Tendvane

← All articles

SecurityOctober 2, 2026

Phishing went from 7 percent of break-ins to 23 in a single year

Twenty-three percent. That is the share of intrusions Microsoft's incident responders traced back to a phishing message in the year to June 2026. A year earlier the figure was seven.

It comes from the 2026 Microsoft Digital Defense Report, published on 1 October and covering July 2025 to June 2026. Microsoft's own summary is unusually blunt: in the early part of the AI race, attackers are getting more out of it than defenders are. The median gap between a vulnerability being discovered and somebody having a working attack for it has fallen to well under 24 hours. Exposed cloud systems are hit an average of 5.3 hours after they appear. The report also describes JADEPUFFER, which Microsoft calls the first automated, AI-run extortion attack it has documented, seen in early July.

The phishing number is the part that lands on ordinary people. The old way to spot a scam message was clumsy English, strange formatting and a story that fell apart if you read it twice. Those were never the real signal, they were just the cheapest things to check, and a language model erases all three at once. Same for the fake profile with no history and the identity document that looks slightly off.

What still works is the boring thing. Stop trusting the message and go to the source yourself: type the bank's address, ring the number printed on the back of the card, open the app instead of the link. And keep the software that opens those messages current, because a weaponisation window measured in hours leaves no room for a browser you last updated in August. Tendvane can push your installed apps through winget in one pass, which takes the effort out of that.

Sources

Download Tendvane