Back to the news portal
Security & DefenceVerified reportAnalysisSource analysisGlobalAmericasAsia-PacificEuropeMiddle East and Africa

Is AI changing cyberattacks—or speeding up familiar tactics?

Microsoft's 2026 Digital Defense Report says threat actors are using AI across parts of existing attack workflows while people, credentials and exposed systems remain central. Its vast telemetry offers useful scale, but the public summary does not disclose a common denominator for every headline percentage.

By The Impact of AI Editorial DeskReleased 1 October 2026 at 22:01 BST9 min read2 sources

Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern

ShareLinkedInXBlueskyRedditEmail
Key themesCybersecurityThreat intelligenceAI agentsIdentity securityPhishing
The Impact of AI analysis cover asking whether AI is changing cyberattacks or speeding up familiar tactics, with a conceptual network of identities, email and cloud systems.
AI-generated editorial illustration. It is a conceptual security network, not a depiction of a real breach, organisation or Microsoft product interface.

At a glance

  • 1Microsoft says current threat-actor use of AI is concentrated in parts of existing workflows, including reconnaissance, social engineering, malware and exploit development, rather than replacing familiar initial-access routes.
  • 2The report draws on enormous vendor telemetry—more than 165 trillion security signals processed daily—but each published percentage has its own observed population and time window, so the figures should not be combined into a universal incident rate.
  • 3The near-term operational implication is to secure identities, data and agent permissions while testing AI-specific risks such as prompt injection, excessive agency and sensitive-data exposure.

Living evidence record

Impact record IAI-1S1IXWQ

Explore the full tracker

Evidence stage

Observed

Confidence

Supported

Reporting basis

Source analysis

Independent support

Not yet

Record status

Monitoring

Last checked

1 October 2026

Source trail

2 direct sources across 1 source type.

People impact

Documented in this record.

Uncertainty

Limits and next checks are explicit.

Stages describe the evidence available—not whether a technology is good or bad. See the public method.

Related-source reporting disclosure

This record analyses 2 linked source records around the same underlying development. The extra records add method, date or context, but they do not by themselves constitute independent replication of every performance claim or predicted outcome.

The strongest present-tense finding is continuity, not science fiction

Microsoft's 2026 Digital Defense Report, released on 1 October, argues that artificial intelligence is increasing the speed, scale and tailoring of cyber activity. Yet the accompanying analysis makes a narrower and more useful claim about what the company actually observes today: threat actors are incorporating AI into reconnaissance, social engineering, malware and exploit development and post-compromise work, while much of that use remains focused on particular stages of existing attack workflows.

That distinction matters. The report is not evidence that autonomous systems have replaced human operators or that every attack now involves a model. People, valid credentials, exposed services and trusted access still feature prominently. AI can make a phishing approach more tailored or compress technical work without changing the underlying route into an organisation. For defenders deciding where to spend limited time, familiar identity and access controls therefore remain relevant even as AI-specific controls are added.[1][2]

What Microsoft measured—and what the public overview does not disclose

Microsoft describes a global vantage point spanning billions of users, millions of organisations and more than 15,000 security partners. It says its systems process more than 165 trillion security signals a day, analyse 31 million identity-risk detections on an average day, screen 5.2 billion emails daily and block 4.7 million net-new malware files each day. Much of the geographic reporting covers activity from 1 July 2025 to 30 June 2026, although several figures use different stated periods.

Scale is not the same as a representative sample. These observations arise from Microsoft's customer base, products, sensors, investigations and classification systems. The public report hub does not provide one denominator that turns every headline number into a share of all global attacks, nor does it expose raw event data for independent replication. Customers using different vendors, disconnected operational technology and incidents never detected by Microsoft can be underrepresented. The report is best read as a very large vendor-observation dataset, not a census of cybercrime.[1]

Identity and human action still dominate the route in

The report says most intrusions still begin with a person or credential rather than an exploit. Valid accounts and user execution remain leading initial-access techniques, and 52.2% of the observed valid-account intrusions involved follow-on credential theft. Microsoft also reports detecting more than 46 million business-contact impersonation attacks over the past 12 months and more than 145 million QR-code phishing attacks between July 2025 and June 2026 through Defender for Office 365.

Those numbers describe detections within named Microsoft systems, not the number of unique victims or successful compromises. A campaign may generate many events, and detection coverage changes over time. Still, the pattern supports practical priorities: phishing-resistant authentication, constrained privileges, rapid revocation, browser and endpoint protections, and monitoring that connects identity, email, cloud and application signals. AI-generated language increases the possible volume and variation of lures; it does not make compromised credentials harmless.[1]

Agents widen the attack surface because they can act

Microsoft separates two related problems: attackers using AI against conventional systems, and AI systems themselves becoming targets. An enterprise agent may read sensitive files, call APIs, use tools, remember prior instructions and act under a service identity. Its usefulness comes from those connections. The same connections can allow an injected instruction, stolen credential or over-broad permission to produce a larger consequence than a standalone chatbot response.

The report groups agent risk into five classes: prompt and intent manipulation, sensitive-data exposure, identity and privilege compromise, excessive agency, and operational-integrity failures affecting configuration, memory, training data, software supply chains or logs. This is a security model rather than an incidence study. It identifies plausible control points—scoped credentials, allow-listed tools, runtime gates, output review, immutable logs and revocable agent identities—but does not publish a measured probability for each risk class.[1][2]

A malicious extension case shows why AI data needs ordinary controls

The report highlights a December 2025 case in which Microsoft found a malicious browser extension with more than 600,000 installs harvesting ChatGPT and DeepSeek conversation histories. Microsoft says almost 10,000 organisations were affected before the activity was mitigated. The case illustrates a concrete pathway: prompts and model conversations can contain source code, system architecture, customer information and credentials, while an extension with browser access can collect them without attacking the model itself.

