VPN Without MFA: Ransomware's Favourite Entry Vector in Spain in 2026
There is one finding that appears in virtually every forensic analysis of ransomware attacks in Spain in 2026: initial access does not happen through an exotic technical vulnerability. It happens through a valid credential used against a VPN or remote desktop that has no multi-factor authentication.
The Akira group — one of the most active in Spain this year — has a recognisable victim profile: companies with Cisco VPN concentrators accessible from the internet without MFA. RansomHub, Qilin and 8Base have similar vectors. The infostealers Lumma, RedLine and Stealc circulate on dark web markets selling access to specific Spanish companies for hundreds of euros. An attacker buys the access, logs in with legitimate credentials, and the VPN cannot tell the difference between the real employee and the intruder.
The conclusion is uncomfortable but clear: a VPN without MFA is not a security control — it is a door with the key left under the mat. And in the 2026 threat environment, that door is being tested systematically and automatically.
Why VPN Without MFA Is the Most Exploited Vector in Spain
Step 1 — Credential acquisition. Credentials are not stolen at the moment of the attack. They are gathered in advance. Infostealers are malicious programmes that install silently on an employee's device — through an email attachment, software downloaded from an unofficial source, a malicious browser extension — and extract all stored passwords, including VPN credentials. Those credentials are sold on specialised dark web markets, where any attacker can purchase access to a specific Spanish company for prices ranging from a few hundred to several thousand euros, depending on the account's privilege level.
Step 2 — Automated reconnaissance. Before using the credentials, attackers verify what is on the other side. The SonicWall Cyber Protect 2026 report documents that bots perform more than 36,000 vulnerability scans per second in Spain. Each internet-connected device receives an average of 93,474 intrusion attempts per year — the highest figure in all of Europe.
Step 3 — Access with valid credentials. With the purchased credentials, the attacker logs into the VPN exactly as the legitimate employee would. The VPN verifies the username and password, the data is correct, and access is granted. Without MFA, there is no second verification layer. Without network segmentation, that initial access opens up a flat network where the attacker can move freely toward the most critical systems.
Step 4 — Lateral movement and attack preparation. The attacker does not act immediately. They explore the network, identify backup servers, accounting systems, customer databases. They move laterally using legitimate operating system tools — PowerShell, WMI, remote administration tools — that conventional detection systems do not flag as malicious because they are legitimate tools being used in an anomalous way.
VPN Vulnerabilities Grew 82.5% in the Past Year
The problem is not just the absence of MFA. It is the combination of absent MFA and unpatched firmware versions. Every time a critical vulnerability is published in a popular VPN concentrator — Cisco, Fortinet, Palo Alto, SonicWall — attackers immediately launch massive automated campaigns to identify which companies are running that vulnerable version before they apply the patch.
CISA issued alerts in 2026 about active attacks against vulnerabilities in Fortinet and Microsoft SharePoint Server. Spanish companies using those products that have not applied the available patches are being actively scanned right now.
What Zero Trust Changes Compared to VPN
With VPN: the concentrator is internet-facing (required for it to work), accepts inbound connections, and once the user authenticates they have broad network access. If credentials are compromised and there is no MFA, the attacker enters and can move freely across the entire network.
With ZTNA: there is no internet-facing entry point. Connectors establish outbound connections to the control platform — an attacker scanning from the internet finds no service to attack. Even if credentials are compromised, access is limited to the specific resource the user is authorised for — not the full network. And every access is logged, enabling real-time detection of anomalous behaviour.
ConnectaSec implements this model without requiring changes to the existing firewall and without additional hardware. Deployment takes minutes, and migration can coexist with the current VPN during the transition.
The Akira Case: Why It Targets Cisco VPN Without MFA
Akira is the most well-documented example of the most frequent attack pattern in Spain in 2026. Their playbook is known from multiple forensic investigations: they identify companies using Cisco ASA or Cisco FTD, verify if the SSL VPN service is internet-exposed, check for available credentials on infostealer marketplaces or use password spraying — testing common passwords across many accounts rather than many passwords against a single account, to avoid triggering lockout systems. Without MFA, one valid credential grants access. Once inside, their lateral movement playbook is defined: find the backup server first, disable it, then move to the most critical systems.
The direct antidote is twofold: MFA to ensure a stolen credential alone is not enough to get in, and Zero Trust to ensure that once inside, the attacker cannot move freely toward critical systems.
Frequently Asked Questions
I have MFA enabled but still use a VPN — am I protected?
MFA significantly reduces the risk of initial access through compromised credentials. But it does not eliminate the problem that, once inside with legitimate credentials and MFA, the user still has broad network access. Nor does it eliminate the risk of vulnerabilities in the VPN concentrator itself. MFA is necessary but not sufficient if the underlying access model remains flat network.
How do I know if my VPN credentials are circulating on the dark web?
Services like HaveIBeenPwned allow you to check whether a corporate email appears in known data breaches. The simplest signal: if an employee has installed software from unofficial sources or opened suspicious attachments, their credentials may already be compromised without their knowledge.
Can I keep my VPN and add Zero Trust on top?
Yes. The recommended migration is incremental: deploy ZTNA alongside the VPN, migrate the highest-risk access first (external vendors, access to critical systems), validate operations, and retire the VPN progressively. ConnectaSec is designed for this coexistence — no changes required to the existing firewall.
Is password spraying detectable?
It is difficult to detect precisely because it is designed not to trigger lockout systems. Instead of many attempts against one account, it makes few attempts against many accounts. Conventional detection systems identify this as normal activity. Systems with MFA neutralise it because even if the attacker guesses the password, they cannot complete the second factor.
Summary
→ VPN without MFA is the most exploited initial access vector by ransomware groups active in Spain in 2026 — Akira, Qilin, RansomHub and 8Base all use it systematically.
→ Credentials are obtained before the attack through infostealers or purchased on dark web markets. The attacker enters with a legitimate key, not by forcing the door.
→ Vulnerabilities in VPN concentrators grew 82.5% in the past year. Every published vulnerability triggers a wave of automated scans within hours.
→ ZTNA eliminates the visible entry point: no exposed ports, no VPN concentrator to attack. Even if credentials are compromised, access is limited to the specific authorised resource.
→ MFA is necessary but not sufficient if the access model remains flat network. The right combination is MFA + Zero Trust: verification at the access point and least privilege once inside.
Does your VPN have MFA enabled at every access point — and control what the user can do once inside?
In 30 minutes we analyse your current remote access model and explain how to close the two vectors most exploited by attackers in Spain in 2026.
Request free analysis →