Skip to content

Thanks to AI, the pirates have gained the upper hand

Microsoft's annual cybersecurity report is unequivocal: for now, AI benefits attackers more than defenders. The figures, and what can be done about them.

Advertisement

Imagine a race between burglars and locksmiths. For years, the two moved at roughly the same pace: a new lock, a new technique for picking it, and so on.

According to Microsoft, artificial intelligence has just given the burglars a serious head start.

Every year, the company publishes a major report on the state of cybersecurity around the world. It draws on more than 165,000 billion security signals that it observes every day. The 2026 edition, published on 1 October, covers the period from July 2025 to June 2026. Its conclusion can be summed up in one sentence: for now, it is the attackers who are benefiting most from AI.

The three figures that are cause for concern

Less than 24 hours. That is now the median time between the discovery of a flaw in a piece of software and the moment when attackers know how to exploit it. Yet companies often take weeks to install the patches. In the meantime, the door stays open.

23%. That is the share of intrusions analysed by Microsoft's teams that began with a booby-trapped email. A year earlier, it was 7%. Phishing, which was thought to be somewhat past it, has more than tripled.

24%. That is the share of attacks that targeted software accessible from the internet, against 15% the previous year.

What AI changes for attackers

Microsoft sums it up in a phrase: AI changes the physics of cybersecurity. In practice, it helps attackers at every stage: identifying their targets, finding flaws, writing malicious programs, and acting once inside.

For the most experienced attackers, operations that used to take days are now done in a matter of seconds. For amateurs, AI puts within reach a level of perseverance and precision that was once reserved for intelligence services.

The report cites in particular groups linked to China, Russia and North Korea. It also notes that these attacks still generally need a human to direct them. AI accelerates, it does not yet decide on its own.

The end of spelling mistakes ✉️
For years, the same advice was repeated: an email full of mistakes is surely a scam. That advice is dead. An AI writes without a single mistake, in any language, with the exact tone of a colleague or a supplier. According to Microsoft, above all it makes it possible to personalise every message at scale: what once required painstaking work for a single victim can now target thousands of people, each with a bespoke message.

A very recent example

Last week we reported on the EvilTokens scam, dismantled by Microsoft: an AI read the stolen mailboxes to work out who to impersonate and whom to ask for money. This is exactly what the report describes: AI does not create new crimes, it makes the old ones far more effective.

The report also notes that, in more than half of the intrusions that began with a stolen legitimate account, the attackers took the opportunity to obtain yet more credentials once inside.

What you can do

Turn on a phishing-resistant login. Passkeys, increasingly offered by the big services, or failing that two-factor verification through an app rather than by SMS. Even if you type your password into a fake page, the scammer will not be able to get in.

Leave automatic updates on. If a flaw is exploited in under 24 hours, every day of delay counts.

Verify through another channel. An unusual request for money, a code or a transfer, even if perfectly written? Call the person, on a number you already know.

What we take away

Microsoft is not saying the game is lost. The company believes the balance will eventually be restored, because AI is also used for defence. But for now, it is the defenders who have to run to catch up.

That is exactly the bet Google is making this week, by first reserving its most powerful model for security experts: giving the locksmiths a head start.

Advertisement