Short answer: Microsoft’s latest annual threat report shows that most attacks are about money, that stolen sign-ins are still the easiest way in, and that AI is making phishing far more convincing. The good news is that a handful of basic controls stop most of it. Here is what the Microsoft Digital Defense Report 2025 says, and what it means for a UK small business.
Read the full report on Microsoft.com Download the PDF
The report at a glance
Why attackers attack: it is mostly about money
Attack motives (known motive only)
- 52% extortion and ransomware
- 4% espionage
- 44% other motives, including data theft
Small firms are not too small to be worth it. Criminals automate, so every business with money or data is a target.
Identity is the front door, and AI is picking the lock
How people get in
Share of identity attacks and what stops them
AI-written phishing is four and a half times more effective
Click-through rate, standard phishing compared with AI-automated phishing
Microsoft also estimates AI can make a phishing operation up to 50 times more profitable for the attacker, and reports AI-generated fake IDs up 195%.
How breaches start
Common entry points
Share of breaches, as summarised from the report
Newer tricks are climbing too: ClickFix fake-fix prompts were behind 47% of Defender Expert initial-access notifications, and device-code phishing is growing quickly.
Who gets hit, and where
Most-affected countries
Share of observed activity
Most-targeted sectors
Share of attacks
Healthcare, finance and critical infrastructure also feature, and supply chains link small suppliers to all of them.
The cloud is now the battleground
Nation-state activity
Only about 4% of attacks are espionage, but small suppliers are often the stepping stone.
The scale behind the numbers
What a small business should do this month
- Turn on MFA for everyone, admins first. Prefer phishing-resistant methods such as passkeys or security keys.
- Block legacy sign-in and add conditional access. Password spray relies on old protocols that skip MFA.
- Patch internet-facing systems quickly. Firewalls, VPNs and remote access tools are favourite targets.
- Close or protect remote access. No open RDP, and put everything else behind MFA.
- Train for AI-grade phishing. Teach staff to verify unusual requests by phone, and to be wary of fake-fix prompts.
- Have a tested backup and a one-page incident plan. Ransomware is the main motive, so recovery is your safety net.
Frequently asked questions
What is the Microsoft Digital Defense Report
It is Microsoft’s annual report on the global threat landscape, drawing on trillions of daily security signals. The 2025 edition covers cybercrime, nation-state activity, identity, cloud and AI.
Does the report apply to small businesses
Yes. Most attacks are automated and financially motivated, so small firms face the same phishing, password attacks and ransomware as large ones, usually with fewer defences.
How effective is multifactor authentication
Microsoft reports that MFA blocks over 99% of identity-based attacks, which makes it the single most valuable control to switch on.
How is AI changing phishing
AI-automated phishing achieved a 54% click-through rate in the report, compared with 12% for standard campaigns, because the messages are more personal and better written.
Where can I read the report
The full report and PDF are published by Microsoft: Microsoft Digital Defense Report 2025.
Source: Microsoft Digital Defense Report 2025. Some figures are taken from published summaries of the report and measure different things, so they are not directly comparable. Check the report for full context.
Do not just read it. Act on it.
Reading is the easy part. Book a free IT review and we will tell you, in plain English, where your business stands and what to fix first.

