CrowdStrike

162 stats9 reports

All Statistics

In 1H 2026, 88% of observed exploitation of vulnerabilities with a public PoC occured within 48 hours of release.

Vulnerability ExploitationTime-to-Exploit

China-nexus actors VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of disclosure.

State-Sponsored ThreatsVulnerability Exploitation

Vishing intrusions increased by 2x in 1H 2026.

PhishingSocial EngineeringVishing

The Axios NPM package was downloaded 100 million times per week.

Open SourceSupply ChainSoftware Distribution

Malware operators compromised 350 GitHub repositories to inject malicious code into JavaScript and Python projects.

Supply ChainOpen SourceSoftware SecurityGitHub

China-nexus adversaries drove more than 58% of state-sponsored targeted intrusions against the technology sector.

State-Sponsored EspionageTechnology Sector

FAMOUS CHOLLIMA doubled its operations using AI-generated identities to infiltrate cryptocurrency exchanges, fintech platforms, and consumer banks.

AI-Generated IdentitiesCryptocurrencyFinancial FraudDeepfakesFinancial Services

MURKY PANDA deployed an operational relay box network across more than 150 endpoints in 36 countries, targeting 340 organizations across more than 30 sectors.

Cyber EspionageNetwork Operations

423 financial services organizations appeared on dedicated leak sites, marking a 27% year-over-year increase.

Data LeaksFinancial ServicesData Leak Sites

40% of exploited vulnerabilities by China-nexus actors targeted internet-facing edge devices.

CrowdStrike2026 Global Threat Report·6mo ago
Edge DevicesVulnerabilitiesChina

DPRK-linked incidents rose by more than 130%.

CrowdStrike2026 Global Threat Report·6mo ago
Nation-State Activity

PRESSURE CHOLLIMA stole $1.46 billion in cryptocurrency, the largest single financial heist ever reported.

CrowdStrike2026 Global Threat Report·6mo ago
Cryptocurrency TheftFinancial CrimeNation-State ActivityPRESSURE CHOLLIMA

Chinese state-sponsored adversaries targeted industries in 11 countries in 2025

State-Sponsored AttacksChinaEurope

92% of ransomware cases in Europe involved file encryption and data theft in 2025

RansomwareEuropeData theftFile encryption

260 initial access brokers advertised to over 1,400 European organizations in 2025

Initial access brokersEurope

87% of organizations expect deepfakes to become major attack vectors in future ransomware campaigns.

CrowdStrikeSTATE OF RANSOMWARE SURVEY·10mo ago
RansomwareDeepfake

45% of organizations that paid ransoms could not recover all of their data even after paying.

CrowdStrikeSTATE OF RANSOMWARE SURVEY·10mo ago
RansomwareRecovery

34% of victim organizations experienced reputational damage that undermined customer and partner trust.

CrowdStrikeSTATE OF RANSOMWARE SURVEY·10mo ago
RansomwareReputational damage

CrowdStrike OverWatch observed a 40% year-over-year increase in intrusions by suspected cloud-conscious China-nexus actors.

Cloud

SCATTERED SPIDER moved from initial access to encryption by deploying ransomware in under 24 hours in one observed case

RansomwareInitial accessEncryptionScattered Spider

eCrime activity represented 73% of total interactive intrusions.

Interactive intrusionseCrime

Among SMBs under 25 employees who experienced a cyber incident in the past year, 29% reported ransomware.

SMBSecurity incidentRansomware

50% of SMBs feel overwhelmed by the number of cybersecurity tools on the market.

SMBSecurity tools

Nearly 70% of SMBs rely on third-party guidance to inform buying decisions.

SMBSecurity tools

79% of attacks to gain initial access are now malware-free.

CrowdStrike2025 Global Threat Report·1y ago

Access broker advertisements surged 50% YoY.

CrowdStrike2025 Global Threat Report·1y ago

Valid account abuse is the primary initial access tactic, accounting for 35% of cloud incidents in H1 2024.

CrowdStrike2025 Global Threat Report·1y ago

SNARKY SPIDER moved from account takeover to data theft in under five minutes in one incident.

Account TakeoverData Theft

China-nexus adversaries exploited critical vulnerabilities within 24 hours of public proof-of-concept release.

Vulnerability ExploitationState-Sponsored Threats

DPRK-nexus adversaries injected malicious packages into AI frameworks, poisoning 131 trusted AI framework packages.

Supply Chain SecurityAI FrameworksState-Sponsored Threats

One campaign sent nearly 200,000 AI model requests in two minutes.

AI Abuse

AI agent-triggered detection leads grew at 2.5x the rate of human-triggered leads.

Threat DetectionAISecurity Operations

In 1H 2026, 87% of identified software registry threats involved malicious npm packages.

Software Supply ChainMalicious Packagesnpm

eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.

Supply Chain SecurityCredential Theft

Monthly device code phishing attempts increased 15x in 1H 2026.

PhishingAuthentication

Cloud-conscious eCrime activity surged 171% as adversaries executed credential theft, cryptomining, LLM abuse, and digital financial asset theft.

Cloud SecurityeCrimeCryptominingLLM Abuse

Initial access brokers advertised access to 277 technology organizations, a nearly 30% increase.

Initial Access BrokersTechnology Sector

MURKY PANDA's password-spraying campaign impacted more than 340 U.S.-based entities.

MURKY PANDACredential AttacksUS

FAMOUS CHOLLIMA accounted for 47% of all state-sponsored interactive intrusions against the technology sector.

State-Sponsored EspionageFAMOUS CHOLLIMATechnology Sector

Big game hunting adversaries named 572 technology entities on dedicated leak sites for extortion.

ExtortionRansomwareTechnology Sector

Financially motivated attacks accounted for 65% of all interactive operations against the technology sector.

ExtortionTechnology Sector

PRESSURE CHOLLIMA conducted the largest financial theft ever reported: $1.46 billion in cryptocurrency via a trojanized supply chain compromise.

CryptocurrencySupply ChainFinancial Theft

Hands-on-keyboard intrusions against financial institutions spiked 43% globally and 48% in North America over the past two years.

Financial ServicesHands-on-keyboard IntrusionsNorth America

DPRK-nexus actors stole a reported $2.02 billion in digital assets across the financial services sector in 2025.

Digital Asset TheftFinancial Services

SCATTERED SPIDER resumed aggressive ransomware operations against insurance entities in the first half of 2025 after a four-month pause.

RansomwareInsurance

DPRK-nexus actors drove a 51% year-over-year increase in digital asset theft in 2025.

Digital Asset TheftNation-State Threats

STARDUST CHOLLIMA tripled its operational tempo and deployed AI-generated recruiter personas and synthetic video conferencing environments to target fintechs across North America, Europe, and Asia.

AI-Generated IdentitiesFintechDeepfakesGlobal Threats

Average eCrime breakout time fell to 29 minutes in 2025.

CrowdStrike2026 Global Threat Report·6mo ago
eCrimeeCrime Breakout Time

The fastest observed eCrime breakout occured in 27 seconds.

CrowdStrike2026 Global Threat Report·6mo ago
eCrimeeCrime Breakout Time

42% of vulnerabilities were exploited before public disclosure.

CrowdStrike2026 Global Threat Report·6mo ago
Zero-DayVulnerabilities