Microsoft: phishing that bypasses MFA hits 23% of intrusions
Microsoft's 2026 Digital Defense Report covering July 2025 to June 2026 says phishing was the initial access vector in 23% of intrusions, up from 7% a year earlier. Adversary-in-the-middle kits account for 44.6% of phishing techniques, and 87.7% of phishing intrusions involved credential or session harvesting.
- Phishing as initial access rose from 7% to 23% of cases
- AiTM kits make up 44.6% of phishing techniques
- 87.7% of phishing intrusions involved credential or session theft
- Defender for Office 365 saw 145 million QR-code phishing attacks
Read next
Security