Phishing, identity theft, and ClickFix are the leading methods of intrusion as observed by Microsoft and the ENISA. While artificial intelligence primarily enhances existing techniques, the American company anticipates more advanced applications becoming commonplace within a year.
Scientists confirm: This is the most effective way to get your cat’s attention, according to new research
Elderly Couple Refuses Reserved Seats—Viral Train Standoff Sparks Fiery Debate on Courtesy
Contents
- Attackers initially target users and their credentials
- Vulnerabilities exploited more quickly and attacks via suppliers
- AI as an attack accelerator that may become widespread within a year
To penetrate organizational IT systems, cyber attackers primarily exploit human factors and stolen credentials, with artificial intelligence mainly speeding up the process. This observation is shared in two annual reports released days apart: the Microsoft Digital Defense Report 2026, produced by Microsoft’s threat intelligence teams, and the ENISA Threat Landscape 2026, published by the European Union Agency for Cybersecurity. While the first is based on observations from Microsoft’s global client base, the second analyzes 8,257 incidents in the European Union. Although the data types differ, their conclusions align.
Why You Should Never Reheat These Foods in the Microwave – The Hidden Dangers Experts Warn About
I tried the top 5 guard dogs—here’s what makes these breeds the ultimate protectors
Attackers Primarily Target Users and Their Credentials
In Microsoft’s incident response engagements from July 2025 to June 2026, phishing emerged as the most rapidly growing method of entry, now ranking second among the most utilized tactics by cyber attackers to breach systems:

- Exploitation of publicly exposed applications, at 24% in 2026 (up from 15% the previous year),
- Phishing, at 23% (up from 7%),
- Use of valid accounts, at 13% (down from 17%),
- Social engineering, distinguished from phishing by Microsoft, at 7% (down from 15%),
- Exposed remote access services such as VPNs or remote desktops, at 5% (down from 8%).
Once an account is compromised, attackers seek to acquire more. In 52.2% of the breaches involving valid accounts analyzed by Microsoft, a subsequent theft of credentials occurred. Consequently, the company recommends robust multi-factor authentication resistant to phishing, the use of passkeys, and stricter governance of non-human identities, such as service accounts and API keys.
Similarly, the ENISA’s findings at the European level indicate that phishing accounted for 77.8% of the social engineering techniques noted in incidents targeting the EU in 2025, far outpacing “malspam” (13%), which involves mass email campaigns to spread malware. The agency also notes an increasing use of ClickFix, a technique that tricks the victim into “repairing” a fictitious problem by executing a malicious command. Microsoft has observed a significant increase in such attacks, which have become about 23 times more frequent between December 2025 and May 2026. These tactics rely on victim response, while protective reflexes remain uncommon among the French population, as shown in the latest Cybermalveillance.gouv.fr barometer.
Distinguishing Microsoft and ENISA Data
Microsoft measures what it observes among its clients and in its incident response missions globally. ENISA compiles incidents that are publicly disclosed or shared by EU member states, with 51.3% being DDoS attacks often claimed by hacktivists. Therefore, the percentages from both reports are based on different foundations and cannot be directly compared.
Vulnerabilities Exploited More Rapidly and Attacks Through Suppliers
Software vulnerabilities are identified by Microsoft as the primary point of entry. The median time between the discovery of a vulnerability and its exploitation has dropped well below 24 hours. ENISA concurs, albeit on a narrower basis. Among the unauthorized accesses it could pinpoint, 60.4% were based on exploiting a vulnerability. Over 48,000 new vulnerabilities were reported in 2025 in the Common Vulnerabilities and Exposures (CVE) program, marking a 22% increase from the previous year.
Both reports also highlight attacks that target a supplier to reach its clients, whether it be a service provider, a cloud service, or a software component. ENISA notes the increasing number of compromised npm packages, such as during the Shai-Hulud campaign. Microsoft mentions the compromise in March 2026 of the Axios package, which exceeded 100 million weekly downloads while under attackers’ control. The company also ranks the open-source supply chain among the three most significant threats for the coming year.
France Among the Most Exposed European Countries
According to ENISA, France was the second most frequently mentioned EU country in ransomware claims in 2025 (14.7%), after Germany (26.5%). Microsoft ranks it 17th globally and 6th in Europe among the countries where its clients were most affected in the first half of 2026.
AI, an Attack Accelerator That May Become Widespread Within a Year
The reports on artificial intelligence offer a more nuanced analysis than expected, between a focus on enhancing known techniques and a rapidly evolving landscape.

Known Techniques Executed Faster
According to ENISA, attackers primarily use publicly available AI tools to enhance skills they already possess, rather than to acquire new capabilities. The agency even reports a cloud intrusion assisted by AI that achieved administrative access in just eight minutes.
Microsoft notes the use of AI at various stages of attacks, from reconnaissance to malware development and social engineering. AI tools also become targets themselves. In December 2025, the company detected a malicious browser extension installed over 600,000 times, which collected conversation histories with AI assistants from nearly 10,000 organizations.
Towards Increasingly Automated Attacks
The projections from both reports suggest a significant acceleration in the offensive use of AI in the coming months. “What today involves the most advanced techniques will be commonplace within a year, and new categories of threats will emerge,” warns Microsoft, indicating that attackers currently have an edge over defenders.
At the European level, ENISA believes that an increasing number of attack chain steps will be directly managed by AI, with potential experiments in attacks conducted without human intervention. The European Commission, meanwhile, released an action plan on cybersecurity and artificial intelligence in July, based on the AI Act, the Cyber Resilience Act, and the NIS 2 directive. On the same day, ENISA presented its recommendations to address the risks associated with the most advanced AI models.
Methodology: The Microsoft Digital Defense Report 2026 relies on signals from Microsoft’s products and incident response missions between July 2025 and June 2026. The other study mentioned here is the ENISA Threat Landscape 2026, which analyzes 8,257 incidents that occurred in the EU in 2025, collected from open sources and information shared by member states and agency partners.
Similar Posts
- Cybersecurity Alert: Top 5 Precautions for Remote Work Safety
- Discover the Most Common Password Hacking Techniques: Protect Your Data Now!
- Cyber Resilience Act 2026: Major Changes for Digital Professionals Starting September 11
- Google Play Store Alert: 200 Malicious Apps Downloaded 42 Million Times: Learn How to Avoid Them!
- Hackers Shift Headquarters: Is Your Favorite Collaboration Platform Their New Den?

Jordan Park writes in-depth reviews and editorial opinion pieces for Touch Reviews. With a background in UI/UX design, Jordan offers a unique perspective on device usability and user experience across smartphones, tablets, and mobile software.