Why Trusted IT Tools are Becoming a Bigger MSP Security Risk

Huntress research identifies RMM abuse, mailbox manipulation, and account takeovers as cyber threats MSPs should prioritize in 2026.

Oct 1, 2026
3 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

RMM abuse is emerging as one of the most immediate cybersecurity risks facing managed service providers and their customers, with Huntress reporting a 277% year-over-year increase in 2025 and involvement in 45% of endpoint-related incidents during the first quarter of 2026.

Those findings are part of Huntress’ new “Tragic Quadrant” research, which ranks cyberattack tactics by both how frequently they occur and how close they put organizations to serious business damage. The analysis draws on telemetry from more than 5 million endpoints and 15 million identities across nearly 300,000 protected organizations.

For MSPs, the broader warning is that some of the most consequential attacks are not relying on exotic new techniques. Instead, attackers are increasingly abusing trusted remote-management tools, authenticated sessions, mailbox rules, and other technologies already embedded in customers’ environments. 

RMM abuse puts a core MSP tool in attackers’ sights

The significance of RMM abuse goes beyond its prevalence. Remote management platforms are foundational to the MSP operating model, providing technicians with persistent access and remote command capabilities across customer environments. 

Those same features can make unauthorized use difficult to distinguish from legitimate administrative activity.

One Huntress investigation illustrates that challenge. A fake service agreement led to Tiflux being installed on a device, followed by UltraVNC, Splashtop, and ScreenConnect, providing the attacker with multiple avenues for persistent access.

For MSPs that depend on remote-management tooling to serve customers at scale, the takeaway is not to retreat from RMM but to establish tighter control over what remote tools are authorized and improve detection of unexpected installations and behavior.

Identity threats are bypassing traditional MFA defenses

Advertisement

The report also underscores why identity protection cannot end with the deployment of multifactor authentication.

Mailbox manipulation represented 24.6% of Huntress identity threat signals observed in 2026. Once inside an account, attackers can create inbox rules that conceal messages, manipulate vendor communications, or support business email compromise without deploying malware. 

AiTM attacks present another challenge. They accounted for 18.9% of identity-based threats Huntress tracked in 2025. In these attacks, adversaries can intercept a valid session token during authentication, allowing them to access an account even after the victim has successfully completed MFA. 

That shifts the conversation MSPs need to have with customers from simply securing credentials toward securing authenticated sessions, access controls, mailbox configurations, and identity activity after login.

AI is accelerating familiar threats, not replacing them

Despite the industry’s focus on AI-enabled cybercrime, Huntress places AI platform abuse and deepfake or voice-phishing attacks in its “overhyped, for now” category because it has not yet observed them causing widespread damage at the same rate as higher-priority techniques. 

That does not mean AI can be ignored.

Huntress has observed attackers using AI-generated RMM phishing lures, while its research into device-code phishing found that attackers use AI to build phishing infrastructure and automate analysis of compromised inboxes. 

What Huntress’ findings mean for MSP security strategies

For channel partners, that distinction matters. The immediate opportunity may be less about selling customers protection against an entirely new generation of exotic “AI attacks” and more about strengthening defenses around the mundane technologies attackers already know work.

The report ultimately points MSPs toward a risk-based security conversation: inventory legitimate remote-management tools, monitor identities after authentication, tighten mailbox and access configurations, and maintain rapid patching processes.

Advertisement

AI may make attackers faster and their lures more convincing, but for now, many of the most consequential attacks are still succeeding by turning everyday business technology against the organizations that trust it.

Victoria Durgin

Victoria Durgin is a technology communications professional and editorial leader specializing in channel technology, cloud marketplaces, managed service providers (MSPs), technology distribution, and partner ecosystems. As Managing Editor of Channel Insider, she oversees editorial strategy and content development focused on helping technology vendors, solution providers, and channel partners navigate an evolving IT landscape. With nearly a decade of experience spanning technology journalism, corporate communications, content strategy, and digital publishing, Victoria has developed deep expertise in the business side of technology. Her work includes creating executive thought leadership content, industry analysis, case studies, and channel-focused reporting that helps organizations better understand market trends, partner relationships, and technology buying decisions. Before leading Channel Insider, Victoria built experience across local journalism, business reporting, social media communications, and corporate marketing. She has worked closely with technology vendors, cloud providers, and managed service organizations to develop content that highlights industry innovation, business growth strategies, and successful channel partnerships. Her portfolio includes case studies featuring mid-sized MSPs across the United States, Canada, and Australia. Victoria's work has appeared in Channel Insider, The Valley Ledger, and Medium. She holds a Bachelor of Arts in Communications and Environmental Studies from Susquehanna University. Through her reporting and editorial leadership, she helps technology professionals stay informed about the trends, challenges, and opportunities shaping the global IT channel.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.