Microsoft published its sixth annual Digital Defense Report (MDDR), revealing that over half of cyberattacks with known motives were driven by extortion or ransomware
Covering trends from July 2024 to June 2025, the report — authored in collaboration with Chief Information Security Officer Igor Tsyganskiy — highlights that over 52% of incidents were financially motivated, while purely espionage-focused attacks accounted for only 4%. State-sponsored attacks remain a serious and persistent threat, but the bulk of immediate attacks facing organizations today come from opportunistic criminals looking to profit.
According to data presented, daily Microsoft processes more than 100 trillion signals, blocks approximately 4.5 million new malware attempts, analyzes 38 million identity risk detections, and filters 5 billion emails looking for malware and phishing. Advances in automation and readily available tools on the market have enabled cybercriminals — even those with limited technical expertise — to significantly expand their operations. The use of artificial intelligence has further accelerated this trend, with criminals developing malware faster and creating more realistic synthetic content, improving the efficiency of activities such as phishing and ransomware.
One of the most alarming points in the report is that over 97% of identity attacks are password-based attacks. In the first half of 2025 alone, identity-based attacks increased by 32%. Criminals obtain credentials for these attacks primarily through password breaches, but also through "infostealer" malware, which secretly collects credentials and session tokens from browsers at scale. In May this year, Microsoft's Digital Crimes Unit (DCU) dismantled the most popular infostealer — Black Basta.
For Microsoft, the solution to identity compromise is straightforward: implementation of phishing-resistant multifactor authentication (MFA), which can block more than 99% of such attacks even when the attacker has the correct username and password combination. The report also highlights that hospitals and local governments are constant targets because they store sensitive data or have limited cybersecurity budgets with limited incident response capabilities, often resulting in outdated software.
State espionage also demands attention. China continues its wide-ranging effort across all industries to conduct espionage and steal sensitive data, increasingly targeting non-governmental organizations (NGOs) to expand its intelligence. Iran is attacking a wider range of targets than ever before, from the Middle East to North America, as part of expanding espionage operations. Russia expanded its targets beyond Ukraine, with the ten countries most affected by Russian cyber activity belonging to NATO — a 25% increase compared to the previous year. North Korea remains focused on revenue generation and espionage, with thousands of state-affiliated remote workers applying for jobs at companies around the world.
The report concludes that defensive measures alone are not enough to deter state adversaries. Governments need to build structures that signal credible and proportional consequences for malicious activity violating international norms. As digital transformation accelerates — amplified by the rise of AI — cyber threats present risks to economic stability, governance, and personal security. Addressing these challenges requires not only technical innovation, but coordinated societal action.
The question that remains: as AI becomes increasingly accessible to criminals, how can organizations prepare for a future where the barrier to entry for sophisticated cyberattacks becomes virtually non-existent?
Sources: Microsoft On the Issues, The Register, The Verge
✓ Independent sources cross-checked and verified before publishing