MICROSOFT’S Digital Defense Report 2026 warns that threat actors are using AI to compress major attack lifecycles from days to minutes, creating a rapidly accelerating risk for defenders. The report notes attackers first gain access through techniques such as phishing and AI-assisted vulnerability discovery in source code, binaries, and AI-serving systems, with social engineering campaigns now being customised at scale. AI is also used to generate tailored malware.
In post-compromise activity, AI shortens the data exfiltration, credential discovery and lateral movement phases to minutes, and highly sophisticated campaigns can require minimal operator intervention. The findings reference a shift towards autonomous, agentic AI attacks, including the JadePuffer campaign identified in July, suggesting future attacks could operate with even less human oversight.
The recommended response is for defenders to invest in AI-based protections that can connect signals, threat intelligence and surveillance to keep pace with the attackers.
The report highlights an increasingly interconnected risk landscape, with organisations’ ecosystems spanning networks, partner and vendor relationships, identities, data, applications, cloud services and AI systems. Identity remains the most important surface, and Microsoft urges stronger controls such as phishing-resistant MFA, tiered administration and strict privileged access enforcement.
Phishing as an initial access vector rose from 7% of incidents in 2025 to 23% in 2026, while the share of social engineering fell overall, and exploitation of public-facing apps grew from 15% to 24%—likely tied to AI-enabled vulnerability discovery. Government, IT and research sectors were the most targeted in 2026, with the US leading regional attack volumes at 25.5%.