Construction AI BriefSubscribe →
Issue
№321
Pillar
Trend
Audience
GC ops
Dated
2026.10.03

Microsoft says AI phishing now starts 23% of the intrusions it investigates. Here's what a contractor's payment and email controls need

Microsoft's 2026 Digital Defense Report says attackers are getting AI's benefits first, with phishing up from 7% to 23% of incident-response intrusions. For GCs and subs, the exposure runs through email, vendor payments and shared accounts.

ByConstruction AI BriefAbout this publication

Microsoft's 2026 Digital Defense Report says phishing started 23% of the intrusions in its incident-response cases, up from 7% a year earlier, and that attackers are getting AI's benefits before defenders. For a contractor, the practical exposure is the email inbox that approves pay apps, vendor bank changes and shared project accounts.

What did Microsoft actually report?

Per Microsoft's own summary and coverage from Help Net Security and BleepingComputer, the report's main points are:

  • Attackers have the near-term advantage. Microsoft expects defenders to gain similar AI benefits eventually, but says the gap exists now.
  • Phishing is up sharply. It was the initial access vector in 23% of intrusions in Microsoft's incident-response cases, versus 7% the year before.
  • Patch windows are shrinking. The median time from a vulnerability being found in the wild to being weaponized is well below 24 hours.
  • Session theft is common. Adversary-in-the-middle kits are 44.6% of identified phishing techniques, per a write-up of the report, and 87.7% of phishing intrusions involved credential or session harvesting.

Microsoft's incident-response cases are a sample of organizations that asked for help, not a census of all attacks. Treat the percentages as direction, not a measured industry rate.

Why does this reach a contractor's accounting desk?

Construction runs on email approvals with money attached. Pay applications, lien waivers, retainage releases, change-order approvals and updated ACH instructions all move by message. AI makes a believable fake easier to produce: it can copy a sub's tone, reference a real project name and arrive in an existing thread.

The report says nothing construction-specific, so the link is an inference. But the pattern it describes, a stolen session leading to follow-on credential theft (52.2% of valid-account intrusions in the report), fits how payment-redirection fraud works.

What should a GC or sub change this month?

ControlWhat it stopsEffort
Call-back rule for any change to bank details, using a number already on fileRedirected vendor and sub paymentsLow
Passkeys or hardware keys for accounting, PM and executive accountsSession and password theft that gets past text-message codesMedium
Auto-update on laptops, VPN and remote-access toolsThe sub-24-hour exploit windowLow
Separate approval for payments over a set dollar amountOne compromised mailbox approving a large paymentLow
Limited, named access for outside parties on shared project sitesA guest account used as the way inMedium

Should a mid-size contractor buy something new?

Probably not first. Most of the table is policy, not software. The one purchase worth pricing is phishing-resistant sign-in for the handful of people who can move money. If an outside IT provider runs your systems, ask them in writing how fast they apply security patches and whether remote access is protected by anything beyond a password and text code.

Limits to keep in mind: the 23% figure comes from vendor incident-response data, and the report's forecasts about autonomous attacks are projections. The fixes above are standard hygiene, and they hold up whether the AI forecasts prove right or not.

Takeaway

Pick the three or four people in your company who can approve a payment or change bank details. This week, require a call-back for any bank change and move those accounts to a passkey or hardware key. That covers the most direct route from a convincing fake email to money leaving your account.

FAQCommon questions
What did Microsoft's 2026 Digital Defense Report say about AI and phishing?
Microsoft reported that phishing was the initial access vector in 23% of the intrusions in its incident-response cases, up from 7% the year before. It says AI lets attackers personalize lures at scale, and that attackers are getting AI's benefits before defenders do.
How fast are attackers exploiting new software vulnerabilities now?
The report says the median time from a vulnerability being discovered in the wild to being weaponized is well below 24 hours. That leaves little time to patch internet-facing systems.
Does multi-factor authentication stop modern phishing?
Not always. Reporting on the Microsoft data says adversary-in-the-middle kits are 44.6% of identified phishing techniques, and these steal session tokens in addition to passwords. Phishing-resistant methods such as passkeys or hardware keys hold up better than text-message codes.
Why does this matter for construction companies?
Contractors move large payments through email-driven workflows, such as pay applications, lien waivers and changes to vendor bank details. A single compromised mailbox can be used to redirect those payments.
End of sheet — issue №321
Published · 2026.10.03
Project
Construction AI Brief
Dated
2026.10.04
Sheet
1 / 1
Rev
A
Published independently · constructionaibrief.com · © 2026Facebook·Privacy·About