Views Bangladesh Logo

Government sector becomes top target for cyberattacks as AI accelerates threats

Special  Correspondent

Special Correspondent

Government agencies and public services have become the biggest targets of cyberattackers worldwide, accounting for 27% of the cyber threats observed over the past year, up from 17% the previous year. At the same time, hackers are increasingly using artificial intelligence (AI) to accelerate and expand their attacks.

The findings were published in Microsoft’s annual Digital Defense Report 2026, released on October 1. The report is based on data collected between July 2025 and June 2026, during which Microsoft analysed more than 165 trillion security signals every day.

According to the report, AI is shortening the time required to launch cyberattacks and reducing the cost of carrying out complex operations. A software vulnerability can be weaponised less than 24 hours after it becomes publicly known.

Government sector emerges as top target


State-backed hacking groups are targeting government networks more than any other sector. The IT sector was the second-most targeted, accounting for 17% of threats, followed by research and education institutions at 14%.

Phishing has emerged as the main route into government systems. It accounted for 23% of intrusions, compared with just 7% the previous year. In 52.2% of incidents involving stolen legitimate accounts, attackers went on to obtain additional passwords and identity information.

The report said state-backed hacking groups from China, Russia, Iran and North Korea were active in seeking long-term access to critical systems in various countries. The United States, Taiwan, the United Kingdom and Israel recorded the highest levels of state-sponsored cyber activity.

AI is reshaping attack techniques


Microsoft said attackers are now using AI to identify targets, create deceptive messages, write malware and exploits, and carry out post-compromise activities. In most cases, however, AI remains limited to specific stages of conventional attack operations.

As a result, although the underlying tactics remain largely unchanged, attacks are becoming faster, more scalable and more targeted.

The nature of cyber fraud is also changing. More than 145 million QR-code-based phishing attacks were detected over the year, while more than 46 million attacks involved impersonating business contacts. In 93% of voice-phishing cases, attackers were able to keep victims on the phone for a sufficient period to advance the scam.

Advances in AI-assisted code analysis have made it easier to identify software vulnerabilities. This allows defenders to patch flaws earlier, but the same technology is also giving attackers a more powerful tool. The number of publicly disclosed software vulnerabilities could reach 72,000 this year, the report said.

Growing concerns over AI agents

According to the report, 88% of organisations are now experimenting with AI agents, while 82% plan to expand their use over the next 12 to 18 months. The number of active AI agents worldwide is projected to reach 1.3 billion by 2028.

These agents can access organisational data, applications and various tools. Microsoft warned that the same connections that make AI agents useful can also create new security risks.

The report therefore stressed the need for dedicated identities for AI agents, limited access privileges and mechanisms to rapidly revoke permissions when necessary. Nearly 10,000 organisations have been affected by data theft from AI chats through malicious browser extensions, according to the report.

Data theft and ransomware on the rise


Data was stolen in 63% of all intrusions, the report said. Ransomware attacks against organisations increased by 15.8%, with the manufacturing sector accounting for the largest share of victims.

Cloud services exposed to the internet were attacked, on average, within just 5 hours and 18 minutes.

Across all sectors, attackers are taking longer to be detected after gaining access to systems. However, once detected, organisations have become faster at responding to incidents, according to the report.

Five priorities for governments

With the government sector emerging as the largest target, Microsoft outlined five priorities for governments: preparing for rapid decision-making and coordination before cyber incidents occur; building security into the design of AI systems and their supply chains; preparing for the possibility that an intrusion will spread across networks; strengthening threat-intelligence sharing between the public and private sectors; and conducting regular exercises to ensure essential services can continue operating during cyberattacks.

The report said fundamental cybersecurity practices—including identity and access management, data protection, least-privilege access and secure software development—remain effective.

AI, it said, is essentially bringing these established practices into increasingly interconnected systems.

Leave A Comment

Avatar

Trending Views