Quick Facts
- Average eCrime breakout time fell to 29 minutes in 2025, down from 48 minutes in 2024, with the fastest recorded intrusion occurring in 27 seconds.
- AI-enabled adversary operations rose 89% year-over-year, with 82% of detections involving no traditional malware.
- In the first half of 2026, 88% of vulnerability exploits with a proof of concept launched within 48 hours of public disclosure.
Adversaries are moving faster than ever, and AI is the reason. CrowdStrike’s 2026 Threat Hunting Report, published August 3, draws on more than seven trillion security events processed daily between July 2025 and June 2026. The findings are stark: the attack window is nearly gone, and AI systems are now a primary target.
The average eCrime breakout time dropped to 29 minutes in 2025, a 65% speed increase from 2024’s 48 minutes. That number was 98 minutes in 2021. In one observed intrusion, data exfiltration began within four minutes of initial access. CrowdStrike recorded the fastest-ever breakout at 27 seconds.
AI Cuts Both Ways
AI-enabled attackers increased operations 89% year-over-year. They used generative AI tools across reconnaissance, credential theft, and evasion. ChatGPT was referenced in criminal forums 550% more than any other model.
AI is also a target, not just a tool. Adversaries injected malicious prompts into legitimate GenAI platforms at more than 90 organizations to steal credentials and cryptocurrency. They exploited vulnerabilities in AI development platforms to deploy ransomware and published fake AI servers impersonating trusted services to intercept sensitive data.
Adam Meyers, CrowdStrike’s head of counter adversary operations, framed it directly: “The same AI tools driving modern businesses are creating under-defended attack surfaces that adversaries are exploiting.”
The Exploit Window Is Closing
In the first half of 2026, 88% of exploits for vulnerabilities with a published proof of concept launched within 48 hours of disclosure. China-linked groups Vault Panda and Genesis Panda moved within 24 hours. Forty-two percent of vulnerabilities were exploited before any public disclosure at all.
CrowdStrike CEO George Kurtz warned that today’s average time to build a working exploit after a vulnerability announcement is roughly five days. With AI, he expects that window to fall to five minutes.
Nation-State Actors Target AI Directly
North Korea’s Famous Chollima, a unit linked to the Lazarus Group, demonstrated what CrowdStrike called the most advanced AI usage of any state-sponsored actor. The group built fake companies with AI-generated websites, GitHub accounts, and email infrastructure to place operatives inside technology firms. Famous Chollima accounted for 47% of all state-sponsored interactive intrusions against the technology sector.
A separate North Korea-linked group, PRESSURE CHOLLIMA, executed the largest cryptocurrency theft in history, stealing $1.46 billion by compromising a developer workstation and pivoting into a wallet platform’s cloud environment.
On March 31, 2026, STARDUST CHOLLIMA compromised the Axios npm package, an HTTP client library downloaded 100 million times per week, by stealing maintainer credentials and deploying malicious code. Separately, a financially motivated crew called Altered Spider compromised more than 300 software dependencies in a single day, harvesting credentials before moving into cloud environments.
Cloud Attacks Surge
Cloud-conscious intrusions rose 37% overall. State-nexus actors drove a 266% increase in cloud environment targeting, focused on intelligence collection. Meyers tied the trend to competition over AI capabilities: “China runs cyberespionage as industrial policy to try to close the AI innovation gap, demonstrating that AI capabilities are the prize adversaries are after.”
For technology executives, the report signals that AI infrastructure is now as attractive a target as financial data or credentials. Security teams operating on traditional patch and response cycles are outpaced before they start.
Read more: CrowdStrike finds AI systems under direct attack as exploit windows shrink
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
