Microsoft Digital Defense Report 2026: Data theft was part of 63% of observed breaches

The Microsoft Digital Defense Report 2026 describes observed attacks on identities, cloud environments, supply chains, and edge devices. The company also warns of AI’s growing role.

The document titled Microsoft Digital Defense Report 2026, published by Microsoft on October 1, draws on the company’s telemetry and intelligence data from several specified periods. According to Microsoft, 63% of observed breaches involved data theft, and exposed cloud workloads were attacked an average of 5.3 hours after discovery.

The report describes an environment involving identity abuse, social engineering, supply chain attacks, and compromises of edge devices. Microsoft also considers artificial intelligence a factor that may multiply both malicious activity and defensive capabilities.

Microsoft Digital Defense Report and observed attacks

Microsoft states that between January 2025 and June 2026, 25.5% of the malicious activity it observed targeted customers in the United States. According to the company’s methodology, government agencies and services were the most affected sector, accounting for 27% of observed activity.

These figures do not represent a complete measurement of global cybercrime. They are observations from Microsoft’s own sources, and their methodology or representativeness has not been independently confirmed by an external authority. The figures should therefore be read as a picture of activity visible within this particular ecosystem.

A major theme of the document is the speed of attackers’ progress in cloud environments. Microsoft reported an average time of 5.3 hours from discovery to an attack on exposed cloud workloads. According to the report’s findings, this highlights the importance for security teams of rapid response, visibility across environments, and exposure management.

Digital identities, people, and the supply chain

The report identifies identity abuse and social engineering as key risk areas. This also includes open-source supply chain compromise and attacks on edge devices.

In response to these findings, Microsoft lists measures such as phishing-resistant multifactor authentication, limiting privileges, data protection, correlating telemetry across environments, and continuous exposure management. The report presents these as areas organizations should consider when prioritizing their defenses.

AI as an attack and defense factor

Microsoft describes AI as a multiplier of malicious activity and also warns of the growing risk posed by AI agents. However, the company’s claim that AI is “changing the physics of cybersecurity” remains its assessment, not an independently verified fact.

The report itself does not confirm a specific new mass-exploited vulnerability or an ongoing widespread campaign associated with AI agents. Further signals to monitor will therefore include independent analyses of the methodology and key statistics, possible alerts from security agencies, and new evidence of the real-world misuse of AI in automated vulnerability discovery or supply chain attacks.

Sources

Verified and updated: 10/02/2026 06:23

Sharing