30 MSP Cybersecurity Statistics for 2026

MSP cybersecurity statistics 2026

Key takeaways

  • Identity is Where the Attack Unfolds, not Where it Starts: 89% of SMBs have at least one compromised credential, making identity the main attack surface.
  • AI is Increasing Attack Scale: AI is involved in 1 in 6 breaches and is driving more effective phishing and credential attacks.
  • Session Theft is Rising: Session hijacking grew 23%, while OAuth abuse surged, showing attackers are moving beyond passwords.
  • BEC Remains Highly Costly: Business email compromise caused $2.77B in reported losses and relies on account takeover and mailbox manipulation.

The defining shift in the 2026 threat landscape is the growing reliance on identity-based attacks. For the small and mid-size businesses MSPs protect, identity is now central to how attacks unfold. Even as software vulnerabilities overtook stolen passwords as the top initial entry point in Verizon’s 2026 Data Breach Investigations Report, compromised credentials still feature in 13% of breaches once attackers move past first contact, through stolen sessions, abused cloud permissions, and lateral movement. Identity systems and everyday business tools now sit at the center of the attack, changing both where risk starts and how teams have to respond.

This roundup pulls together 30 statistics that map the terrain across six areas. We look at AI-driven attacks, identity compromise, business email compromise, ransomware and the endpoint, the cloud and Microsoft 365, and what the numbers signal for the second half of the year. The figures come from established industry research (IBM, Verizon, the FBI, Datto, and Gartner) alongside original Guardz telemetry, drawn from a 180-day observation period spanning billions of audit events across Microsoft 365 and Google Workspace environments.

MSP-specific data matters because MSPs sit at the center of the SMB attack surface, making their telemetry a leading indicator of where attacker tactics are heading next. For the technician triaging alerts at 2 a.m. and the MSP owner scaling a security practice, the message is the same. Threats are evolving faster, becoming more automated, and increasingly targeting the identities and platforms that keep businesses running.

MSP Cybersecurity Statistics at a Glance

StatisticFigureSource
SMBs with at least one compromised credential at any time89%Guardz
Unique password-spray source IPs per month14,000+Guardz
Growth in session hijacking over 180 days23%Guardz
Growth in logins from known-malicious infrastructure (120 days)50%Guardz
Spike in Google Workspace OAuth abuse (Sep 2025 to Feb 2026)2,000%+Guardz
Confirmed suspicious Google Workspace logins125,983Guardz
Breaches involving AI (phishing, deepfakes)1 in 6IBM
Global average cost of a data breach$4.44MIBM
The US average cost of a data breach$10.22MIBM
Reported BEC losses (most recent year)$2.77BFBI IC3
SMB breaches involving ransomware88%Verizon

AI-Powered Threats Are Rewriting the Attack Playbook

Generative AI has erased the old tells of a phishing email and handed commodity attackers capabilities that once belonged to nation-states. The numbers below show how quickly the offense is compounding, and how the defense is starting to answer in kind.

1. AI now factors into roughly 1 in 6 data breaches, used most often for phishing and deepfake impersonation, according to IBM’s Cost of a Data Breach Report. The barrier to a convincing attack has collapsed.

2. The global average cost of a data breach is $4.44M, but in the United States, it has climbed to a record $10.22M, per the same IBM research. For an SMB client, even a fraction of that figure can be existential.

3. Guardz telemetry shows roughly 31% of monitored users have compromised passwords in any given month, a direct consequence of AI-optimized credential stuffing running continuously against SMB tenants.

4. Guardz observed more than 14,000 unique password-spray source IPs per month, each targeting 10 or more accounts, with spray infrastructure growing about 13% month over month. This is automation at a scale no manual defense can match.

5. AI-generated phishing has erased the old detection cues. The 2026 Verizon DBIR notes that attackers now use AI assistance across 15 or more attack techniques, and updated its own phishing-detection guidance from spotting typos to spotting em dashes, a sign of how convincing machine-written lures have become. The offense is using AI to scale attacks, and the defense has to match that volume. 

