CrowdStrike

162 stats9 reports

All Statistics

China-nexus adversaries drove more than 58% of state-sponsored targeted intrusions against the technology sector.

State-Sponsored EspionageTechnology Sector

The Axios NPM package was downloaded 100 million times per week.

Open SourceSupply ChainSoftware Distribution

Malware operators compromised 350 GitHub repositories to inject malicious code into JavaScript and Python projects.

Supply ChainOpen SourceSoftware SecurityGitHub

Vishing intrusions increased by 2x in 1H 2026.

PhishingSocial EngineeringVishing

SNARKY SPIDER moved from account takeover to data theft in under five minutes in one incident.

Account TakeoverData Theft

China-nexus adversaries exploited critical vulnerabilities within 24 hours of public proof-of-concept release.

Vulnerability ExploitationState-Sponsored Threats

MURKY PANDA deployed an operational relay box network across more than 150 endpoints in 36 countries, targeting 340 organizations across more than 30 sectors.

Cyber EspionageNetwork Operations

423 financial services organizations appeared on dedicated leak sites, marking a 27% year-over-year increase.

Data LeaksFinancial ServicesData Leak Sites

PRESSURE CHOLLIMA conducted the largest financial theft ever reported: $1.46 billion in cryptocurrency via a trojanized supply chain compromise.

CryptocurrencySupply ChainFinancial Theft

DPRK-linked incidents rose by more than 130%.

CrowdStrike2026 Global Threat Report·5mo ago
Nation-State Activity

PRESSURE CHOLLIMA stole $1.46 billion in cryptocurrency, the largest single financial heist ever reported.

CrowdStrike2026 Global Threat Report·5mo ago
Cryptocurrency TheftFinancial CrimeNation-State ActivityPRESSURE CHOLLIMA

Average eCrime breakout time fell to 29 minutes in 2025.

CrowdStrike2026 Global Threat Report·5mo ago
eCrimeeCrime Breakout Time

260 initial access brokers advertised to over 1,400 European organizations in 2025

Initial access brokersEurope

Ransomware deployment speed increased by 48% as observed in 2025

RansomwareRansomware deploymentEurope

Since January 1, 2024, more than 2,100 victims across Europe were named on extortion leak sites

RansomwareExtortion leak sitesEurope

Over 40% of organizations reported using AI or automation to support threat detection and alerting in response to a ransomware incident

CrowdStrikeSTATE OF RANSOMWARE SURVEY·10mo ago
RansomwareAIRecovery

37% of financial services organizations suffered significant disruption to business operations due to ransomware attacks.

CrowdStrikeSTATE OF RANSOMWARE SURVEY·10mo ago
RansomwareResilience

87% of organizations expect deepfakes to become major attack vectors in future ransomware campaigns.

CrowdStrikeSTATE OF RANSOMWARE SURVEY·10mo ago
RansomwareDeepfake

eCrime activity represented 73% of total interactive intrusions.

Interactive intrusionseCrime

FAMOUS CHOLLIMA infiltrated over 320 companies in the last 12 months, representing a 220% year-over-year increase.

Nation-stateFamous Chollima

Nation-state activity in the telecom sector rose by 130%, driven by adversaries like GLACIAL PANDA.

Nation-stateTelecom

Among SMBs under 25 employees who experienced a cyber incident in the past year, 29% reported ransomware.

SMBSecurity incidentRansomware

50% of SMBs feel overwhelmed by the number of cybersecurity tools on the market.

SMBSecurity tools

Nearly 70% of SMBs rely on third-party guidance to inform buying decisions.

SMBSecurity tools

The average eCrime breakout time dropped to 48 minutes, with the fastest recorded at 51 seconds.

CrowdStrike2025 Global Threat Report·1y ago

China's cyber espionage attacks increased by 150%, with targeted attacks in financial services, media, manufacturing, and industrial sectors soaring up to 300%.

CrowdStrike2025 Global Threat Report·1y ago

Voice phishing (vishing) increased by 442% between H1 and H2 2024 due to AI-driven phishing and impersonation tactics.

CrowdStrike2025 Global Threat Report·1y ago

Initial access brokers advertised access to 277 technology organizations, a nearly 30% increase.

Initial Access BrokersTechnology Sector

MURKY PANDA's password-spraying campaign impacted more than 340 U.S.-based entities.

MURKY PANDACredential AttacksUS

FAMOUS CHOLLIMA accounted for 47% of all state-sponsored interactive intrusions against the technology sector.

State-Sponsored EspionageFAMOUS CHOLLIMATechnology Sector

Big game hunting adversaries named 572 technology entities on dedicated leak sites for extortion.

ExtortionRansomwareTechnology Sector

Financially motivated attacks accounted for 65% of all interactive operations against the technology sector.

ExtortionTechnology Sector

DPRK-nexus adversaries injected malicious packages into AI frameworks, poisoning 131 trusted AI framework packages.

Supply Chain SecurityAI FrameworksState-Sponsored Threats

One campaign sent nearly 200,000 AI model requests in two minutes.

AI Abuse

AI agent-triggered detection leads grew at 2.5x the rate of human-triggered leads.

Threat DetectionAISecurity Operations

In 1H 2026, 87% of identified software registry threats involved malicious npm packages.

Software Supply ChainMalicious Packagesnpm

eCrime actor ALTERED SPIDER compromised more than 300 software dependencies in a single day to harvest credentials and pivot into cloud environments.

Supply Chain SecurityCredential Theft

Monthly device code phishing attempts increased 15x in 1H 2026.

PhishingAuthentication

Cloud-conscious eCrime activity surged 171% as adversaries executed credential theft, cryptomining, LLM abuse, and digital financial asset theft.

Cloud SecurityeCrimeCryptominingLLM Abuse

In 1H 2026, 88% of observed exploitation of vulnerabilities with a public PoC occured within 48 hours of release.

Vulnerability ExploitationTime-to-Exploit

China-nexus actors VAULT PANDA and GENESIS PANDA launched deliberate attacks within 24 hours of disclosure.

State-Sponsored ThreatsVulnerability Exploitation

Hands-on-keyboard intrusions against financial institutions spiked 43% globally and 48% in North America over the past two years.

Financial ServicesHands-on-keyboard IntrusionsNorth America

DPRK-nexus actors stole a reported $2.02 billion in digital assets across the financial services sector in 2025.

Digital Asset TheftFinancial Services

SCATTERED SPIDER resumed aggressive ransomware operations against insurance entities in the first half of 2025 after a four-month pause.

RansomwareInsurance

FAMOUS CHOLLIMA doubled its operations using AI-generated identities to infiltrate cryptocurrency exchanges, fintech platforms, and consumer banks.

AI-Generated IdentitiesCryptocurrencyFinancial FraudDeepfakesFinancial Services

DPRK-nexus actors drove a 51% year-over-year increase in digital asset theft in 2025.

Digital Asset TheftNation-State Threats

STARDUST CHOLLIMA tripled its operational tempo and deployed AI-generated recruiter personas and synthetic video conferencing environments to target fintechs across North America, Europe, and Asia.

AI-Generated IdentitiesFintechDeepfakesGlobal Threats

The fastest observed eCrime breakout occured in 27 seconds.

CrowdStrike2026 Global Threat Report·5mo ago
eCrimeeCrime Breakout Time

42% of vulnerabilities were exploited before public disclosure.

CrowdStrike2026 Global Threat Report·5mo ago
Zero-DayVulnerabilities

Average eCrime breakout time of 29 minutes was 65% faster than in 2024.

CrowdStrike2026 Global Threat Report·5mo ago
eCrimeeCrime Breakout Time