Ransomware has evolved: crews now target identity systems, administrative controls, backups and recovery infrastructure to stop victims from restoring operations. With 721 publicly disclosed victims recorded in June 2026 alone, the shift toward identity-first attacks is unmistakable.
If an attacker owns your Active Directory, they own your recovery too.
Our analysis
The move from “encrypt files” to “own identity and recovery” is the most important ransomware trend of 2026. If attackers control Active Directory, they can disable backups, escalate everywhere and dictate terms — encryption becomes optional leverage rather than the whole attack. Any recovery plan that quietly assumes your identity provider will still be intact after an incident is now dangerously out of date.
What you should do
- Harden and tier Active Directory; close the common escalation paths (Kerberoasting, delegation abuse, dangerous ACLs).
- Keep offline, immutable backups and rehearse restoration without trusting production AD.
- Deploy identity threat detection and alert on mass privilege or GPO changes.
- Validate the whole chain with AD penetration testing, assumed-breach and red-team exercises.
How AgentOffense helps: our Active Directory penetration testing closes the escalation paths to domain admin, while an assumed breach assessment and red team operations test detection, response and recovery.
Source: Cybersecurity Insiders.