India Ransomware Risk Is Now an Identity Problem
Fresh 2026 research shows ransomware crews winning through stolen accounts, human trust and repeat extortion—not only unpatched servers.
Aisha Rahman
Cybersecurity reporter
Published Jul 27, 2026
Updated Jul 27, 2026
12 min read
Overview
India ransomware risk in 2026 is increasingly an identity problem before it becomes an encryption problem. Attackers are using stolen credentials, convincing impersonation and weak account controls to enter organisations with less noise than a software exploit. Once inside, they steal data, reach privileged systems and build pressure that can continue even after files are restored.
New research released in July sharpens that picture for India. Proofpoint's 2026 AI-Era Ransomware Report says 62% of Indian organisations affected by ransomware believed AI made attacks more effective. Nearly half of those that paid, 48%, then faced another extortion demand. The lesson is uncomfortable: payment doesn't necessarily buy closure, and a clean backup doesn't erase stolen data or compromised accounts.
Valid accounts are replacing noisy break-ins
For years, ransomware advice centred on patching internet-facing systems. That remains essential, especially for VPNs, firewalls and remote-management tools. But current incident data shows attackers increasingly arriving with credentials that make them look like legitimate users. A valid login can pass through controls designed to detect malware at the perimeter.
Sophos' 2026 Active Adversary Report found that 67% of incidents investigated by its response and managed-detection teams were rooted in identity attacks. Brute-force activity accounted for 15.6% of initial access, almost level with exploited vulnerabilities at 16%. Missing multi factor authentication appeared in 59% of cases.
This does not make patching less important. It changes triage. Security teams need to treat authentication logs, impossible travel, unusual token use, new inbox rules and unexpected privilege changes with the same urgency as an endpoint malware alert. An attacker using a real account may never trigger the signature that defenders expect.
India faces a trust-based attack advantage
Proofpoint's India findings point to an unusually high role for user interaction. Phishing and impersonation work when a message fits the recipient's context: a supplier invoice, a payroll request, a document share or an urgent executive instruction. AI can improve grammar, generate variants and help attackers imitate the language of a company or sector at scale.
The defensive response cannot be another annual awareness slide deck. People need a fast way to question unusual requests without being blamed for slowing work. Finance teams should have an independent confirmation route for payment changes. Help desks need stronger identity proof before resetting credentials or adding a new authenticator. Executives must accept that their urgent messages will sometimes be challenged.
India's large business-process, technology and manufacturing sectors create many trusted relationships across vendors and customers. That connection supports growth, but it also gives attackers more believable stories. A compromised supplier mailbox can be more persuasive than an obviously external phishing domain.
Ransomware groups are consolidating at high volume
The criminal market remains crowded, yet the largest operators are regaining share. Check Point Research counted 2,122 victims posted to data-leak sites in the first quarter of 2026. That was 12.2% below the record fourth quarter of 2025 but still the second-highest first quarter on record and 117% above Q1 2024.
The top 10 groups accounted for 71% of listed victims. Qilin posted 338, while The Gentlemen jumped from 40 victims in the prior quarter to 166. LockBit returned with 163. Concentration matters because established programmes can offer affiliates better infrastructure, negotiation support and access to stolen credentials.
Leak-site counts are not a complete census. Some victims never appear, some listings may be disputed, and one intrusion can affect several legal entities. Still, the measure is useful for direction: ransomware has not faded after law-enforcement disruption. Operators reorganise, brands change and affiliates move.
India ransomware risk follows exposed access
India's place in the threat picture is not explained only by an attacker deciding to target the country. Check Point found India represented 4.2% of victims attributed to The Gentlemen in Q1, alongside larger shares in Thailand and Brazil. Researchers linked that pattern partly to a stockpile of compromised FortiGate VPN access concentrated in Asia-Pacific and Latin America.
This distinction affects defence. If campaigns follow available access, reducing exposure can directly change who gets attacked. Organisations should inventory every internet-facing appliance, remove abandoned portals, rotate credentials after vulnerabilities and check whether credentials or devices have appeared in threat intelligence. Asset ownership has to be explicit; an unowned gateway becomes an attacker-owned gateway eventually.
