logo

Guardz-State-of-MSP-Threat-Report-2026.md

ID: 47fd918e-7bf0-44ff-bf27-effc4f395e2f

STIX ID: report--47fd918e-7bf0-44ff-bf27-effc4f395e2f

Threat Score

78/100

Uploaded: 2026-08-14

Published Date: 2026-07-26

Last Modified Date: 2026-07-26

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The Guardz 2026 State of MSP Threat Report presents telemetry-driven findings showing a shift to identity- and AI-driven attacks against MSP-managed SMBs: large-scale AI-enabled phishing (AiTM), automated credential stuffing, OAuth consent abuse, RMM tool abuse, and ransomware are active and growing. The report documents high-volume indicators (e.g., 14,000+ spray IPs/month, ~31% monthly compromised passwords, 125,983 suspicious GWS logins, a 23% rise in session hijacking, 560 ransomware detections, and confirmed BEC losses up to $1.5M), outlines prevalent TTPs and affected services (M365, GWS, Copilot), and recommends phishing-resistant MFA, passwordless auth, OAuth governance, and tighter MSP supply-chain controls.