Microsoft says government sector accounts for 27% of observed cyber threat activity in 2026 Digital Defense Report

By Public Technologies
  • Microsoft’s Digital Defense Report flagged government agencies as the top target in July 2025–June 2026, representing 27% of observed cyber activity.
  • Government exposure rose from 17% in 2025, underscoring heightened nation-state focus on public-sector networks.
  • Phishing drove 23% of observed intrusions, up from 7% in 2025, reinforcing identity compromise as a primary entry point.
  • Dwell time increased across sectors, pointing to slower detection even as response improved once intrusions were identified.
  • Valid-account intrusions led to additional credential theft in 52.2% of cases, raising the risk of rapid lateral spread into disruption or data theft.


Disclaimer: This news brief was created by Public Technologies (PUBT) using generative artificial intelligence. While PUBT strives to provide accurate and timely information, this AI-generated content is for informational purposes only and should not be interpreted as financial, investment, or legal advice. Microsoft Corporation published the original content used to generate this news brief on October 01, 2026, and is solely responsible for the information contained therein.

Capital.com is an execution-only brokerage platform and the content provided on the Capital.com website is intended for informational purposes only and should not be regarded as an offer to sell or a solicitation of an offer to buy the products or securities to which it applies. No representation or warranty is given as to the accuracy or completeness of the information provided.

The information provided does not constitute investment advice nor take into account the individual financial circumstances or objectives of any investor. Any information that may be provided relating to past performance is not a reliable indicator of future results or performance.

To the extent permitted by law, in no event shall Capital.com (or any affiliate or employee) have any liability for any loss arising from the use of the information provided. Any person acting on the information does so entirely at their own risk.

Any information which could be construed as “investment research” has not been prepared in accordance with legal requirements designed to promote the independence of investment research and as such is considered to be a marketing communication.