Guardz 2026 Cyber Threat Report: What It Means for MSPs

Cybersecurity threats

Guardz protects thousands of businesses across Microsoft 365 and Google Workspace, giving their research team visibility across billions of audit events. Guardz’ 2026 threat report combines telemetry from a 180-day observation period with recognised research from IBM, Verizon, the FBI, Datto and Gartner to show how the MSP threat landscape is changing.

This summary brings together key figures covering AI-enabled attacks, identity compromise, business email compromise, ransomware, endpoint exposure, cloud risk, Microsoft 365… and what these trends suggest for the rest of 2026.

While some of the source data is US-focused, the patterns and implications are relevant for MSPs in Australia and New Zealand. Whether you are triaging alerts after hours or building out a managed security practice, the direction is clear:

Attackers are moving faster, using more automation and concentrating on the identities and platforms that small businesses rely on every day.

“Cybersecurity leaders are navigating uncharted territory this year... testing the limits of their teams in an environment defined by constant change. This demands new approaches to cyber risk management, resilience, and resource allocation.”

Alex Michaels, Director Analyst, Gartner

AI-Enabled Attacks Are Changing the Rules

Generative AI has made phishing harder to spot and given everyday attackers capabilities that once required far more resources. 

  1. AI now factors into roughly 1 in 6 data breaches, used most often for phishing and deepfake impersonation, according to IBM’s Cost of a Data Breach Report.
  2. The global average cost of a data breach is $4.44M. For an SMB client, even a small portion of that amount could threaten the future of the business.
  3. About 31% of monitored users have compromised passwords in any given month, a direct consequence of AI-optimised credential stuffing running continuously against SMB tenants.
  4. Guardz identified more than 14,000 unique source IP addresses conducting password-spray attacks each month, each targeting 10 or more accounts, with supporting infrastructure growing about 13% month over month. This is automation at a scale no manual defence can match.
  5. AI-generated phishing has erased the old detection cues. The 2026 Verizon Data Breach Investigations Report notes that attackers now use AI assistance across 15 or more attack techniques, and updated its own phishing-detection guidance from spotting typos to spotting em dashes, a sign of how convincing machine-written lures have become.

For MSPs, the volume, speed and polish of AI-assisted attacks make automated triage and response a practical requirement, and highlights the importance of security awareness training such as MPaware.

Identity Is the Battleground

For SMB environments, identity is now the frontline. Constant automated pressure against user accounts is not an occasional spike in activity; it is part of the daily threat landscape.

  1. Across monitored environments, Guardz found that 89% of SMBs have at least one user with a confirmed credential compromise at any given time.
  2. Nearly 1 in 3 sign-in attempts in monitored tenants is unauthorised, with failed authentication events holding at 28% to 30% across every region over the full 180-day window.
  3. Session hijacking rose about 23% over the same 180 days, making it the fastest-growing identity attack category in the Guardz dataset. As MFA adoption climbs, attackers are shifting from stealing passwords to stealing the authenticated session itself.
  4. Stolen credentials remain a leading entry point for attackers, even as vulnerability exploitation overtook them as the top initial access vector. Credential abuse featured in 13% of breaches in the 2026 edition, and the human element remained present in 62% of breaches overall.
  5. Authentication attempts originating from known-malicious infrastructure grew 50% over a 120-day window in Guardz telemetry, a clear signal that adversaries are industrialising their access attempts.

Session hijacking is the change MSPs need to pay close attention to.

Once an attacker is operating inside a valid authenticated session, controls designed to catch stolen passwords may not fire. That is why identity detection now needs to look at login behaviour, permission changes and session anomalies in real time, not just whether the user supplied the right credentials.

Guardz Cybersecurity Identity Incidents 2026

Email Remains the Money Vector

Email is where stolen access often becomes financial loss. The attacker may not need malware, links or attachments; account takeover, mailbox changes and convincing messages can be enough.

  1. Business email compromise drove $2.77B in reported losses across 21,442 complaints in the FBI’s Internet Crime Report 2024, second only to investment fraud in total dollars lost.
  2. Guardz recorded a 240% surge in email quarantine activity, with inbox-rule modifications roughly doubling over the measurement window. Quiet manipulation of the mailbox is the tell that an account has been taken over.
  3. Malicious inbox rules remain the leading persistence mechanism in BEC attacks. Guardz observed a 13x spike in suspicious inbox rules in the US across 304 affected users Attackers use these rules to conceal replies and remain undetected.
  4. Nearly 2 million SendAs operations appeared in the Guardz dataset, a strong indicator of widespread email impersonation, where an attacker sends mail as a legitimate user to redirect payments or harvest further access.

