Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› Why do phishing and ransomware continue to drive…
Threats, Abuse & Incident Response

Why do phishing and ransomware continue to drive so many breaches even when security tools improve?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 27, 2026 Domain: Threats, Abuse & Incident Response

Phishing and ransomware remain effective because they exploit people, not only systems. Phishing uses psychology to trick employees into revealing access or approving actions, while ransomware pressures organisations through business disruption. When identity controls are weak, a single compromised account can expose a limited but still valuable slice of systems and data.

Why phishing still works when tools get better

Phishing is effective because the target is often the decision-maker, not the perimeter control. Better filtering helps, but it does not remove the attacker’s ability to create urgency, impersonate trusted senders, or push a user into approving a login, payment, token grant, or inbox rule. The real weakness is usually the human decision path, plus the fact that one valid credential can still open valuable access.

Security tools also face an asymmetric problem: the attacker only needs one convincing message, while defenders must suppress many variants without blocking normal business activity. That is why modern phishing defense depends on stronger authentication, user-verification steps for high-risk actions, and tighter control of what an approved session can do after the initial click.

For a practical view of how credential theft and social engineering drive real breaches, see The 52 NHI Breaches Report and MailChimp Breach, which both show how a single compromised account can become a broader exposure event.

Why ransomware keeps converting intrusion into business pressure

Ransomware does not need to defeat every control, it only needs to make disruption expensive enough that the victim feels pressure. Once an attacker has initial access, the path to impact is often encryption, data theft, or both, followed by threats to publish data or prolong outage. That turns a technical compromise into an operational and reputational crisis.

Ransomware remains persistent because many environments still allow broad internal movement after the first foothold. If an attacker reaches an account with excessive privilege, weak segmentation, or reused credentials, the blast radius expands quickly. The breach may start with one phish, but the impact grows because access is more capable than it should be.

The lesson is consistent across incidents: The 52 NHI Breaches Report highlights how compromised access material and lateral movement can turn a limited entry point into a much larger incident, while the Anthropic report on AI-orchestrated cyber espionage is a current reminder that automation can accelerate reconnaissance, credential collection, and exfiltration once access is obtained.

Why the defender advantage is narrower than it looks

Improved tools reduce noise, but they do not eliminate trust abuse. Phishing and ransomware both exploit the gap between detecting a suspicious event and stopping a legitimate-looking action in time. They also benefit from the fact that security teams must balance prevention with business usability, especially where email, remote access, SaaS, and identity providers are deeply connected.

That is why controls that focus only on perimeter filtering or malware signatures underperform over time. The durable control set is stronger identity assurance, reduced standing privilege, better segregation of duties, quicker revocation of suspicious access, and recovery planning that assumes some endpoints or accounts will be compromised. These measures do not promise immunity, but they reduce how far one mistake or one stolen credential can travel.

For the identity side of that problem, NIST SP 800-63 Digital Identity Guidelines is useful for thinking about phishing-resistant authentication, while NIST SP 800-207 Zero Trust Architecture helps frame why access should be continuously verified rather than assumed after initial login.

Risk and Threat Considerations

Phishing and ransomware remain high-impact because they exploit the most failure-prone part of security, the moment a human or system grants trust. When that trust is paired with weak privilege boundaries, the result can be account takeover, data theft, service disruption, and rapid lateral movement.

Failure mechanism: A convincing message, stolen credential, or malicious approval grants access that appears legitimate, then the attacker uses that access to expand privileges, steal data, or deploy encryption and extortion tooling.

Impact: Even a narrow compromise can become a material breach if the account can reach email, file stores, identity systems, backups, or privileged admin functions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementCredential theft and rotation are central to phishing and ransomware.
IA-9 — Service Identification and AuthenticationRansomware often spreads through non-human access paths and internal trust.
AC-6 — Least PrivilegeExcessive access turns one phished account into broad compromise.
Recommendation — Rotate exposed credentials quickly and enforce lifecycle controls for all high-risk accounts. Require strong authentication for service and workload access paths. Limit each account to the minimum permissions needed for its role.
NIST SP 800-63AAL2 — Authentication Assurance Level 2Stronger authentication reduces the success rate of phishing-based credential theft.
Recommendation — Use phishing-resistant authenticators for sensitive user access.
NIST Zero Trust (SP 800-207)0 — Zero Trust ArchitectureContinuous verification helps limit damage after an initial compromise.
Recommendation — Treat each request as untrusted and verify access continuously.

Practitioner Guidance

What to prioritise: Focus first on the accounts and workflows that can create the biggest blast radius, especially email, remote access, admin approval paths, and anything that can approve token grants or sensitive business actions. If those paths are hardened, a successful phish is much less likely to become a breach.

What to verify: Confirm that high-risk actions require phishing-resistant authentication or step-up verification, and that privileged access is time-bound and reviewable. Also verify that incident response can quickly revoke sessions, reset exposed credentials, and isolate affected endpoints without waiting for a full investigation to finish.

Practitioner takeaway: The goal is not to stop every phishing attempt, it is to make one stolen credential or one mistaken click insufficient to create meaningful business impact.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 27, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org