RMM abuse is emerging as one of the most immediate cybersecurity risks facing managed service providers and their customers, with Huntress reporting a 277% year-over-year increase in 2025 and involvement in 45% of endpoint-related incidents during the first quarter of 2026.
Those findings are part of Huntress’ new “Tragic Quadrant” research, which ranks cyberattack tactics by both how frequently they occur and how close they put organizations to serious business damage. The analysis draws on telemetry from more than 5 million endpoints and 15 million identities across nearly 300,000 protected organizations.
For MSPs, the broader warning is that some of the most consequential attacks are not relying on exotic new techniques. Instead, attackers are increasingly abusing trusted remote-management tools, authenticated sessions, mailbox rules, and other technologies already embedded in customers’ environments.
RMM abuse puts a core MSP tool in attackers’ sights
The significance of RMM abuse goes beyond its prevalence. Remote management platforms are foundational to the MSP operating model, providing technicians with persistent access and remote command capabilities across customer environments.
Those same features can make unauthorized use difficult to distinguish from legitimate administrative activity.
One Huntress investigation illustrates that challenge. A fake service agreement led to Tiflux being installed on a device, followed by UltraVNC, Splashtop, and ScreenConnect, providing the attacker with multiple avenues for persistent access.
For MSPs that depend on remote-management tooling to serve customers at scale, the takeaway is not to retreat from RMM but to establish tighter control over what remote tools are authorized and improve detection of unexpected installations and behavior.
Identity threats are bypassing traditional MFA defenses
The report also underscores why identity protection cannot end with the deployment of multifactor authentication.
Mailbox manipulation represented 24.6% of Huntress identity threat signals observed in 2026. Once inside an account, attackers can create inbox rules that conceal messages, manipulate vendor communications, or support business email compromise without deploying malware.
AiTM attacks present another challenge. They accounted for 18.9% of identity-based threats Huntress tracked in 2025. In these attacks, adversaries can intercept a valid session token during authentication, allowing them to access an account even after the victim has successfully completed MFA.
That shifts the conversation MSPs need to have with customers from simply securing credentials toward securing authenticated sessions, access controls, mailbox configurations, and identity activity after login.
AI is accelerating familiar threats, not replacing them
Despite the industry’s focus on AI-enabled cybercrime, Huntress places AI platform abuse and deepfake or voice-phishing attacks in its “overhyped, for now” category because it has not yet observed them causing widespread damage at the same rate as higher-priority techniques.
That does not mean AI can be ignored.
Huntress has observed attackers using AI-generated RMM phishing lures, while its research into device-code phishing found that attackers use AI to build phishing infrastructure and automate analysis of compromised inboxes.
What Huntress’ findings mean for MSP security strategies
For channel partners, that distinction matters. The immediate opportunity may be less about selling customers protection against an entirely new generation of exotic “AI attacks” and more about strengthening defenses around the mundane technologies attackers already know work.
The report ultimately points MSPs toward a risk-based security conversation: inventory legitimate remote-management tools, monitor identities after authentication, tighten mailbox and access configurations, and maintain rapid patching processes.
AI may make attackers faster and their lures more convincing, but for now, many of the most consequential attacks are still succeeding by turning everyday business technology against the organizations that trust it.