The takeaway for MSPs is not that AI replaces analysts. It is that the volume and polish of AI-driven attacks make automated first-pass triage a baseline requirement, and the math only worsens as each new client environment is added to the book.

Identity Is the Most Attacked Layer

For SMBs, identity has overtaken the endpoint as the front line. Continuous, automated pressure on credentials is now the baseline condition of doing business, not an occasional event.

6. Across monitored environments, Guardz found that 89% of SMBs have at least one user with a confirmed credential compromise at any given point in time. Compromise is not the exception; it is the standing state.

7. Nearly 1 in 3 sign-in attempts in monitored tenants is unauthorized, with failed authentication events holding at 28% to 30% across every region over the full 180-day window. The pressure is global and constant.

8. Session hijacking rose about 23% over the same 180 days, making it the fastest-growing identity attack category in the Guardz dataset. As MFA adoption climbs, attackers are shifting from stealing passwords to stealing the authenticated session itself.

9. Stolen credentials remain a leading entry point for attackers, even as vulnerability exploitation overtook them as the top initial access vector for the first time in the 19-year history of Verizon’s Data Breach Investigations Report. Credential abuse featured in 13% of breaches in the 2026 edition, and the human element remained present in 62% of breaches overall.

10. Authentication attempts originating from known-malicious infrastructure grew 50% over a 120-day window in Guardz telemetry, a clear signal that adversaries are industrializing their access attempts.

11. The United States accounts for 75.4% of recorded adversary-in-the-middle phishing incidents in the Guardz dataset, reflecting both target density and the maturity of phishing-as-a-service kits aimed at North American businesses.

The shift toward session hijacking is the development that defenders most need to absorb. An attacker riding a valid, authenticated session does not trigger the alarms designed to catch a stolen password, which is why identity threat detection has shifted toward analyzing login behavior, permission changes, and session anomalies in real time rather than gating on credentials alone. 

Email and Business Email Compromise Remain the Money Vector

Email is where a compromised identity turns into financial loss. The persistence techniques are quiet, the payouts are climbing, and the attack rarely involves a malicious link or attachment at all.

12. Business email compromise drove $2.77B in reported losses across 21,442 complaints in the FBI’s Internet Crime Report 2024, second only to investment fraud in total dollars lost. BEC works because it exploits trust and routine, not technology.

13. Confirmed BEC incidents analyzed by Guardz in 2026 ranged from $140k to $1.5M per event. For an SMB, the lower end of that range can still mean the difference between solvency and closure.

14. Guardz recorded a 240% surge in email quarantine activity, with inbox-rule modifications roughly doubling over the measurement window. Quiet manipulation of the mailbox is the tell that an account has been taken over.

15. Malicious inbox rules remain the leading persistence mechanism in BEC attacks, mapped to MITRE technique T1098.003. Guardz observed a 13x spike in suspicious inbox rules in the US across 304 affected users, the mechanism attackers use to hide replies and sustain access undetected.

16. Nearly 2 million SendAs operations appeared in the Guardz dataset, a strong indicator of widespread email impersonation, where an attacker sends mail as a legitimate user to redirect payments or harvest further access.

What makes BEC so durable is that there is no malware to detect and no exploit to patch, only a believable message arriving at the right moment. That pushes detection up the stack to the identity and behavior layer, where a suspicious login and an anomalous inbox rule can be read as one event rather than two.

Ransomware and the Endpoint Threat Surface

Ransomware is a small share of total threat volume but remains the highest-impact category, where each instance is a potential business-ending event. The tooling has shifted decisively toward living off the land, using the tools already trusted inside the environment.

17. Ransomware was present in 48% of breaches in the latest Verizon data, up from 44% the prior year, even as the median ransom payment fell to $139,875 and only 31% of victims chose to pay, according to the 2026 Verizon DBIR. Attacks are rising while the willingness to pay keeps falling.

