In its newly-released 2026 Global Threat Report, CrowdStrike has revealed a dramatic acceleration in AI-driven cyber-attacks, with adversaries exploiting both AI tools and traditional enterprise systems at unprecedented speed.
According to CrowdStrike, the average eCrime breakout time fell to just 29 minutes in 2025, while the fastest observed breakout occurred in only 27 seconds.
The report highlights that AI is not only powering attacks but is itself a target. Malicious actors have injected harmful prompts into genAI tools at more than 90 organisations and are abusing AI development platforms to establish persistence, deploy ransomware, and intercept sensitive data.
Major hacking groups leveraging AI at a frightening pace
According to the report, AI-enabled adversaries increased their operations by 89% year-on-year, leveraging AI across reconnaissance, credential theft, and evasion. Intrusions are increasingly moving through trusted identities, cloud infrastructure, and SaaS applications, blending into normal activity and leaving defenders with a narrow window to respond.
The report details significant activity from both state and eCrime actors. Russia-linked FANCY BEAR deployed LLM-enabled malware for automated reconnaissance, while eCrime group PUNK SPIDER used AI-generated scripts to accelerate credential dumping and erase forensic evidence.
Beyond this, DPRK-linked FAMOUS CHOLLIMA scaled insider operations using AI-generated personas, contributing to a 130% rise in North Korea-nexus incidents. PRESSURE CHOLLIMA’s $1.46 billion cryptocurrency theft was the largest single financial heist ever reported.
Recommended reading
- Terabit-Scale DDoS Attacks Now a Daily Reality, Warns Nokia
- The Largest DDoS Attack in History Has Been Recorded
- DDoS Attacks Dominate as Hacktivists Target Public Sector
China-nexus activity grew 38% in 2025, with logistics the most heavily targeted vertical, while 67% of exploited vulnerabilities delivered immediate system access. Exploitation of zero-day vulnerabilities also remains high, according to the report, with 42% of attacks occurring before public disclosure, and cloud-targeted intrusions rose by 37% overall, surging 266% among state-linked actors.
“This is an AI arms race,” said Adam Meyers, head of counter adversary operations at CrowdStrike.
“Breakout time is the clearest signal of how intrusion has changed. Adversaries are moving from initial access to lateral movement in minutes. AI is compressing the time between intent and execution while turning enterprise AI systems into targets. Security teams must operate faster than the adversary to win.”





