents, each generating new credentials with broad, persistent access and inconsistent human oversight. Existing identity frameworks were not built for this, and organisations are already behind: only 1 in 3 regularly rotate or audit service accounts and non-human identities, and just 11% do so continuously.

Recommendations to reduce identity-based risks

To reduce exposure to identity-related attacks, organisations should implement a multi-layered approach covering both human and non-human identities. Essential steps include enforcing Multi-Factor Authentication (MFA) for all user accounts, applying least-privilege access principles, and disabling or removing inactive identities promptly.

For non-human identities specifically, organisations should inventory and classify all NHIs, replace long-lived credentials with short-lived alternatives, and implement secrets management platforms to manage NHI credentials at scale. As agentic AI accelerates the proliferation of NHI, deploying Identity Threat Detection and Response (ITDR) capabilities and adopting a Zero Trust security model are increasingly critical layers of defence.

The report is available from Sophos.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Woolworths attack raises bomb preparedness questions
News & Events
Two explosions have been reported at Woolworths stores in South Africa over the past week. SMART Security Solutions asked Jimmy Roodt, an experienced and accredited explosive ordnance disposal specialist from Gauntlet Security Solutions, for his insight into the events.

Read more...
Growing adoption of AI at work
News & Events AI & Data Analytics
AI adoption accelerates worldwide, with South Africa making gains amid uneven diffusion. Locally, South Africa ranks 46th of 147 economies measured, and its AI usage increased to 23,1% in Q1 2026.

Read more...
Enterprise AI hits the wall
News & Events AI & Data Analytics
Demands for AI privacy and sovereignty expose the limits of architectures built for centralised and borderless data flows. Organisations that redesign early are gaining a measurable edge in AI readiness and scale.

Read more...
From the Editor's desk: Security goes mainstream
Technews Publishing News & Events
      Welcome to SMART Security’s SMART Mining & Industrial Security Handbook 2026. While the world is focused on cybersecurity and AI, physical security has become a board-level concern across South Africa’s ...

Read more...
Global security in 2026
Editor's Choice News & Events Security Services & Risk Management Industrial (Industry) Mining (Industry)
The World Security Report 2026 states: “In a world of increasing volatility, physical security has evolved. It is no longer just a defensive measure; it is a critical driver of corporate value.”

Read more...
Industry perspective on industrial cybersecurity
Technews Publishing News & Events Infrastructure Industrial (Industry)
The Industrial Security Harmonization Group has released a joint industry perspective highlighting a critical truth in industrial cybersecurity: secure communication is not determined by protocols alone, but by how they are deployed and managed in real-world environments.

Read more...
Cyber resilience is the real defence
Security Services & Risk Management Information Security Infrastructure
Cyber resilience has evolved into a form of strategic agility, ensuring that when an interruption occurs, the business does not just survive; it snaps back into place before the market even notices a pause.

Read more...
Employees are SA’s biggest cyber threat
Security Services & Risk Management Information Security
South Africa experienced a 46% increase in insider cyber risk in 2026, surpassing the global average of 44%. What is more, 63% of South African companies surveyed expect insider-driven data losses to increase.

Read more...
Aerial firefighter training revolution
Fire & Safety News & Events
Sophisticated new flight simulation software capable of accurately modelling the performance of firefighting helicopters could help train pilots to tackle wildfires more effectively and safely in the future.

Read more...
PoPIA turns its attention to gated access
News & Events Security Services & Risk Management
The Information Regulator has gazetted its proposed Code of Conduct for the processing of personal information at gated access points. At 65 pages long, the code signals a significant shift in how personal information is collected and managed at entry points.

Read more...










While every effort has been made to ensure the accuracy of the information contained herein, the publisher and its agents cannot be held responsible for any errors contained, or any loss incurred as a result. Articles published do not necessarily reflect the views of the publishers. The editor reserves the right to alter or cut copy. Articles submitted are deemed to have been cleared for publication. Advertisements and company contact details are published as provided by the advertiser. Technews Publishing (Pty) Ltd cannot be held responsible for the accuracy or veracity of supplied material.




© Technews Publishing (Pty) Ltd. | All Rights Reserved.