cisavendorNewsThe Broadside1 min read

Governments drew 27% of Microsoft's observed 2026 threat activity

The 27% share is Microsoft-owned telemetry, not a census; the phishing jump to 23% is the operational signal for identity control owners.


TL;DR

Microsoft's 2026 Digital Defense Report puts government agencies and services at 27% of threat activity its telemetry observed between July 2025 and June 2026, up from 17% in 2025, and names the sector the top nation-state target. Dwell time rose across sectors, and phishing jumped to 23% of observed intrusions from 7%. Those figures are vendor telemetry, not an independent census, and the five government priorities are advocacy. The phishing swing is load-bearing: compromised identities as the entry point.

Microsoft's Digital Defense Report puts government agencies and services at 27% of the threat activity its telemetry observed between July 2025 and June 2026, up from 17% in 2025, and names the sector the top target for nation-state activity. That share is Microsoft-observed, not an independent census, and the report's authors, Mike Yeh and Terrell Cox, use it to argue for five government priorities.

The numbers that travel better are the ones any defender can recognize. Dwell time rose across sectors even as teams responded faster once they found an intrusion, and phishing accounted for 23% of observed intrusions, up from 7%. Both point the same way: attackers are entering through compromised identities and hiding longer by mimicking legitimate activity. For an agency CISO or a contractor holding CUI, that's a reminder to treat identity as the entry point worth hardening rather than a control to check off. The blog is vendor advocacy; the phishing swing is the part worth holding onto.


Published ·Deep Fathom

Governments drew 27% of Microsoft's observed 2026 threat activity — The Broadside