Microsoft’s Digital Defense Report 2026 says AI is shortening the time defenders have, and it puts figures on where that time is going. The report, covering July 2025 to June 2026 and published on Microsoft’s Digital Defense Report page, also names identity the primary control plane for defense and flags AI agents as a fast-growing new estate to protect.

What Microsoft says has changed

The first of the report’s top takeaways reads: “AI is compressing attack timelines, lowering the cost of sophisticated capabilities, and enabling attackers to operate with greater speed, scale, and autonomy.” The same takeaway adds that those capabilities can also strengthen defense by speeding up discovery, analysis, prioritization and response. Microsoft’s shorter version of the argument is “AI is changing the physics of cybersecurity.”

That is a claim about tempo, and the report backs it with telemetry. Microsoft says its security operation processes more than 165 trillion signals a day and screens an average of 5.2 billion emails daily, so the figures below describe what Microsoft observes across its own customer base. They are a strong indicator of the market, not a census of every organization.

Media Partner

Web3 x AI Fusion — Media Partner

The figures worth keeping

Several numbers bear directly on how a security team spends the next quarter.

  • Microsoft reports that 63% of intrusions it observed involved data theft, and gives 5.3 hours as the average time before exposed cloud workloads were attacked.
  • In intrusions that began with valid accounts, 52.2% involved follow-on credential theft. Across critical infrastructure, 78% of observed attack techniques used cloud identity abuse.
  • Between July 2025 and June 2026 Microsoft detected more than 145 million QR-code phishing attacks. It says 89% to 95% of email phishing attachments led to a credential theft effort, and it counted more than 46 million business contact impersonation attacks over 12 months.
  • Ransom detonations against enterprises rose 15.8% year on year. Government agencies were the most affected sector at 27%, ahead of information technology at 17% and research and academia at 14%.

One case study runs the other way. Microsoft says the disruption of the Tycoon2FA phishing service reduced that activity by 95% by June 2026, which shows what coordinated takedowns can do when a service sits behind a lot of campaigns.

AI agents as a new estate to defend

The report says “88% of enterprises are already experimenting with AI agents,” with 82% of leaders planning broader rollouts within 12 to 18 months. It cites industry projections of roughly 1.3 billion AI agents in production by 2028. Microsoft sorts the risk into five classes: prompt and intent manipulation, sensitive data exposure, identity and privilege compromise, excessive agency, and operational integrity.

The report gives a concrete case. A malicious browser extension with more than 600,000 installs harvested ChatGPT and DeepSeek conversation history and reached nearly 10,000 organizations before it was mitigated in December 2025. The speed side of the same problem is the subject of our opinion on AI-run ransomware beating the response clock.

Where the report points defenders

Microsoft’s recommendations cluster around four ideas. It says “Identity is the primary control plane for defense,” and pairs that with phishing-resistant multi-factor authentication and privileged access enforcement. It calls signal correlation through shared threat intelligence “one of the highest-leverage strategic variables under the defender’s control.” For data, it asks organizations to apply “sensitivity-aware access and least-privilege controls” as AI systems reach information at a scale that was not possible before. And it recommends moving from reactive incident response toward proactive threat exposure management, built on asset visibility and detection coverage.

What it means for the security leader

This section is our read, not Microsoft’s.

Newsletter

Get the week's best tech coverage.

Free. Read by thousands of HR, tech, and business leaders.

First, an average of 5.3 hours before exposed cloud workloads are attacked means an exposure window counted in business days is not a control. Teams that wait for a vendor advisory before starting a patch clock are already behind that number, which is the case we made in our opinion on starting the patch clock on release day. The delay between a fix and its disclosure is also a window attackers use, as we reported in our piece on Zimbra probing before disclosure.

Second, the identity figures point to where hardening pays most. If 52.2% of valid-account intrusions end in more credential theft and 78% of critical infrastructure techniques abuse cloud identity, then the accounts attackers already hold matter as much as the perimeter they crossed. Session and token revocation, tiered administration and standing-privilege reviews belong on the list ahead of new detection tooling.

Third, AI agents should be inventoried the way service accounts are. An agent that holds credentials and can act on a user’s behalf is an identity with a privilege level, and the report’s own risk classes of excessive agency and identity and privilege compromise say as much. If the business is among the 82% planning wider rollouts, the access review has to come before the rollout.

Fourth, the report is a vendor’s account of its own telemetry and it argues for using AI in defense. Read the figures as direction and verify them against your own logs before they set a budget.

What to do in the next 30 days

List every internet-facing system and record how long a critical patch takes from vendor release to production. Enforce phishing-resistant multi-factor authentication for administrators first. Review which service principals, API keys and AI agents hold standing privileges, and remove the ones nobody can justify. Check that you can revoke active sessions and tokens, not only reset passwords, and test that procedure once before you need it.

Source: Microsoft, Digital Defense Report 2026