The most damaging attacks abused trust, not exploits.
The 2026 MSP Threat Report's central finding. Attackers succeeded by abusing trusted identities, trusted software, trusted automation and trusting users, not by breaking systems. They blended into them.
This is our reading of the report for Australian businesses and the operators who support them. Six threat categories from 2025, what each one means on the ground, and the controls that close the gap.
What defined 2025
Ransomware victims, year on year
+58%
Primary attack surface
Trust
VPN access to full domain
< 2 hrs
Threat categories analysed
6
Drawn from ConnectWise Cyber Research Unit incident response investigations, partner telemetry and ransomware leak-site data across 2025.
What the report found
Initial access was rarely sophisticated. It was reliable.
Across the investigations behind this report, most successful intrusions began with credential abuse, a misconfigured VPN, or a user persuaded to run a command. Attackers did not need a zero-day when a valid path already existed.
The common thread was trust. Security controls that assumed trust, rather than verifying it, were routinely bypassed. For Australian businesses that lean on remote access and a small internal team, that is the uncomfortable part: the front door was usually left to the attacker by ordinary gaps, not clever ones.
58%
rise in ransomware victims on leak sites, year on year
Q4
the most dangerous period of 2025 for ransomware
< 2 hrs
VPN access to full domain compromise in some incidents
MITRE
ClickFix now has its own ATT&CK technique (T1204.004)
Reactive security models kept failing. Detection after execution was often too late. The environments hit hardest had limited identity monitoring, weak application control, or poor visibility into how processes were actually launched.
The 2025 threat landscape
Six ways attackers got in last year
Each category below is taken from the report and translated into what it means for an Australian business. Open one to read how it worked and where the exposure sits.
- Double extortion remained the dominant model: encrypt the files, steal the data, then pressure on a public leak site.
- Akira affiliates used stolen VPN credentials, then moved quickly: scan, steal, encrypt, with little effort to dwell quietly.
- Backup infrastructure was targeted early to prevent recovery and raise the pressure to pay.
- Fragmented extortion groups replaced takedowns, leaving a resilient ecosystem that complicates attribution and response.
What it means here
For Australian SMBs the risk is not being singled out, it is being part of a large pool of opportunistic targets. For too many, the easiest path in starts at the VPN.
Anatomy of an incident
How Akira moved from VPN to full compromise
Akira was one of the most disruptive ransomware operations of 2025, with a consistent lifecycle and little effort to stay quiet. In several incidents the path from VPN login to full domain compromise took under two hours.
Stolen VPN credentials log in to an exposed SSL VPN. Even with MFA enabled, migrated OTP seeds or inherited credentials let attackers walk in.
1Network scanners (Advanced IP Scanner, SoftPerfect) map the environment. Active Directory and credentials are dumped with Mimikatz and Ntdsutil.
2Backup credentials are harvested and restore points removed. Data is staged with WinRAR and exfiltrated using Rclone, WinSCP or FileZilla.
3Endpoint protection is disabled via a vulnerable driver, then the final payload encrypts files across systems. Double extortion follows.
4The takeaway: if you are not catching attackers at the VPN login or the recon phase, you are catching them too late. Backups are targeted early and on purpose, which is why immutable storage and tested restores matter as much as prevention.
From insight to action
The defences that actually moved the needle
The report's recurring conclusion is that security has to shift earlier in the attack lifecycle. These are the controls that mattered in 2025, and how we deliver them for Australian businesses.
Identity and privileged access
Identity and access failures sat at the centre of the most damaging incidents. Remove standing privileges, enforce least privilege and just-in-time elevation, and audit every administrative session.
Zero Trust architectureHardened, monitored remote access
SSL VPNs need treating as critical infrastructure, not background noise. Continuous login monitoring, phishing-resistant MFA, credential rotation after migrations, and firmware kept current.
Managed IT and cybersecurityManaged Detection and Response
Signature-based detection is too late when attacks blend into normal activity. Behaviour-based monitoring catches anomalous authentication, suspicious tooling and attempts to impair security controls early.
Managed Detection and ResponseApplication control and endpoint privilege
Trojanised installers and ClickFix both rely on user execution of legitimate tooling. Safelist what can be installed, verify installers, and watch script interpreters and persistence mechanisms.
Essential Eight complianceImmutable backup and tested recovery
Ransomware operators target backups first. Immutable storage, backup access isolated from production credentials, and regularly tested restores keep recovery possible when everything else is bypassed.
Backup and disaster recoveryAI-aware verification and governance
Deepfakes and AI-crafted lures defeat email-only awareness. Multi-channel verification for payments, browser extension allowlists, and a clear acceptable-use position on AI tools.
AI threats for Australian SMBsCommon questions
What businesses ask us about the report
Yes. The report studies attacks on the small and midsized businesses that MSPs support, which is exactly the profile of most Australian organisations. The patterns, credential abuse, VPN compromise, ClickFix and trojanised software, are the same ones hitting local businesses, often through the same exposed remote access.
Turn the report's findings into a plan
We will review your identity, remote access and backup posture against the patterns in this report and give you a prioritised, plain-English order of work. No obligation, no jargon.
Source: ConnectWise 2026 MSP Threat Report , "How Modern Attacks Abuse Trust and Identities". Findings drawn from ConnectWise Cyber Research Unit incident response investigations and partner telemetry across Calendar year 2025.

Remote Support