Skip to content

Security1 publisher2 min readPublished

Phishing's share of intrusions Microsoft observed more than tripled to 23% in a year

Microsoft's 2026 Digital Defense Report puts phishing behind 23% of observed intrusions, up from 7% a year earlier. Organizations responded faster once they found an intrusion, yet dwell time still grew, so the added time sits before the first alert.

The Watch · Security desk

Illustration accompanying Phishing's share of intrusions Microsoft observed more than tripled to 23% in a year

What happened

  • Government agencies and services were the most affected sector in Microsoft's data, at 27% of observed threat activity against 17% in 2025.
  • Microsoft also names governments as the sector nation-state actors target most often.
  • Criminal and nation-state actors increasingly get in through the same routes, including compromised identities, social engineering and legitimate administrative tools.
  • Microsoft says an agency may not know at first whether an intrusion is criminal, geopolitical or something else.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • decision Teams choosing between faster containment and better detection of valid-account misuse have Microsoft's data pointing at detection, the stage where the time was lost.
  • exposure A credential phished at one agency opens a route toward the contractors, technology providers and infrastructure operators connected to that agency.
  • contradiction Agencies that follow the report's opening priorities would put money into crisis coordination, the stage Microsoft's own figures show is already getting faster.

A phished password gives an attacker a working account, and Microsoft ties the rise in phishing to compromised identities as an entry point [6]. In about half of cases, that account does not stay the only one. Microsoft found that 52.2% of intrusions involving valid accounts resulted in additional credential theft [10]. Every one of those steps runs under a real user's name. Microsoft wrote: "Attackers increasingly gain access through techniques that mimic legitimate activity, making malicious behavior harder to spot" [5].

Phishing's share rose 16 percentage points, to about 3.3 times its 2025 level [1]. Government's share of observed threat activity rose 10 points [2]. Both figures are shares of what Microsoft observed in a report year running from July 2025 to June 2026 [7]. A sector's share can climb because other sectors fell. The blog does not publish absolute counts or dwell-time figures.

Dwell time is the period from an attacker's first access to the point where defenders detect and stop them. Microsoft says it increased across multiple sectors [3]. Organizations also responded faster once an intrusion was identified [4]. If the response end of the window got shorter and the whole window got longer, the stretch before detection grew [3]. During that stretch a phished login looks like an employee at work [5].

Microsoft lists five priorities for governments [16]. The first is speed. The best-prepared governments, it says, will be those that can "rapidly gather and assess information, make decisions, coordinate across institutions and industries, and communicate effectively during a crisis" [14]. The third tells them to "assess incidents not only by how they begin, but by where they could lead" [15]. Both start from an intrusion someone has already found.

The vulnerability figures in the report matter less to this pattern than their size suggests. Microsoft projects a record 72,000 publicly disclosed CVEs in 2026 [9]. It says the gap from discovery in the wild to active weaponization can be well below 24 hours [8]. Those numbers set patch schedules. The vector whose share more than tripled runs on stolen identities, and a patch does not revoke a password someone typed into a fake login page [6].

What to watch

  • Whether the full Digital Defense Report publishes dwell-time figures by sector, showing how much the pre-detection window grew.
  • Absolute intrusion counts behind the 7% and 23% phishing shares, to separate a real rise in phishing from a change in what Microsoft observed.
  • Terrell Cox's companion post for CISOs, and whether it puts detection of valid-account misuse ahead of response coordination.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories