// threat intel

Ransomware in 2026 Is Targeting Identity Systems, Not Just Files

Ransomware in 2026 Is Targeting Identity Systems, Not Just Files — security advisory

Ransomware has evolved: crews now target identity systems, administrative controls, backups and recovery infrastructure to stop victims from restoring operations. With 721 publicly disclosed victims recorded in June 2026 alone, the shift toward identity-first attacks is unmistakable.

If an attacker owns your Active Directory, they own your recovery too.

Our analysis

The move from “encrypt files” to “own identity and recovery” is the most important ransomware trend of 2026. If attackers control Active Directory, they can disable backups, escalate everywhere and dictate terms — encryption becomes optional leverage rather than the whole attack. Any recovery plan that quietly assumes your identity provider will still be intact after an incident is now dangerously out of date.

What you should do

  • Harden and tier Active Directory; close the common escalation paths (Kerberoasting, delegation abuse, dangerous ACLs).
  • Keep offline, immutable backups and rehearse restoration without trusting production AD.
  • Deploy identity threat detection and alert on mass privilege or GPO changes.
  • Validate the whole chain with AD penetration testing, assumed-breach and red-team exercises.

How AgentOffense helps: our Active Directory penetration testing closes the escalation paths to domain admin, while an assumed breach assessment and red team operations test detection, response and recovery.

Source: Cybersecurity Insiders.

Why attackers go after identity, not files

Encrypting files is noisy and recoverable from backups. Owning identity is quiet and total: control Active Directory or your cloud identity provider and you can grant yourself access to everything, disable defences, and deploy ransomware everywhere at once from a position of trust.

That is why modern intrusions race toward Domain Admin or global admin as the real objective. Kerberoasting, delegation abuse and privilege-escalation paths are the routes they take — and finding those paths before an attacker does, from an assumed-breach starting point, is the only reliable defence.

What this means for your business

Ransomware crews have shifted from encrypting files to owning identity — because control of Active Directory or your identity provider means control of everything. Identity is now the primary battleground.

How to reduce your exposure

  • Harden Active Directory and cloud identity: tiered admin, no standing privileges, MFA everywhere.
  • Hunt for Kerberoasting, delegation abuse and privilege-escalation paths to Domain Admin.
  • Monitor identity systems for anomalous authentication and privilege changes.
  • Test identity attack paths with an assumed-breach mindset.

Test your identity attack paths with Active Directory penetration testing and Entra ID security assessment — get a fixed-price quote.

// get started

Work with AgentOffense

Tell us about your target and goals. We’ll reply with scope and a fixed-price quote — usually within one business day.

./request_engagement