
The cyberattack dealership employees need to worry about may increasingly look like a perfectly normal login.
A new report from Proton Dealership IT and Cybersecurity found 79 per cent of ransomware attacks now begin with an identity-based approach, while 82 per cent of detections involved no malware. Instead, attackers are increasingly using stolen identities, hijacked sessions and legitimate administrative tools to appear like authorized users.
The findings are included in Proton’s October report, Attackers Would Rather Log In Than Break In: An Examination of Cybersecurity in 2026 for Retail Automotive Dealerships.
One finding illustrates how the threat is changing: multi-factor authentication was enabled in 97 per cent of breaches that began with credentials. Proton said techniques such as adversary-in-the-middle phishing can capture an authenticated session after a user has logged in, while information-stealing malware can harvest session cookies and trusted-device status.
The shift is also showing up in ransomware. Malicious email accounted for 26 per cent of ransomware root causes and phishing another 24 per cent, together representing half of incidents cited in the report. Exploited vulnerabilities, previously the leading cause for three consecutive years, fell from 32 per cent to 18 per cent.
Proton cautions that the decline does not mean vulnerabilities have become unimportant. Rather, email and identity-based attacks have grown more quickly as alternative ways into business systems.
The report recommends putting greater emphasis on monitoring identities and authenticated sessions, alongside existing measures such as patching, email filtering, employee training and incident-response planning.