Manufacturing is particularly exposed because plants combine older operational systems, remote support, vendors and pressure to maintain uptime. A shutdown can cost more by the hour than an office outage, giving extortion crews more negotiating power. The Foxconn ransomware incident and its supply-chain implications illustrate why recovery plans need to include factories and suppliers, not only corporate laptops.
Identity attacks compress the defender's clock
Sophos found attackers reached Active Directory in a median 3.4 hours after entry. Median overall dwell time fell to three days, reflecting both faster attacker movement and faster detection in managed environments. Those numbers leave little room for a ticket that waits until morning.
Off-hours activity makes the gap more dangerous. The report observed 88% of ransomware payload deployments and 79% of data exfiltration actions outside normal business hours. A security operation that has strong daytime staffing but weak night escalation is aligned with employee schedules, not attacker behaviour.
Organisations do not all need a large internal 24-hour centre. They do need a named path for urgent alerts, authority to isolate accounts and systems, and tested contact details for decision-makers. Managed detection can fill coverage gaps only if the provider can act and has the telemetry required to see the event.
Backups solve only one part of extortion
Reliable offline or isolated backups can prevent encryption from becoming a total operational loss. They cannot retrieve copied customer records, stop a leak-site post or prove that a privileged account is clean. Modern incidents often combine encryption, data theft, harassment and threats to customers or partners.
Proofpoint's finding that 48% of paying Indian victims faced a second demand shows why ransom payment is not a recovery plan. Criminal promises are difficult to enforce. Even when a decryptor works, restoration may be slow and stolen data may already have been copied or sold.
Recovery planning should therefore separate four questions: Can the business restore systems? Can it trust identities? Does it know what data left? Can it meet legal, contractual and customer communication duties? Each needs evidence. A successful server restore is encouraging, but it does not answer the other three.
Multi factor authentication needs stronger design
MFA blocks many stolen-password attacks, but implementation details matter. Push fatigue can train users to approve repeated prompts. SMS codes can be intercepted through social engineering or SIM attacks. Recovery flows may be weaker than the main login. Service accounts and machine identities may have no interactive second factor at all.
Phishing-resistant methods such as passkeys and hardware-backed credentials reduce the value of captured passwords. Privileged administrators should use separate accounts and managed devices. Conditional access can limit risky locations, unmanaged endpoints and unusual sessions, while short-lived tokens reduce the window for replay.
Non-human identities deserve the same discipline. AI agents, scripts, integrations and service accounts should receive narrow permissions, clear owners and expiry dates. The growing identity risk around AI agents is an extension of a familiar problem: credentials survive longer than the work they were created to perform.
Incident response must start before encryption
An effective response begins when defenders see suspicious access, not when a ransom note appears. Early actions include disabling or containing the account, revoking sessions, preserving logs, checking privilege changes and identifying every system the identity touched. Teams should avoid deleting evidence in the rush to clean machines.
Exercises need to test realistic failure. What happens if email is unavailable? Can staff reach the response team without the corporate directory? Who can shut down a production link? How will the company communicate with employees and customers? A plan that assumes all normal tools work is a document, not a capability.
Telemetry retention is another practical weakness. Sophos reported that missing logs linked to retention problems doubled, often because firewall defaults kept only seven days or even 24 hours. Storage costs money, but insufficient history can prevent investigators from finding initial access, affected identities and data movement.
Boards should measure recovery evidence
Ransomware dashboards often count training completion, vulnerabilities closed and backup jobs that reported success. Those are inputs. Leaders also need outcome measures: time to disable a compromised account, percentage of privileged identities using phishing-resistant MFA, restore time for a critical service and the age of the last full recovery exercise.
Third-party access belongs on the same dashboard. Vendors should receive only the systems and time windows they need. Shared accounts must be removed. Contracts should set notification expectations and evidence requirements, but contract language cannot replace technical restrictions.
Security teams can use AI-assisted patch and defence tools to reduce manual work. They should not assume that more automation automatically improves control. Every automated action needs permissions, logs and a safe way to stop it.
Ransomware recovery cost reaches beyond the payment
The ransom is only one line in the financial damage. Sophos' identity survey put mean recovery cost at $1.64 million and the median at $750,000; 73% of affected respondents reported at least $250,000. Those figures can include investigation, restoration, outside specialists, legal work, business interruption and new controls. They still may not capture lost sales or damaged supplier trust.
