---
title: Microsoft report shows phishing-driven intrusions rising to 23 percent
url: https://www.dataloco.com/en/microsoft-report-shows-phishing-driven-intrusions-rising-to-23-percent
published: 2026-10-09T19:21:12+00:00
language: en
section: Security
source: https://www.zerounoweb.it/cyber-security/cybersecurity-phishing-in-forte-crescita-lai-spinge-gli-attacchi/
organizations: Microsoft
publisher: Dataloco
---

# Microsoft report shows phishing-driven intrusions rising to 23 percent

Microsoft reported that intrusions attributable to phishing increased from 7 percent to 23 percent in 2026, according to its Digital Defense Report. The report, published on October 1, 2026, details how these attacks are expanding in scale and complexity. Data theft occurred in 63 percent of the observed intrusion cases. The findings cover security signals analyzed by Microsoft teams from July 2025 to June 2026.

The report highlights that compromised accounts can lead to access to other credentials and movement within cloud environments. These intrusions can extend to multiple systems and organizations through their interconnections. A single compromised account may open access to connected services and suppliers. This propagation occurs through digital identities, infrastructure, and third-party software components.

In the first half of 2026, Italy ranked 14th globally and fifth in Europe for the frequency of hostile cyber activity directed at Microsoft clients. The report notes that exposed cloud workloads were attacked on average after 5.3 hours. Social engineering techniques were used to exploit human interaction for access and credentials. Microsoft detected over 46 million impersonation-based attacks in corporate emails. In voice phishing, 93 percent of attacks kept the victim on the phone long enough to initiate social engineering. Email phishing attachments led to credential theft attempts in a range of 89 percent to 95 percent of cases.

User actions, valid account usage, social engineering, and phishing constituted 73.3 percent of initial access attempts. Attackers use legitimate tools, cloud services, and administrative functions to blend malicious behavior with normal user operations. Techniques include phishing that interrupts authentication, abuse of application permissions, and exploitation of application programming interfaces. Password spraying attempts, which test passwords on numerous accounts, are also part of these methods.

Microsoft Incident Response observed a recurring sequence where the compromise of a human identity is followed by the discovery of credentials belonging to non-human identities, such as applications and services. These accesses are used to increase privileges and achieve goals like data exfiltration or installing command and control tools. In 52.2 percent of intrusions involving valid accounts, attackers stole additional credentials. This cycle allows one compromise to fuel other accesses, support lateral movement, or provide credentials for sale on the dark web.

The report describes state-sponsored operations from China, Iran, North Korea, and Russia evolving toward more persistent and scalable access. These activities exploit legitimate authentication flows, compromised accounts, and cloud-based information collection. State-sponsored actors and ransomware groups continue to exploit publicly disclosed vulnerabilities, particularly in internet-exposed infrastructure, identity management systems, and third-party software. The interval between vulnerability disclosure and exploitation can narrow to a few days, with some cases showing exploitation within 24 hours of discovery.

Artificial intelligence is accelerating attacks by helping identify vulnerabilities, generating customized malware, and accelerating credential searches, lateral movement, and data exfiltration. In social engineering, AI increases campaign volume and adapts content to recipients. For sophisticated actors, AI can compress attack sequences from days to seconds. For less experienced actors, it makes persistence and personalization capabilities accessible that were previously reserved for better-resourced organizations. Microsoft assesses that attackers are currently gaining early advantages from these technologies.

## This story in other languages

- [Svenska](https://www.dataloco.com/sv/phishing-attacker-okar-kraftigt-medan-artificiell-intelligens-accelererar-hotbilden)
- [Português (Brasil)](https://www.dataloco.com/pt-br/intrusoes-por-phishing-crescem-e-inteligencia-artificial-acelera-ataques-ciberneticos)
