Report by CrowdStrike
2026 Global Threat Report
Key Findings
DPRK-linked incidents rose by more than 130%.
PRESSURE CHOLLIMA stole $1.46 billion in cryptocurrency, the largest single financial heist ever reported.
Average eCrime breakout time fell to 29 minutes in 2025.
The fastest observed eCrime breakout occured in 27 seconds.
42% of vulnerabilities were exploited before public disclosure.
Average eCrime breakout time of 29 minutes was 65% faster than in 2024.
In one intrusion, data exfiltration began within four minutes of initial access.
State-nexus threat actors increased targeting of cloud environments for intelligence collection by 266%.
FAMOUS CHOLLIMA activity more than doubled.
AI-enabled adversaries increased their operations by 89% year-over-year.
Targeting of the logistics vertical by China-nexus actors increased by 85%.
China-nexus activity increased by 38% in 2025.
67% of exploited vulnerabilities used by China-nexus actors delivered immediate system access.
Adversaries exploited legitimate Generative AI tools at more than 90 organizations by injecting malicious prompts.
40% of exploited vulnerabilities by China-nexus actors targeted internet-facing edge devices.
Cloud-conscious intrusions rose by 37% overall.