BEC remains difficult because it often looks like ordinary business communication. There may be no malicious file to scan and no vulnerability to patch. Effective detection depends on connecting the dots between suspicious sign-ins, mailbox rule changes and unusual sending behaviour before the financial impact occurs.

Ransomware and Endpoint Exposure

Ransomware may not represent the majority of security events, but it remains one of the most damaging client outcomes. Attackers are also relying more heavily on legitimate tools already present in the environment, making malicious activity harder to separate from normal administration.

  1. Ransomware was present in 48% of breaches in the latest Verizon data, up from 44% the prior year, even as the median ransom payment fell to $139,875 and only 31% of victims chose to pay, according to the 2026 Verizon DBIR.
  2. Ransomware was implicated in 88% of breaches involving SMBs in the latest Verizon data, far above the rate for large enterprises. The SMBs that MSPs serve are becoming the primary target.
  3. The cost of downtime from a ransomware attack can reach up to 50 times the ransom demand itself, Datto’s channel research has found.
  4. Guardz recorded a 190% surge in ransomware behavioral detections over a single 50-day window, evidence that pre-encryption attacker behaviour is both detectable and accelerating.
  5. Remote monitoring and management tool abuse is the single largest endpoint threat campaign in the Guardz dataset, at 26.2% of all endpoint threats. The tools MSPs rely on to manage clients are precisely the tools attackers most want to hijack.
  6. Malware detections fell 55% in the same window that ransomware behaviour rose, confirming the shift toward fileless, living-off-the-land techniques that signature-based defences are poorly equipped to catch.

The RMM abuse statistic should stand out for MSPs. Traditional endpoint detection based on signatures can struggle when the attacker is using the same management tools the provider uses legitimately. The activity can look normal unless behaviour and context are analysed together.

Cloud Platforms and Microsoft 365

Microsoft 365 cloud security threats
Top 10 security threats found by Guardz in M365 cloud productivity tools

For many SMBs, the productivity suite is both the operating base of the business and a major part of its attack surface. OAuth grants, collaboration traffic and anonymous sharing links have become important paths for persistence, impersonation and data exposure.

  1. OAuth consent activity increased 45% between October 2025 and January 2026, then climbed another 24% from January to February. One malicious consent approval can give an attacker persistent access that remains even after a password reset.
  2. Guardz also saw Google Workspace OAuth abuse rise by more than 2,000% between September 2025 and February 2026, with 125,983 suspicious Google Workspace sign-ins. Because these threats span multiple platforms, protecting one productivity suite is no longer sufficient.
  3. Guardz captured more than 3.1 million Microsoft Teams messages containing links, bypassing SPF, DKIM and DMARC checks applied to email, making collaboration platforms a distinct phishing channel.

The Rest of 2026

The numbers are clear:

  • Session theft over password theft,
  • OAuth abuse over brute-force credentials, and
  • MSP supply chain as a high-value target.

The defensive posture must shift to match.

The broader signals tell the same story as the statistics. Adversary-in-the-middle phishing kits such as Tycoon 2FA and Evilginx are becoming easier to access. BEC tactics are moving beyond mailbox rules toward Graph API abuse. Double extortion is increasingly treated as the standard ransomware playbook. The MSP supply chain remains central because one compromised provider may expose hundreds of SMB customers.

Ready to strengthen your cyber security offering? Contact Manage Protect to see how Guardz delivers cost-effective, AI-powered protection for MSPs and their clients.

The Bottom Line for MSPs

For MSPs, the practical implication is clear: identity protection, session monitoring and behavioural detection must now be treated as part of the standard service layer. The same issue sits behind many of the statistics reported here, from credential abuse and session hijacking to OAuth misuse and BEC. Closing that identity monitoring gap can reduce risk across every client environment at once.

 

A version of this article was originally published by Guardz here. You can also read their complete analysis in the 2026 State of MSP Threat Report.

Related Articles

You may also be interested in...