Extortion and ransomware are behind over half of all cyber-attacks, according to the latest research from Microsoft, with more than 80% of the incidents investigated by the tech giant last year involving data theft and exfiltration.
In what will be no surprise after a year of repeated, high-profile ransomware attacks in the UK, Microsoft’s latest annual Digital Defense Report found that more than half (52%) of these incidents involved financially motivated threat actors, as opposed to intelligence gathering, accounting for just 4% of attacks.
But while Microsoft found that organisations around the world remain under constant threat from a growing wave of ransomware attackers, much as in previous years, these attackers are now leveraging new tactics and technologies as they compete with each other in an increasingly fragmented criminal economy.
For example, the report found that a shift away from phishing as the go-to method for initial access, with ransomware operators increasingly turning to social engineering to steal or reset credentials—especially through vishing and tech support scams.
This year, Microsoft observed several campaigns in which impersonated help desk staff, using platforms like Teams to message victims, and tools like Quick Assist to gain remote access to their machines.
Described by Microsoft as ‘the most sophisticated ransomware actor’, the Scattered Spider collective (aka Octo Tempest) has used ‘advanced’ social engineering, SIM swapping, and identity theft to breach privileged accounts.
According to the report, the ransom group has shifted between Dragon Force, RansomHub, and Qilin, showing how easy it has now become for threat actors to move seamlessly across Ransomware-as-a-Service (RaaS) platforms, but more importantly, it has used these services to escalate its intrusion into hybrid environments.
Hybrid targeting is on the rise, said Microsoft, with attackers now using tools like AADInternals to move from on-premises into cloud environments, maintaining access, deleting VMs, exfiltrating data, and encrypting resources.
Today, over 40% of ransomware attacks involve hybrid components, up from less than 5% just two years ago, while there has been an 87% increase in campaigns aimed at disrupting Azure cloud customer environments through ransomware, mass deletion, or other destructive actions.
Identity-based attacks are the gateway to cloud breaches, with Microsoft warning that the surge in non-human identities, like apps, services, and scripts, that access cloud resources and often hold elevated privileges, is leading to a growing blind spot.
This year, over 97% of identity attacks targeted passwords, and in early 2025, such attacks jumped 32%, with most malicious sign-in attempts stemming from large-scale password guessing, fueled by leaked credentials and helped along by AI.
Recommended reading
- UK Facing 4 Major Cyber-Attacks Each Week, Warns NCSC
- Retail Sector Cyber-attacks Peaked in Q2 2025
- Report: Half of Firms Hit by Months-Long Cyber-attack Disruption
As always, AI is lurking in the background of nearly every threat actor activity. It is well known by now that hackers are not only using genAI to automate phishing, scale social engineering and scan for zero-day vulnerabilities, but to create deepfakes, build mutating malware, and conduct research into their victims.
However, Microsoft’s report shows that AI itself is also proving vulnerable to attack. Last year saw the company work with other genAI providers to disrupt a global campaign using stolen API keys to bypass safety controls on major AI platforms like Azure OpenAI.
The resultant tools, sold and deployed by rogue developers, generated thousands of abusive images, including celebrity deepfakes and explicit, violent, or hateful synthetic content.
“AI’s powerful capabilities extend to producing sensitive materials and enhancing skills in ways that, if misused, pose significant security risks,” warns the report.
“As a result, it is essential for developers of AI and policymakers to establish clear guidelines to ensure appropriate use while minimising the risk of misuse. AI should be designed with strict filters and intent detections to block requests for harmful knowledge, with suspicious queries reviewed by humans.”





