Published this Thursday, October 1st, the Microsoft Digital Defense Report 2026 confirms that artificial intelligence is accelerating cyberattacks. According to the report, nearly three quarters of intrusion attempts target humans and their identifiers. The report describes a cybersecurity landscape disrupted by artificial intelligence, where attacks are gaining in speed and scale. Users' identifiers are at the center of cybercriminal activity, with hijacked accounts, fake phone calls, and cloud services appearing shortly after being exposed. The company's report shows that cybercriminals are not doing anything fundamentally new, but are simply doing it faster and on a much larger scale.
Hackers are betting on AI, but it is always digital identities they want to steal. According to Microsoft, 73.3% of initial access attempts target humans or their identifiers, using an attachment opened without suspicion, a valid account already compromised, or a well-practiced manipulation. Rather than relying on their own malicious software, attackers are increasingly diverting legitimate tools, which hides their actions in normal activity. Operations supported by China, Russia, Iran, or North Korea play the same card of discretion to establish themselves durably in high-value environments. Once the door is crossed, the harvest can begin. In more than half of the intrusions, the attackers immediately seize other identifiers, to go deeper into the network or sell them on the dark web. Each stolen account fuels others, and the machine eventually runs on its own.
Microsoft's response teams describe a recurring sequence: a human is trapped, then the discovery of accesses reserved for software, such as API keys (a kind of password used by applications), before a rise in privileges. In total, 63% of intrusions involve data theft. The volumes are impressive. Imagine that in the first half of 2026, Microsoft detected an average of 31 million identity-related risks each day worldwide. The report also lists over 46 million identity spoofing attacks in professional emails, which are scams where the fraudster pretends to be a trusted contact. Between 89 and 95% of the attached files have resulted in an attempt to steal identifiers. In the first months of the year, France ranked 17th globally and 6th in Europe among countries where Microsoft customers were most often affected by cyber activity.
With AI, cyberattacks are multiplied, and the worst is yet to come. The methods have not changed, but the tempo has. Among the most experienced hackers, artificial intelligence brings the attack chain from several days to just a few seconds. It is used to detect vulnerabilities, to create custom malware or to orchestrate an attack from start to finish. Less experienced profiles also benefit, as AI offers them persistence previously reserved for intelligence services and better personalized scams, therefore more likely to succeed. A cloud workload exposed, that is, an application or service hosted in the cloud, is attacked on average after 5.3 hours. Between the revelation of a vulnerability and its exploitation, only a few days generally pass. AI also accelerates the search for vulnerabilities, which should further reduce the margin for companies to correct them.
Microsoft recommends deploying passkeys, security keys that allow connecting without a password by simply unlocking the device. It also sees in multi-factor authentication resistant to phishing, which a fake site cannot deceive, one of the most effective protections. The report advises companies to limit access rights to the strict minimum, to regularly renew the identifiers used by software, and to fix their exposed equipment on the Internet without delay. It also invites them to inventory their use of cryptography to anticipate the post-quantum transition. In an environment where attacks are carried out at machine speed, Microsoft considers AI now essential, and no longer optional, for defenders, to whom it can also be beneficial! Artificial intelligence can summarize and classify incidents, continuously track and correct vulnerabilities. The report even envisions defensive agents with increasing autonomy, who would support human teams. However, these remain irreplaceable, as according to red teaming exercises (attack simulations conducted by experts) analyzed by Microsoft, detecting an attack path never documented always requires the eye of an experienced professional. This defense is precisely a team effort. The more organizations cross their signals, internally as well as with their partners and public authorities, the sooner they detect attacks that no single organization would see alone. Open source demonstrates this. A single stolen identifier or a compromised process can open the way for many organizations at once. To boards of directors, Microsoft concludes thus: it is no longer a question of whether a disruption will occur, but whether the company will be able to continue operating, limit the damage, recover quickly, and preserve trust.
AI Accelerates Cyberattacks, Targeting Human Identities at Scale
AI-rewritten from original reportingHow it works
aicybersecuritymicrosoftidentity-thefthackersdefensive-ai
Original sources:
- 🇫🇷Clubic



