Skip to content
June 27, 2026
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy

Microsoft News Now

The Home of Microsoft News Today

Primary Menu
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Light/Dark Button
Subscribe

Home - News - Microsoft Digital Defense Report 2025 says extortion and ransomware now drive most cyberattacks, with MFA blocking 99% of identity threats

  • News
  • Microsoft Announcements

Microsoft Digital Defense Report 2025 says extortion and ransomware now drive most cyberattacks, with MFA blocking 99% of identity threats

The Microsoft Digital Defense Report 2025: 52% of attacks are extortion/ransomware; MFA can stop 99% of identity-based attacks.
Dave W. Shanahan 8 months ago (Last updated: 8 months ago) 4 minutes read
Microsoft Digital Defense Report 2025 says extortion and ransomware now drive most cyberattacks, with MFA blocking 99% of identity threats

The Microsoft Digital Defense Report 2025 finds that over half of cyberattacks with known motives in the past year were driven by extortion or ransomware, underscoring a decisive tilt toward financially motivated crime over classic espionage. The report, authored by CVP Amy Hogan‑Burney with CISO Igor Tsyganskiy, covers July 2024 through June 2025 and frames the threat landscape as increasingly opportunistic, automated, and AI‑accelerated.​

The Microsoft Digital Defense Report 2025 shows how threats are evolving faster than ever, fueled by AI. https://t.co/wWinYWQVuL

Key insights from report include:

-More than 50% of cyberattacks with known motives had financial objectives such as extortion or ransom, while only…

— Microsoft Threat Intelligence (@MsftSecIntel) October 16, 2025

Headline stats

In 80% of incidents Microsoft investigated, attackers sought to steal data, reinforcing profit as the primary motive rather than intelligence gathering. Espionage-only operations represented just 4% of cases with known motives, while at least 52% were tied to extortion or ransomware, confirming the dominance of financially driven attacks.​

Scale of Microsoft’s visibility

Microsoft Digital Defense Report 2025 says extortion and ransomware now drive most cyberattacks, with MFA blocking 99% of identity threatsMicrosoft reports processing more than 100 trillion security signals daily, blocking about 4.5 million net new malware files each day, analyzing 38 million identity risk detections, and screening roughly 5 billion emails for malware and phishing on an average day. This telemetry underpins the company’s conclusions about attacker focus areas and the defensive controls most likely to reduce risk quickly.​

“Signing in,” not breaking in

More than 97% of identity attacks are password attacks, and identity-based attacks surged 32% in the first half of 2025, driven by credential leaks and a spike in infostealer malware that harvests credentials and session tokens at scale. Microsoft highlights that phishing-resistant MFA can stop over 99% of these attacks even if an adversary has valid credentials, making it the single highest‑impact control to deploy broadly and fast.​

Critical sectors under pressure

Microsoft Digital Defense Report 2025 says extortion and ransomware now drive most cyberattacks, with MFA blocking 99% of identity threats

Hospitals, local governments, and other public services remain prime targets because operational urgency, sensitive data, and tight budgets amplify the impact of disruption and the likelihood of ransom payment, causing real-world harms like delayed emergency care and canceled classes. Ransomware crews exploit these pressures, rapidly encrypting systems to force difficult choices under time-sensitive conditions.​

Nation-state activity

China continues wide-ranging data theft and espionage, accelerating its exploitation of newly disclosed vulnerabilities and probing NGOs to expand insights beyond government channels, according to Microsoft’s tracking. Iran has broadened its targeting from the Middle East to North America and recently hit shipping and logistics firms in Europe and the Persian Gulf, likely pre‑positioning for possible interference with commercial operations.​

Russia, while fixated on the war in Ukraine, is increasingly targeting small businesses in NATO countries as lower-resourced pivot points into larger organizations, reflecting a 25% increase in affected NATO countries year over year outside Ukraine. North Korea remains focused on revenue and espionage, including state-affiliated remote IT workers applying for jobs worldwide and, when exposed, turning to extortion to generate funds for the regime.​

AI on both sides

Microsoft Digital Defense Report 2025 says extortion and ransomware now drive most cyberattacks, with MFA blocking 99% of identity threats

Attackers are using AI to automate phishing, craft synthetic media, accelerate vulnerability discovery, and generate adaptive malware, increasing both volume and believability of campaigns. Defenders are also leveraging AI to close detection gaps, flag suspicious identity activity earlier, and raise the overall cost and complexity for attackers, with Microsoft urging organizations to secure their AI systems and train teams accordingly.​

Microsoft actions and guidance

Microsoft’s Digital Crimes Unit helped disrupt the Lumma Stealer ecosystem in May alongside the U.S. Department of Justice and Europol, targeting a key infostealer supply line for credential theft at scale. The company reiterates its Secure Future Initiative commitments and stresses that legacy defenses are no longer sufficient, calling for modern, AI‑assisted protection and deeper collaboration across industry and government.​

What organizations should do now

Adopt phishing-resistant MFA everywhere, especially for admins and high-risk roles, to block over 99% of identity-based attacks and reduce the blast radius of credential leaks and infostealers. Modernize legacy tooling, segment critical workloads, and monitor identity signals continuously while securing emerging AI systems and educating staff to counter evolving social engineering and deepfake risks.​

About The Author

Microsoft Digital Defense Report 2025

Dave W. Shanahan

I’m Dave W. Shanahan, a Microsoft enthusiast with a passion for Windows, Xbox, Microsoft 365 Copilot, Azure, and more. I started MSFTNewsNow.com to keep the world updated on Microsoft news. Based in Massachusetts, you can email me at davewshanahan@gmail.com.

See author's posts

Like this:

LikeLoading…

Related


Discover more from Microsoft News Now

Subscribe to get the latest posts sent to your email.

Tags: CybersecurityLinkedinMicrosoftSecurityTwitter

Post navigation

Previous: Windows details strict security model for Copilot Actions and agentic AI on Windows 11
Next: Turn Off Sticky Keys on Windows 11 Fast (And Stop It Coming Back)

Related Stories

Next Week on Xbox: Every Bizarre New Game Hitting June 29–July 3
  • News
  • XBOX and Gaming

Next Week on Xbox: Every Bizarre New Game Hitting June 29–July 3

Dave W. Shanahan 11 hours ago 0
XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs
  • News
  • XBOX and Gaming

Unfortunately Expected: XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs

Dave W. Shanahan 2 days ago 0
XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend
  • News
  • XBOX and Gaming

XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend

Dave W. Shanahan 2 days ago 0

AccessibilityAmazonAndroidAuthenticationAzureCall of DutyCopilotCybersecurityDeveloperEnterpriseFree Play DaysGamingGenerative AIGitHubGoogleLinkedinMicrosoftMicrosoft 365Microsoft 365 CopilotMicrosoft CopilotMicrosoft EdgeMicrosoft StoreMicrosoft TeamsNext Week on XBOXOpenAIOutlookPatch TuesdayPrivacySecuritySettingsSharePointSurfaceTwitterWindowsWindows 10Windows 11Windows InsiderXBOXXBOX Game PassXBOX Game Pass UltimateXBOX OneXBOX Play AnywhereXBOX Series XXBOX Series X|SXBOX Wire

Useful Links

  • AI and Copilot (249)
  • Azure & Cloud (35)
  • Developers (3)
  • Enterprise (3)
  • How To Guides (98)
  • Microsoft 365/Office (95)
  • Microsoft Announcements (97)
  • News (1,265)
  • Security (78)
  • Surface (47)
  • Windows (166)
  • XBOX and Gaming (415)

You May Have Missed

Next Week on Xbox: Every Bizarre New Game Hitting June 29–July 3
  • News
  • XBOX and Gaming

Next Week on Xbox: Every Bizarre New Game Hitting June 29–July 3

Dave W. Shanahan 11 hours ago 0
XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs
  • News
  • XBOX and Gaming

Unfortunately Expected: XBOX Console Prices Increasing August 2026 as Microsoft Cites Rising Component Costs

Dave W. Shanahan 2 days ago 0
XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend
  • News
  • XBOX and Gaming

XBOX Free Play Days Adds House Flipper 2, Blades of Fire, and Assetto Corsa Competizione This Weekend

Dave W. Shanahan 2 days ago 0
Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI
  • News
  • AI and Copilot

Massive New Pecos Datacenter in West Texas As Microsoft Bets Big on AI

Dave W. Shanahan 4 days ago 0
  • AI & Copilot
  • Azure Cloud
  • How To Guides
  • Microsoft 365 Office
  • Windows
  • XBOX
  • Privacy Policy
Copyright © 2026 All rights reserved. ReviewNews by AF themes.

    %d