18. Ransomware was implicated in 88% of breaches involving SMBs in the latest Verizon data, far above the rate for large enterprises. The SMBs that MSPs serve are not collateral damage; they are the primary target. 

19. The cost of downtime from a ransomware attack can reach up to 50 times the ransom demand itself, Datto’s channel research has found. The ransom is rarely the real expense; the lost operating days are.

20. Guardz recorded a 190% surge in ransomware behavioral detections over a single 50-day window, evidence that pre-encryption attacker behavior is both detectable and accelerating.

21. Remote monitoring and management tool abuse is the single largest endpoint threat campaign in the Guardz dataset, at 26.2% of all endpoint threats. The tools MSPs rely on to manage clients are precisely the tools attackers most want to hijack.

22. Malware detections fell 55% in the same window that ransomware behavior rose, confirming the shift toward fileless, living-off-the-land techniques that signature-based defenses are poorly equipped to catch.

23. Guardz saw ransomware spike to 8.2% of all threats in December 2025, nearly double the 180-day average, consistent with the long-running pattern of attackers timing campaigns to holiday periods when staffing is thin.

The RMM-abuse figure is the one that should concentrate MSP attention. A signature-based endpoint tool cannot distinguish legitimate RMM use from an attacker living inside the same software, because the activity is identical at the signature level. Only behavioral detection catches the difference, and the stakes are doubled for an MSP: the tooling that makes the business efficient is the tooling an attacker most wants to turn against every client at once.

The Cloud and Microsoft 365 Attack Surface

The productivity suite is now the operational backbone of the SMB and its breach surface in one. OAuth grants and anonymous sharing links have become the new channels for persistence and exfiltration.

24. OAuth consent events rose 45% between October 2025 and January 2026 in Guardz telemetry, followed by a further 24% jump from January to February. A single malicious consent grant can hand an attacker durable access that survives a password reset.

25. Guardz recorded a spike exceeding 2,000% in Google Workspace OAuth abuse between September 2025 and February 2026, alongside 125,983 confirmed suspicious Google Workspace logins. The cross-platform nature of the threat means securing one suite is no longer enough.

26. More than 3.1 million link-bearing messages were sent through Microsoft Teams over 180 days in the Guardz dataset, traffic that bypasses the SPF, DKIM, and DMARC checks that protect email. Collaboration platforms are now a phishing channel in their own right.

27. Cloud security is the fastest-growing subsegment of security spending heading into 2026, expanding 28.8% year over year, faster than any other category, as organizations race to cover gaps that cloud and AI adoption have widened, according to Gartner. The spend is following the risk.

What the Data Signals for the Rest of 2026

The trend lines point in one direction: session theft over password theft, OAuth abuse over brute-force credentials, and the MSP supply chain as a high-value target in its own right. The defensive posture has to shift to match.

28. Worldwide spending on information security is projected to reach $244.2B in 2026, up 13.3% year over year, with managed security services among the fastest-growing categories as the talent shortage pushes more organizations toward providers, per Gartner. The demand for what MSPs sell is rising in step with the threat. 

29. An estimated 98% of organizations would be at least somewhat exposed to an attack if their primary MSP or security partner were suddenly unavailable, according to research from Infosecurity Europe. A single point of failure in the provider cascades to every downstream client, which is exactly why supply-chain targeting of MSPs is intensifying.

30. The shift away from passwords is underway but far from complete. 68% of organizations have deployed or are actively deploying passkeys for employee sign-ins, yet 57% still rely on phishable authentication for primary day-to-day access, according to FIDO Alliance research. That gap is exactly why credential and session compromise remain the dominant attack path. 

Beyond the numbers, the qualitative signals reinforce the same story. Adversary-in-the-middle phishing kits such as Tycoon 2FA and Evilginx are going fully commodity. BEC tradecraft is migrating from inbox rules toward direct Graph API abuse. Double extortion is becoming the ransomware default rather than a premium tactic. And the MSP supply chain sits at the center of it, because compromising one provider can expose hundreds of SMBs at once.

