There’s a comforting myth that ransomware still spreads mostly through some employee clicking a sketchy attachment. It’s not wrong, exactly — phishing is still a major player. But it’s not the whole story anymore, and treating it as the only threat leaves some very obvious doors unlocked.
Understanding the actual pathways ransomware uses to get in is the fastest way to close them. So let’s walk through where these attacks really start.
The Infection Vectors That Matter Most Right Now
According to Sophos’s State of Ransomware research, exploited vulnerabilities have been the single leading ransomware entry point for three years running, accounting for roughly a third of incidents. Compromised credentials and phishing follow close behind. Here’s what each one actually looks like in practice.
1. Unpatched and Exposed Systems
This is the big one. Attackers — and the automated scanners they run — actively search the internet for internet-facing systems running outdated, vulnerable software: VPN appliances, firewalls, file transfer tools, and exposed Remote Desktop Protocol (RDP) ports.
Once a vulnerability is publicly disclosed, the clock starts ticking fast. Some research shows nearly 28% of vulnerabilities get exploited within 24 hours of being made public, which is a brutal window compared to the typical 30-to-45-day patch cycle many organizations still follow.
RDP deserves a special mention here. Exposed RDP ports are frequently scanned, cataloged, and sold on criminal marketplaces by “initial access brokers,” whose entire business model is finding a way in and reselling that access to ransomware operators.
2. Compromised Credentials
Attackers increasingly don’t need to break in at all — they just log in. Infostealer malware quietly harvests saved passwords from browsers on infected personal devices, and those credentials end up for sale on dark web marketplaces. Verizon’s 2026 DBIR found that a majority of ransomware victims had experienced a credential leak or infostealer infection in the year before the attack, which makes credential monitoring a genuinely useful early-warning signal, not just a nice-to-have.
Weak or reused passwords make this whole process easier. One leaked password from an unrelated breach can become the key to your entire network if it’s reused anywhere else.
3. Phishing Emails
Still very much in play. A convincing phishing email tricks someone into clicking a malicious link or opening an infected attachment, which quietly installs the first piece of malware — often not the ransomware itself yet, but a foothold that lets attackers move deeper into the network over the following days or weeks.
This is part of why ransomware attacks often feel sudden even though the actual intrusion happened much earlier. Dwell time — the gap between initial access and the ransomware detonating — gives attackers room to map out the network, disable backups, and target the most damaging systems before triggering encryption.
Good baseline habits close a lot of this gap before an email ever gets the chance to do damage. The cyber hygiene checklist here covers the everyday practices, patching cadence, and account habits that make phishing-driven ransomware far less likely to gain a foothold in the first place.
4. Malicious Advertising and Drive-By Downloads
Sometimes users don’t have to click anything suspicious at all — visiting a compromised or malicious website can silently trigger a download if the browser or a plugin has an unpatched flaw. This vector gets less attention than phishing but remains a steady contributor, especially against outdated browser versions.
5. Third-Party and Supply Chain Access
Vendors, contractors, and software suppliers with access to your network are a real blind spot. If their systems get compromised, attackers can ride that trusted connection straight into your environment without needing to breach your defenses directly.
Why Recovery Speed Varies So Much
Not every ransomware incident ends in disaster. Sophos’s most recent survey found over half of organizations fully recovered within a week, a meaningful improvement from prior years, largely thanks to better backup practices and faster detection. The organizations that struggle most tend to share the same gaps: no tested offline backups, delayed patching, and no clear incident response plan sitting ready before an attack, not scrambled together during one.
Closing the Doors: What Actually Reduces Risk
There’s no single fix, since ransomware exploits whichever door is easiest, but a few practices consistently move the needle:
- Patch aggressively, especially internet-facing systems like VPNs and firewalls. Prioritize anything on CISA’s Known Exploited Vulnerabilities list.
- Lock down or eliminate exposed RDP. If remote access is necessary, put it behind a VPN with multi-factor authentication.
- Enforce MFA everywhere, particularly on email, VPN, and admin accounts — this single control blocks the overwhelming majority of credential-based intrusions.
- Maintain offline, tested backups. A backup you’ve never tried restoring isn’t a real backup plan.
- Monitor for leaked credentials tied to your domain, since that’s often the earliest signal something’s already gone wrong.
A broader checklist covering monitoring, backup cadence, and access controls is laid out in these ransomware protection solutions, which pairs well with the vector-by-vector view above.
Early Warning Signs Worth Watching For
Because ransomware often sits quietly in a network before it detonates, catching the signs during that dwell-time window can prevent the worst outcome entirely. A few signals worth flagging immediately rather than waiting to investigate later:
- Unusual login times or locations, especially for admin accounts that normally only log in during business hours.
- New or modified user accounts that nobody on the team can explain.
- Disabled security tools, since attackers frequently turn off antivirus or logging before deploying the final payload.
- Unexpected file encryption test runs on a small number of files, sometimes used to confirm the ransomware works before a full-scale attack.
- Large or unusual outbound data transfers, which often precede a “double extortion” threat where attackers steal data before encrypting it.
Catching even one of these early can be the difference between an isolated incident and a full network shutdown.
The Bigger Picture
Ransomware doesn’t need a single dramatic failure to succeed. It needs one unpatched server, one reused password, or one distracted click on a Monday morning. That’s genuinely unsettling when you first think about it — but it also means the fix isn’t some impossibly complex overhaul. It’s steady, unglamorous basics, done consistently, across every one of these entry points at once. Boring security wins more often than exciting security.

