Microsoft's 2025 Digital Defense Report emphasizes the urgent need for organizations to elevate cybersecurity to a boardroom-level priority, citing the increasing frequency and sophistication of cyberattacks. The report urges IT leaders to frame cybersecurity as a business risk equivalent to financial or legal challenges, advocating for direct engagement with corporate boards and CEOs to address organizational security weaknesses. Microsoft recommends tracking key security metrics such as multi-factor authentication (MFA) coverage, patch latency, incident counts, and incident response times to provide a comprehensive view of an organization's vulnerability and preparedness. The report highlights the importance of enforcing phishing-resistant MFA across all accounts, including those with administrative privileges, and regularly auditing third-party perimeter access. Over the past year, Microsoft observed a surge in the development of novel attack techniques by threat actors, who continue to exploit known security gaps opportunistically. The majority of attacks in the last six months have targeted the United States, United Kingdom, Israel, and Germany, reflecting a global threat landscape. According to the report, 80% of cyber incidents investigated by Microsoft involved data theft, with over half of attacks driven by extortion or ransomware motives, underscoring the financial incentives behind most cybercrime. Only a small fraction—about 4%—of attacks were attributed solely to espionage. The proliferation of automation, off-the-shelf hacking tools, and AI has enabled even low-skilled cybercriminals to scale their operations, making cybercrime a pervasive threat to organizations of all sizes. Microsoft processes over 100 trillion signals daily, blocks 4.5 million new malware attempts, analyzes 38 million identity risk detections, and screens 5 billion emails for threats, illustrating the scale of the challenge. The report stresses that legacy security measures are insufficient, advocating for modern, AI-driven defenses and cross-sector collaboration to keep pace with evolving threats. Organizational leaders are encouraged to build resilience into their technology and operations from the outset, treating cybersecurity as a strategic imperative. The report also notes that while nation-state actors remain a persistent concern, the immediate risk to most organizations comes from financially motivated, opportunistic criminals. Microsoft’s recommendations aim to help organizations better understand their risk posture and improve their ability to detect, prevent, and respond to cyber incidents. The report’s findings are informed by Microsoft’s extensive threat intelligence and security operations, providing actionable insights for both technical and executive audiences. The emphasis on board-level engagement reflects a broader industry trend recognizing that cybersecurity is integral to overall business resilience and continuity. By adopting the recommended practices, organizations can better defend against the growing spectrum of cyber threats and minimize the impact of potential breaches.

TTPs, infrastructure, and targeting history in one profile.
1 event from the most recent confirmed update back to the earliest known activity.
Microsoft released its 2025 Digital Defense Report, stating that extortion and ransomware account for more than half of cyberattacks and highlighting boardroom cyber awareness as a top priority. The report publication is the primary real-world event reflected across the references.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.