Much of the original telemetry behind these patterns comes from Guardz, whose 2026 State of MSP Threat Report is built on billions of audit events observed over a continuous 180-day period across the live Microsoft 365 and Google Workspace tenants that MSPs manage. That scale and vantage point are what surface findings the broader industry reports miss: the 89% credential-compromise baseline, the 2,000% jump in Google Workspace OAuth abuse, the 23% rise in session hijacking. Continuous telemetry of this kind functions as an early-warning system, showing where attacker behavior is shifting weeks before it registers in annual survey data.

The Bottom Line

30 numbers, one story. The perimeter has moved to identity, the attack now unfolds as a single chain rather than a set of isolated events, and the defense has to match that with both speed and judgment.

For MSPs, the data points to one concrete shift – stop treating identity protection, session monitoring, and behavioral detection as premium add-ons, and start treating them as the default service layer. Every stat in this roundup that involves credential abuse, session hijacking, OAuth manipulation, or BEC traces back to the identity layer being under-monitored. That is the one control gap that, if closed, changes the risk profile of every client on the book simultaneously.

The MSPs that pull ahead in 2026 will be the ones that build for this before their clients need them to. The threat data is no longer ambiguous about where the next year is heading. The open question is which providers will have moved first.

You can read the complete dataset in the 2026 State of MSP Threat Report.

Still have questions before choosing a plan?
Talk to a real human. No forms. No waiting. No Slack account needed.

No Slack account needed.

A Note on Sources

The statistics in this article draw on a mix of original telemetry and established industry research. Guardz figures come from the 2026 State of MSP Threat Report, based on a 180-day window of audit events across Microsoft 365 and Google Workspace environments. The external figures are drawn from IBM’s Cost of a Data Breach report, Gartner’s information security forecasts, the Verizon Data Breach Investigations Report, the FBI Internet Crime Report, and channel research from Datto. Where figures come from survey or incident-response data rather than continuous telemetry, the reporting period and source are noted alongside the statistic.

Categories:

Doni Brass is a product leader who has been creating cutting-edge technology for nearly two decades, specializing in cybersecurity and technical support tools. As the SVP of product strategy and community at Guardz, a cybersecurity startup, he leads the mission to make the digital world safer for small and medium-sized businesses.

Subscribe to
Our Newsletter.

Abstract image of two overlapping shield shapes, one dark blue and one green, with a soft glowing effect on a light background—perfect for enhancing your single post template with a modern, secure aesthetic.
Abstract image with a large dark blue, semi-circular shape overlapping a bright green, glowing circular shape on a light gray background. Perfect for enhancing your single post template, the green circle appears partially blurred and luminous.

Keep your clients secure.

A stylized, dark blue shield icon with a green gradient glow on the right side, set against a light gray background—ideal for enhancing your single post template design.

Continue Reading

A hooded hacker attacks with digital code while a warrior inspired by Kratos defends with a shield, blocking access to credentials and security icons, symbolizing cybersecurity defense in a game-like battle.

Inside Kratos PhaaS

How MSPs Monitor Security Across Multiple Client Tenants

Green digital code streams down a black screen, resembling the iconic Matrix movie effect, with various symbols, letters, and numbers appearing in vertical columns—evoking the intricate workflows of MSPs managing cybersecurity in a multi-tenant model.

Cynet Alternatives for MSPs: 6 Platforms That Actually Fit the Multi-Tenant Model

A person in a futuristic chair sits at a high-tech control panel, looking out at a starry space scene with planets and mountains. The dashboard glows with colorful buttons and screens, like the perfect single post template for exploring new worlds.

Guardz, Your Cybersecurity
Co-Pilot for MSPs

Demonstrate the value you bring to the table as an MSP and gain visibility into your clients’ external postures.

Holistic Protection.
Hassle-Free.
Cost-Effective.
Slack
Slack
Chat with us No Slack account needed.