The public summary does not provide a full incident denominator, independently audited loss estimate or the number of individual records exposed. It should not be generalised into a failure rate for AI assistants. The operational lesson is nonetheless specific: organisations need extension governance, data-loss prevention, secrets scanning and clear rules about what staff may put into conversational systems. Deploying an approved model does not secure the browser, identity or data flows around it.[1]

The report's percentages cannot all share one denominator

The public overview reports that 63% of observed intrusions involved data theft, exposed cloud workloads were attacked after an average 5.3 hours, and 93% of voice-phishing calls kept a victim on the line long enough for social engineering to begin. It also says 89% to 95% of email phishing attachments led toward credential theft and that ransom detonations against enterprises increased 15.8% year on year. Each statement refers to a different observed activity set.

Readers should resist stacking those figures into a single narrative of universal risk. The page does not display the count behind every percentage or a common sampling frame, and some measures reflect Microsoft's product detections while others arise from incident-response observations. Changes in customer mix, sensor coverage and detection rules can also affect year-on-year comparisons. The figures are useful indicators for investigation and control design, but they are not household probabilities or forecasts for a particular organisation.[1]

People experience the consequences through access and trust

For employees and customers, the immediate effects are not abstract model capabilities. They are fraudulent messages that look more personal, stolen accounts, exposed conversation histories and disruption to services. A security programme that concentrates only on detecting AI-written text can miss the account takeover or misconfigured permission that makes the attack consequential. Verification should focus on requests, identities and authorised actions, not stylistic guesses about whether a message was generated.

For security staff, AI can also help correlate signals, summarise routine investigations and search code for weaknesses. Microsoft has a commercial interest in that conclusion because it sells security and AI products, including Security Copilot. Vendor-reported productivity figures therefore need independent evaluation with comparable teams, task definitions, error measures and total costs. Automation can reduce repetitive work while still producing false confidence if summaries omit context or actions are allowed without review.[1][2]

Global reach does not erase regional visibility gaps

Microsoft maps customer impact across the Americas, Asia-Pacific, Europe, the Middle East and Africa using activity observed from July 2025 through June 2026. It reports the United States, Taiwan, the United Kingdom and Israel as the highest observed event-count countries in their respective regions, and government, information technology, and research and academia as leading targeted sectors. Those rankings reflect both adversary interest and where Microsoft has visible customers and telemetry.

Countries with fewer connected sensors, different cloud providers or limited incident reporting may appear quieter without being safer. Conversely, a country with extensive digital infrastructure and mature detection can produce more observed events. The report does not justify converting event counts into per-person national risk or ranking governments by preparedness. Local authorities and organisations need their own asset inventories, incident data and threat context alongside a global vendor view.[1]

What would change the assessment

The evidence would support a stronger claim that AI has transformed attacks if independently replicable incident datasets showed AI materially increasing successful compromise rates, reducing operator skill requirements or enabling novel capabilities after controlling for detection and reporting changes. Useful disclosure would include the number of incidents examined, explicit classification criteria for AI involvement, false-positive checks, and comparisons with matched non-AI attacks across multiple providers and regions.

For now, the responsible reading is two-sided. AI is already present in several attack and defence tasks, and agents create new combinations of identity, data and tool risk. But Microsoft's own analysis says underlying methods often remain familiar. Organisations should secure the AI systems they deploy and test agent boundaries, while continuing the less glamorous controls that stop real intrusions: strong identity verification, least privilege, rapid patching, monitored data access and practiced response.[1][2]

What this means for people

  • More tailored phishing and impersonation can make it harder for staff and customers to judge a request by language quality alone.
  • Conversation histories may contain sensitive work and personal information even when the underlying model is not breached.
  • Security teams need authority and time to govern agent identities and permissions as well as conventional employee accounts.

Global context

Microsoft reports worldwide observations across four broad regions, but visibility follows its customers, products and partners. Event counts should not be treated as population-adjusted country risk. The central conclusion—that AI currently accelerates parts of familiar attack workflows while identity remains crucial—is globally relevant, but the prevalence of particular techniques needs local and multi-vendor evidence.

What the evidence does not yet show

  • The report is produced by a major security and cloud vendor using its own customer, product, partner and investigation telemetry.
  • The public overview does not disclose the raw count, common denominator or classification method behind every headline percentage.
  • Different metrics cover different products and periods, so they cannot be combined into one global attack rate.
  • Observed events are not necessarily unique attacks, successful compromises, affected people or independently verified losses.
  • Microsoft sells AI and security products, creating a commercial interest that readers should consider when evaluating recommended controls and productivity claims.

What to watch next

  • Independent multi-vendor datasets that classify and compare AI-enabled with non-AI attacks using published criteria.
  • Measured incident rates for prompt injection, excessive agency and agent-identity compromise in production systems.
  • Whether organisations adopt revocable agent identities, scoped credentials, tool allow-lists and human approval for consequential actions.
  • Field evidence on whether AI improves defenders' resolution quality and not only the speed of summaries.

Evidence trail

Sources used for this report

Links checked 1 October 2026

This report is labelled source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.

Continue the story

Related reporting

All reports

Security & Defence

Did AI agents hack government websites—or only attempt to?

California has served OpenAI with an investigative subpoena over agent-related cybersecurity incidents. The update separates a compulsory information request from any finding of liability, while preserving the evidence limits around the reported government-site activity.

8 min · 4 sources

Reader discussion

Add evidence, experience or a question

No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.

Do not include personal, confidential or unlawful information.

Published reader notes

0

No published reader notes yet. You can start the evidence-led discussion above.

Prefer a private correction or response? Contact the newsroom.