By now, it’s well known that AI is turbocharging cybercrime, with adversaries using the tech to speed up every stage of attack, and create frighteningly intelligent code that can easily outmanoeuvre traditional defences.
The problem has reached almost endemic proportions, with CrowdStrike’s latest State of Ransomware Survey finding that more than three-quarters (76%) of organisations are struggling to match the speed and sophistication of AI-powered attacks.
This is having a particularly outsized impact when it comes to the proliferation of ransomware, with nearly half (48%) of the more than 1,000 cyber decision-makers polled by CrowdStrike saying that AI-automated attack chains are today’s greatest ransomware threat.
The study found that half of security leaders fear that they can’t detect or respond as fast as AI-driven attacks can execute, while an overwhelming majority (85%) report that traditional detection is becoming obsolete against AI-enhanced attacks.
Unsurprisingly, this has led to a spike in critical incidents. The report found that 78% of organisations have been hit by ransomware in the past year, with fewer than a quarter recovering within 24 hours, and nearly 25% suffering significant disruption or data loss.
The data shows that paying off these attackers isn’t working out, either, with 83% of victims who complied with ransom demands attacked again, and almost all (93%) having their data stolen regardless.
Backups are proving equally unreliable, according to CrowdStrike, with nearly 40% of firms unable to restore all their lost data despite thinking they are prepared.
In the immediate aftermath of an attack, more than half (51%) of organisations ramped up their general cybersecurity budgets, and 47% worked on quickly improving their detection and monitoring capabilities to cover blind spots, but while organisations are quick to make improvements to their security stack, the data shows these responses could benefit from a more strategic approach.
CrowdStrike found just 38% of ransomware victims addressed the specific issue that initially led to their attack, potentially explaining why so many face repeated incidents, while only 42% upgraded their incident response plans.
Recommended reading
- M&S Cyber-attack Stoking Fears Across British Businesses
- Retail Sector Cyber-attacks Peaked in Q2 2025
- Report: Half of Firms Hit by Months-Long Cyber-attack Disruption
“From malware development to social engineering, adversaries are weaponizing AI to accelerate every stage of attacks, collapsing the defender’s window of response,” said Elia Zaitsev, CrowdStrike CTO.
“Time is the currency of modern cyber defence – and in today’s AI-driven threat landscape, every second counts.”
CrowdStrike’s findings follow recent evidence gathered by Microsoft, which shows that 80% of cyber incidents over the last year have involved data theft and exfiltration, with more than half emanating from financially motivated threat actors.
These figures come as little surprise following a year of repeated, high-profile ransomware incidents, which in the UK alone have targeted the likes of M&S, Co-op, Harrods, and Jaguar-Land Rover, resulting in billions lost for the UK economy.





