Microsoft Digital Defense Report 2026
In an era of interconnected risk, attackers are increasingly exploiting the trusted identities, systems, relationships, and services organizations rely on most. The 2026 Microsoft Digital Defense Report reveals a fundamental shift in cybersecurity with the interconnected digital ecosystem and the rise of AI. This report helps organizations decode what is needed to secure AI and build resilience across the interconnected systems they depend on.
Share
Our unique vantage point
Microsoft’s global presence—spanning billions of users, millions of organizations, and a vast network of partners—provides us with an unparalleled perspective on the cybersecurity threat landscape.
165+ trillion
Security signals processed daily
15,000+
Partners in our security ecosystem, making it one of the largest in the world
4.7 million
Net new malware file blocks every day
35,000
Full-time equivalent security engineers employed worldwide
31 million
Identity risk detections analyzed in an average day
5.2 billion
Emails screened daily on average to protect users from malware and phishing
Top 10 takeaways from this report
AI is changing the physics of cybersecurity
AI is compressing attack timelines, lowering the cost of sophisticated capabilities, and enabling attackers to operate with greater speed, scale, and autonomy. But the same capabilities can strengthen defense by accelerating discovery, analysis, prioritization, and response. Security organizations must prepare for an environment in which both attackers and defenders increasingly operate at machine speed.
Attackers are already targeting AI as another attack surface
Threat actors can exploit AI to do things like execute malicious commands, steal AI serving capacity, and exfiltrate data. As AI becomes ubiquitous in the workplace and at home, it has become both a tool and a target for attackers.
People remain a heavily exploited initial-access path
Threat actors continue to target user behavior through user execution, ClickFix-style social engineering, phishing, and impersonation. These techniques remain effective even as AI changes their speed, scale, and personalization.
Identity is the primary control plane for defense
Attackers consistently take advantage of unnecessary privileges, persistent access, and weak identity governance. This is why phishing-resistant multifactor authentication (MFA) and passkeys, disciplined identity hygiene, tiered administration, and strong privileged-access enforcement remain the best safeguards against cyber attacks. That control plane now spans both human and non-human identities, including applications and agents.
Signal correlation through shared threat intelligence is key to defense at multiple levels
The degree to which a defender’s systems share and correlate threat intelligence is one of the highest-leverage strategic variables under the defender’s control. Signal cross-correlation can reveal attack patterns that remain invisible when endpoint, identity, cloud, application, email, and network telemetry are analyzed in isolation.
Emerging threats facilitate stealthier attacks, operating at a larger and faster scale
Over the next year, Microsoft sees the most significant threats coming from:
- Open-source supply chain compromise
- Attacks against edge devices
- AI as a force multiplier for malicious activity
These threats are emerging as AI-generated synthetic content erodes confidence in digital communications. As authentic and synthetic content become harder to distinguish, individuals can become simultaneously more vulnerable to manipulation and less confident in legitimate sources. This shifts the security model from implicit trust toward explicit verification.
Protecting data is even more important as AI expands access at scale
Trusted AI depends on trusted, well-governed data. Data protection has always been a key priority, and now that AI systems and agents can reach and act on sensitive information at unprecedented scale, it’s more crucial than ever. Organizations should reduce oversharing, apply sensitivity-aware access and least-privilege controls, and govern how data is discovered, used, and shared across AI, cloud, and application environments.
The future of defense involves rethinking how we protect our assets from reactive incident response to proactive, continuous discipline
Defenders must shift from tool-centric vulnerability management to threat exposure management. At the core of this is:
- Asset visibility
- Continuous vulnerability awareness
- Intelligence-driven threat detection
- AI-accelerated insight
This means reporting metrics should shift from number of patches deployed to exposure reduced, detection coverage increased, and time-to-mitigate compressed.
National and international policy decisions will shape the future of cybersecurity
In an increasingly contested landscape, cybersecurity demands clearer rules, credible accountability, and sustained cooperation. Strengthening protections for critical infrastructure, advancing operational accountability, and preserving an open, secure, and resilient digital environment must be a priority for governments on both a domestic and international level.
Resilience must be a core outcome of cybersecurity planning
Retain the existing focus on reducing exposure, detecting threats faster, adapting to changing risks, and maintaining operations. This preserves resilience as the outcome without competing with identity, secure foundations, data, and the three-part operating model for ‘primary’ status.
Key figures from the report
63%
Of intrusions involved data theft
5.3 hours
Average time before exposed cloud workloads were attacked
93%
Of voice phishing attacks kept the victim on the line long enough to begin social engineering
46 million+
Business email impersonation attacks detected over the past 12 months
89-95%
Of email phishing attachments led to a credential theft effort
Cyber threats: Worldwide customer impact in 2026
Countries where customers are most frequently impacted by cyber threats.
Source: Microsoft Threat Intelligence
This map pulls from data from July 1, 2025 – June 30, 2026 on how frequently customers are targeted by malicious activity in each country. The most impacted countries are compared to other countries in their region, both as a percentage of regional activity and a rank of regional activity.
Additional report topics
Take a deeper dive into our 2026 Microsoft Digital Defense Report. Navigate to specific sections of the report below.
Introduction
AI
The Threat Landscape
Cybercrime
Resilience
Beyond our report
Follow us