For a smaller Indian company, the operational cost can be more dangerous than the headline demand. Payroll, invoicing or production may stop while fixed expenses continue. Customers may delay orders because they do not know whether shared data is safe. A recovery that takes weeks can threaten the business even if backups eventually work.
Boards should model several durations rather than one dramatic worst case. What happens after four hours, one day, three days and two weeks without a critical service? Which manual workarounds are legal and safe? Ransomware recovery cost becomes manageable only when those dependencies are known before the incident.
Incident response India needs sector-specific exercises
Incident response India cannot be reduced to one universal checklist. A hospital must protect care continuity and sensitive records. A factory must decide when isolating a network creates physical or safety risk. A bank has strict transaction, customer and regulatory duties. Public agencies may need to maintain citizen services while evidence is collected.
Exercises should reflect those constraints and include vendors who operate critical systems. Teams need to rehearse decisions, not merely read procedures. A useful exercise forces leaders to choose whether to disconnect a plant, notify customers with incomplete facts or restore from a backup whose integrity is uncertain.
India also spans large enterprises with mature teams and smaller suppliers that may have one generalist managing technology. Larger buyers can reduce shared risk by setting attainable controls, offering secure access methods and helping suppliers test notification. A questionnaire alone does little when the smaller firm lacks tools or expertise.
Double extortion changes the communication plan
Double extortion combines operational disruption with a threat to publish or sell stolen data. Some groups skip encryption entirely when theft creates enough pressure. That means a business can keep running and still face a serious incident that requires investigation, legal assessment and communication.
Early messages should separate confirmed facts from open questions. Saying that operations are normal does not answer whether data left the network. Claiming no evidence of theft can mislead if logging is incomplete. Customers need clear actions only when those actions are justified, such as changing a password that was actually exposed.
The second demand reported by many paying victims shows why negotiation cannot substitute for containment. Sessions must be revoked, persistence removed and stolen credentials replaced. Otherwise the organisation may be paying one actor while another still holds access.
Recovery depends on clean identity rebuilding
After containment, organisations often rush to reconnect systems because every hour costs money. Reconnecting with compromised administrator accounts, unchanged service credentials or unreviewed federation settings can invite the attacker back. Identity recovery needs an order of operations.
Teams should establish a small trusted administration environment, reset the most powerful credentials first and verify who controls authentication infrastructure. They must rotate secrets used by services and integrations, not only employee passwords. Tokens and active sessions need revocation because a password change may not invalidate access already granted.
The investigation should identify how privileges changed. New administrators, altered group memberships, unfamiliar applications, forwarding rules and persistence in cloud tenants can survive an endpoint rebuild. Where confidence is low, rebuilding identity components from known-good configuration may be safer than attempting to clean them in place.
Communication is part of this sequence. Employees need to know which devices and channels are trusted, when credentials may be changed, and how to report suspicious prompts. Customers and partners should receive specific guidance when their accounts or data are affected, not generic alarm.
Recovery exercises rarely test this depth. Many prove that a database can be restored but assume the domain, cloud tenant and help desk remain trustworthy. A better test starts with a compromised privileged account and forces the team to rebuild access while normal collaboration tools are unavailable.
The aim is not instant perfection. It is evidence-based restoration. Each reconnected system should have an owner who can state why its data, software and credentials are trusted. That discipline slows the first hours and can prevent a much longer second incident.
Cyber insurance asks for evidence before renewal
Cyber insurance can fund parts of response and recovery, but the market increasingly asks organisations to prove basic controls. Insurers may want details on MFA, privileged access, backups, endpoint monitoring and tested response plans. Answers should match reality; an inaccurate application can create a dispute when the policy is needed most.
Coverage also has limits. Business interruption may depend on a waiting period or a specific cause. Privacy, regulatory and third-party losses can sit under different clauses. Ransom payments may face legal restrictions, sanctions checks and insurer approval. Leaders should understand those conditions before an incident, not during a negotiation.
The underwriting process can still be useful even when a company decides not to buy. It forces owners to document systems, controls and recovery assumptions. Gaps found at renewal should become funded work rather than a collection of optimistic answers.
Insurance is a financial backstop, not a security control. It cannot revoke a stolen session, rebuild a domain or tell customers what data left. The strongest policy sits behind a response capability that has already been exercised.
Reader questions
Quick answers to the follow-up questions this story is most likely to leave behind.