CrowdStrike
Reports
All Statistics
In 1H 2026, 88% of observed exploitation of vulnerabilities with a public PoC occured within 48 hours of release.
China-nexus actors VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of disclosure.
Vishing intrusions increased by 2x in 1H 2026.
The Axios NPM package was downloaded 100 million times per week.
Malware operators compromised 350 GitHub repositories to inject malicious code into JavaScript and Python projects.
China-nexus adversaries drove more than 58% of state-sponsored targeted intrusions against the technology sector.
FAMOUS CHOLLIMA doubled its operations using AI-generated identities to infiltrate cryptocurrency exchanges, fintech platforms, and consumer banks.
MURKY PANDA deployed an operational relay box network across more than 150 endpoints in 36 countries, targeting 340 organizations across more than 30 sectors.
423 financial services organizations appeared on dedicated leak sites, marking a 27% year-over-year increase.
40% of exploited vulnerabilities by China-nexus actors targeted internet-facing edge devices.
DPRK-linked incidents rose by more than 130%.
PRESSURE CHOLLIMA stole $1.46 billion in cryptocurrency, the largest single financial heist ever reported.
Chinese state-sponsored adversaries targeted industries in 11 countries in 2025
92% of ransomware cases in Europe involved file encryption and data theft in 2025
260 initial access brokers advertised to over 1,400 European organizations in 2025
87% of organizations expect deepfakes to become major attack vectors in future ransomware campaigns.
45% of organizations that paid ransoms could not recover all of their data even after paying.
34% of victim organizations experienced reputational damage that undermined customer and partner trust.
CrowdStrike OverWatch observed a 40% year-over-year increase in intrusions by suspected cloud-conscious China-nexus actors.
SCATTERED SPIDER moved from initial access to encryption by deploying ransomware in under 24 hours in one observed case
eCrime activity represented 73% of total interactive intrusions.
Among SMBs under 25 employees who experienced a cyber incident in the past year, 29% reported ransomware.
50% of SMBs feel overwhelmed by the number of cybersecurity tools on the market.
Nearly 70% of SMBs rely on third-party guidance to inform buying decisions.
79% of attacks to gain initial access are now malware-free.
Access broker advertisements surged 50% YoY.
Valid account abuse is the primary initial access tactic, accounting for 35% of cloud incidents in H1 2024.
SNARKY SPIDER moved from account takeover to data theft in under five minutes in one incident.
China-nexus adversaries exploited critical vulnerabilities within 24 hours of public proof-of-concept release.
DPRK-nexus adversaries injected malicious packages into AI frameworks, poisoning 131 trusted AI framework packages.
One campaign sent nearly 200,000 AI model requests in two minutes.
AI agent-triggered detection leads grew at 2.5x the rate of human-triggered leads.
In 1H 2026, 87% of identified software registry threats involved malicious npm packages.
eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.
Monthly device code phishing attempts increased 15x in 1H 2026.
Cloud-conscious eCrime activity surged 171% as adversaries executed credential theft, cryptomining, LLM abuse, and digital financial asset theft.
Initial access brokers advertised access to 277 technology organizations, a nearly 30% increase.
MURKY PANDA's password-spraying campaign impacted more than 340 U.S.-based entities.
FAMOUS CHOLLIMA accounted for 47% of all state-sponsored interactive intrusions against the technology sector.
Big game hunting adversaries named 572 technology entities on dedicated leak sites for extortion.
Financially motivated attacks accounted for 65% of all interactive operations against the technology sector.
PRESSURE CHOLLIMA conducted the largest financial theft ever reported: $1.46 billion in cryptocurrency via a trojanized supply chain compromise.
Hands-on-keyboard intrusions against financial institutions spiked 43% globally and 48% in North America over the past two years.
DPRK-nexus actors stole a reported $2.02 billion in digital assets across the financial services sector in 2025.
SCATTERED SPIDER resumed aggressive ransomware operations against insurance entities in the first half of 2025 after a four-month pause.
DPRK-nexus actors drove a 51% year-over-year increase in digital asset theft in 2025.
STARDUST CHOLLIMA tripled its operational tempo and deployed AI-generated recruiter personas and synthetic video conferencing environments to target fintechs across North America, Europe, and Asia.
Average eCrime breakout time fell to 29 minutes in 2025.
The fastest observed eCrime breakout occured in 27 seconds.
42% of vulnerabilities were exploited before public disclosure.