In France, 85% of ransomware incidents start with an initial attack

In its seventh edition of the annual study on the state of ransomware, Sophos draws for the first time a very clear link between identity-related breaches and ransomware incidents in France.

Sophos, the British cybersecurity vendor, surveyed 2,158 IT and cybersecurity leaders worldwide, including 129 in France*, all from organizations with 100 to 5,000 employees that had suffered a ransomware attack in the prior twelve months.

The most striking figure in the report concerns the link between identity and ransomware. 85% of French organizations affected confirm that last year’s ransomware incident also matched their most serious identity breach, compared with a global average of 67%. An 18-point gap that positions France in a distinctive stance.

Read also: Sophos Fusion: a rebranding for an agentic turning point

This finding is reflected in the primary causes of attacks. Compromised credentials top the list (30%), ahead of phishing (27%) and malicious emails (20%). In contrast, exploitation of vulnerabilities drops sharply, to 13% from 30% a year earlier.

Another new takeaway this year: beyond email and phishing vectors, exposed applications and systems constitute the most frequent entry point (46%), ahead of end-user devices (22%) and VPNs (15%). On this front, France stands out with the highest rate of VPN-related compromises among all the countries surveyed by Sophos.

Regarding organizational causes, staffing shortfalls or capability gaps lead the list (40%), followed by inadequate protection (38%) and lack of expertise (33%).

Lower Ransom Demands, Restoration Costs Skyrocket

60% of attacks resulted in data encryption in France, a rate higher than the global average (56%) and up from 58% in 2025. By contrast, the data theft component tied to these encryptions falls sharply, to 18% from 44% last year.

On recovery, all French organizations whose data were encrypted managed to recover them. Backups played a growing role: 76% of victims used them to restore their systems, up from 60% in 2025. Ransom payments remain common, with 36% of organizations paying to recover their data, up slightly from 33% a year earlier.

The median ransom demand in France stands at $500,000, down 22% from $643,125 in 2025. The share of demands above a million dollars also declines, from 49% to 39%.

But this drop in ransoms does not translate into a lighter overall bill. Excluding ransom payments, the average restoration cost after an attack reaches $2.02 million versus $1.22 million in 2025; up nearly 66%. This amount covers service interruptions, resolution time, hardware costs, and lost operations.

Nevertheless, the recovery time improves: 64% of French organizations recovered in a week or less, compared with 53% in 2025, while the share of companies taking one to six months to recover falls from 18% to 10%.

Read also: AI in business: why CISOs can no longer bear the risk alone

The study also documents the human impact on teams affected by data encryption. 42% report increased pressure from senior management, and 33% report a steadily higher workload since the attack. Nearly a third (31%) say they feel guilt about not having prevented the incident, and 17% report leadership changes within the team.

Positive sign, however: 37% of professionals surveyed report greater recognition from executives, a figure rising sharply from 18% measured in 2025.

* The survey was conducted between January and March 2026, with financial data expressed in dollars and excluding ransom demands of $40 million or more.

Dawn Liphardt

Dawn Liphardt

I'm Dawn Liphardt, the founder and lead writer of this publication. With a background in philosophy and a deep interest in the social impact of technology, I started this platform to explore how innovation shapes — and sometimes disrupts — the world we live in. My work focuses on critical, human-centered storytelling at the frontier of artificial intelligence and emerging tech.