Microsoft Digital Defense Report 2025: What It Means for UK Small Business

THREAT INTELLIGENCE BRIEFINGMicrosoft DigitalDefense Report 2025What it means for UK small business52%99%extortion motiveblocked by MFA

Short answer: Microsoft’s latest annual threat report shows that most attacks are about money, that stolen sign-ins are still the easiest way in, and that AI is making phishing far more convincing. The good news is that a handful of basic controls stop most of it. Here is what the Microsoft Digital Defense Report 2025 says, and what it means for a UK small business.

Read the full report on Microsoft.com   Download the PDF

52%Extortion and ransomwareof attacks with a known motive were driven by extortion or ransomware.
>99%MFA blocks itmultifactor authentication stops over 99% of identity-based attacks.
+32%Identity attacks uprise in identity attacks in the first half of 2025.
54%AI phishing click rateversus 12% for standard phishing emails.

The report at a glance

52%of attacks with a known motiveare extortion or ransomware97%+of identity attacks arepassword spray or brute force47%of Defender Expert alerts: ClickFixwas the top way in54%click rate on AI-automatedphishing, against 12% standard+26%cloud incidents, Jan to Apr 2025with exfiltration alerts up 58%>99%of identity attacks stoppedby multifactor authentication

Why attackers attack: it is mostly about money

52%extortion

Attack motives (known motive only)

  • 52% extortion and ransomware
  • 4% espionage
  • 44% other motives, including data theft

Small firms are not too small to be worth it. Criminals automate, so every business with money or data is a target.

Identity is the front door, and AI is picking the lock

How people get in

Share of identity attacks and what stops them

Password spray / brute force
97%+
Targeted names already in breach lists
85%
Attacks stopped by MFA
99%+
Spray guesses with the right password
1.5%

AI-written phishing is four and a half times more effective

Click-through rate, standard phishing compared with AI-automated phishing

12%
54%
Standard phishingAI-automated phishing

Microsoft also estimates AI can make a phishing operation up to 50 times more profitable for the attacker, and reports AI-generated fake IDs up 195%.

How breaches start

Common entry points

Share of breaches, as summarised from the report

Phishing and social engineering
28%
Unpatched public-facing services
18%
Exposed remote access
12%

Newer tricks are climbing too: ClickFix fake-fix prompts were behind 47% of Defender Expert initial-access notifications, and device-code phishing is growing quickly.

Who gets hit, and where

Most-affected countries

Share of observed activity

United States
24.8%
United Kingdom
5.6%
Israel
3.5%
Germany
3.3%

Most-targeted sectors

Share of attacks

Government
17%
IT
17%
Research and academia
High

Healthcare, finance and critical infrastructure also feature, and supply chains link small suppliers to all of them.

The cloud is now the battleground

+26%Cloud incidentsincrease, January to April 2025.
+87%Disruptive campaignsincrease in the same period.
+58%Data exfiltration alertsincrease in cloud environments.
+23%Credential access attemptsincrease against cloud accounts.

Nation-state activity

ChinaExpanding attacks across industries and NGOs.
IranTargeting logistics firms in Europe and the Gulf.
RussiaOperating beyond Ukraine, including smaller NATO-country businesses.
North KoreaChasing money and intelligence through overseas IT workers.

Only about 4% of attacks are espionage, but small suppliers are often the stepping stone.

The scale behind the numbers

100tnSignals a daysecurity signals processed daily by Microsoft.
38mIdentity risk detectionsanalysed every day.
5bnEmails scannedfor malware and phishing.
$4bnFraud blockedbetween April 2024 and April 2025.

What a small business should do this month

  1. Turn on MFA for everyone, admins first. Prefer phishing-resistant methods such as passkeys or security keys.
  2. Block legacy sign-in and add conditional access. Password spray relies on old protocols that skip MFA.
  3. Patch internet-facing systems quickly. Firewalls, VPNs and remote access tools are favourite targets.
  4. Close or protect remote access. No open RDP, and put everything else behind MFA.
  5. Train for AI-grade phishing. Teach staff to verify unusual requests by phone, and to be wary of fake-fix prompts.
  6. Have a tested backup and a one-page incident plan. Ransomware is the main motive, so recovery is your safety net.

Frequently asked questions

What is the Microsoft Digital Defense Report

It is Microsoft’s annual report on the global threat landscape, drawing on trillions of daily security signals. The 2025 edition covers cybercrime, nation-state activity, identity, cloud and AI.

Does the report apply to small businesses

Yes. Most attacks are automated and financially motivated, so small firms face the same phishing, password attacks and ransomware as large ones, usually with fewer defences.

How effective is multifactor authentication

Microsoft reports that MFA blocks over 99% of identity-based attacks, which makes it the single most valuable control to switch on.

How is AI changing phishing

AI-automated phishing achieved a 54% click-through rate in the report, compared with 12% for standard campaigns, because the messages are more personal and better written.

Where can I read the report

The full report and PDF are published by Microsoft: Microsoft Digital Defense Report 2025.

Book a free IT review

Source: Microsoft Digital Defense Report 2025. Some figures are taken from published summaries of the report and measure different things, so they are not directly comparable. Check the report for full context.

Your next step

Do not just read it. Act on it.

Reading is the easy part. Book a free IT review and we will tell you, in plain English, where your business stands and what to fix first.

Related guides and services

Scroll to Top
Free 3-minute quiz · No sign-up for your score

Is your team using AI you don’t know about?

Score your Shadow AI risk across policy, data, tools, people and detection, then get the three controls to fix first.

Take the Shadow AI Check10 questions · about 3 minutes