ConnectWise 2026 MSP Threat Report · Calendar year 2025

The most damaging attacks abused trust, not exploits.

The 2026 MSP Threat Report's central finding. Attackers succeeded by abusing trusted identities, trusted software, trusted automation and trusting users, not by breaking systems. They blended into them.

This is our reading of the report for Australian businesses and the operators who support them. Six threat categories from 2025, what each one means on the ground, and the controls that close the gap.

What defined 2025

Ransomware victims, year on year

+58%

Primary attack surface

Trust

VPN access to full domain

< 2 hrs

Threat categories analysed

6

Drawn from ConnectWise Cyber Research Unit incident response investigations, partner telemetry and ransomware leak-site data across 2025.

What the report found

Initial access was rarely sophisticated. It was reliable.

Across the investigations behind this report, most successful intrusions began with credential abuse, a misconfigured VPN, or a user persuaded to run a command. Attackers did not need a zero-day when a valid path already existed.

The common thread was trust. Security controls that assumed trust, rather than verifying it, were routinely bypassed. For Australian businesses that lean on remote access and a small internal team, that is the uncomfortable part: the front door was usually left to the attacker by ordinary gaps, not clever ones.

58%

rise in ransomware victims on leak sites, year on year

Q4

the most dangerous period of 2025 for ransomware

< 2 hrs

VPN access to full domain compromise in some incidents

MITRE

ClickFix now has its own ATT&CK technique (T1204.004)

Reactive security models kept failing. Detection after execution was often too late. The environments hit hardest had limited identity monitoring, weak application control, or poor visibility into how processes were actually launched.

The 2025 threat landscape

Six ways attackers got in last year

Each category below is taken from the report and translated into what it means for an Australian business. Open one to read how it worked and where the exposure sits.

  • Double extortion remained the dominant model: encrypt the files, steal the data, then pressure on a public leak site.
  • Akira affiliates used stolen VPN credentials, then moved quickly: scan, steal, encrypt, with little effort to dwell quietly.
  • Backup infrastructure was targeted early to prevent recovery and raise the pressure to pay.
  • Fragmented extortion groups replaced takedowns, leaving a resilient ecosystem that complicates attribution and response.

What it means here

For Australian SMBs the risk is not being singled out, it is being part of a large pool of opportunistic targets. For too many, the easiest path in starts at the VPN.

Anatomy of an incident

How Akira moved from VPN to full compromise

Akira was one of the most disruptive ransomware operations of 2025, with a consistent lifecycle and little effort to stay quiet. In several incidents the path from VPN login to full domain compromise took under two hours.

Access

Stolen VPN credentials log in to an exposed SSL VPN. Even with MFA enabled, migrated OTP seeds or inherited credentials let attackers walk in.

1
Recon

Network scanners (Advanced IP Scanner, SoftPerfect) map the environment. Active Directory and credentials are dumped with Mimikatz and Ntdsutil.

2
Steal

Backup credentials are harvested and restore points removed. Data is staged with WinRAR and exfiltrated using Rclone, WinSCP or FileZilla.

3
Encrypt

Endpoint protection is disabled via a vulnerable driver, then the final payload encrypts files across systems. Double extortion follows.

4

The takeaway: if you are not catching attackers at the VPN login or the recon phase, you are catching them too late. Backups are targeted early and on purpose, which is why immutable storage and tested restores matter as much as prevention.

From insight to action

The defences that actually moved the needle

The report's recurring conclusion is that security has to shift earlier in the attack lifecycle. These are the controls that mattered in 2025, and how we deliver them for Australian businesses.

01

Identity and privileged access

Identity and access failures sat at the centre of the most damaging incidents. Remove standing privileges, enforce least privilege and just-in-time elevation, and audit every administrative session.

Zero Trust architecture
02

Hardened, monitored remote access

SSL VPNs need treating as critical infrastructure, not background noise. Continuous login monitoring, phishing-resistant MFA, credential rotation after migrations, and firmware kept current.

Managed IT and cybersecurity
03

Managed Detection and Response

Signature-based detection is too late when attacks blend into normal activity. Behaviour-based monitoring catches anomalous authentication, suspicious tooling and attempts to impair security controls early.

Managed Detection and Response
04

Application control and endpoint privilege

Trojanised installers and ClickFix both rely on user execution of legitimate tooling. Safelist what can be installed, verify installers, and watch script interpreters and persistence mechanisms.

Essential Eight compliance
05

Immutable backup and tested recovery

Ransomware operators target backups first. Immutable storage, backup access isolated from production credentials, and regularly tested restores keep recovery possible when everything else is bypassed.

Backup and disaster recovery
06

AI-aware verification and governance

Deepfakes and AI-crafted lures defeat email-only awareness. Multi-channel verification for payments, browser extension allowlists, and a clear acceptable-use position on AI tools.

AI threats for Australian SMBs

Common questions

What businesses ask us about the report

Yes. The report studies attacks on the small and midsized businesses that MSPs support, which is exactly the profile of most Australian organisations. The patterns, credential abuse, VPN compromise, ClickFix and trojanised software, are the same ones hitting local businesses, often through the same exposed remote access.

Turn the report's findings into a plan

We will review your identity, remote access and backup posture against the patterns in this report and give you a prioritised, plain-English order of work. No obligation, no jargon.

Source: ConnectWise 2026 MSP Threat Report , "How Modern Attacks Abuse Trust and Identities". Findings drawn from ConnectWise Cyber Research Unit incident response investigations and partner telemetry across Calendar year 2025.