Report by CrowdStrike

2026 Global Threat Report

16 FINDINGSPublished Feb 24, 2026
View Original Report →

Key Findings

DPRK-linked incidents rose by more than 130%.

CrowdStrike2026 Global Threat Report·5mo ago
Nation-State Activity

PRESSURE CHOLLIMA stole $1.46 billion in cryptocurrency, the largest single financial heist ever reported.

CrowdStrike2026 Global Threat Report·5mo ago
Cryptocurrency TheftFinancial CrimeNation-State ActivityPRESSURE CHOLLIMA

Average eCrime breakout time fell to 29 minutes in 2025.

CrowdStrike2026 Global Threat Report·5mo ago
eCrimeeCrime Breakout Time

The fastest observed eCrime breakout occured in 27 seconds.

CrowdStrike2026 Global Threat Report·5mo ago
eCrimeeCrime Breakout Time

42% of vulnerabilities were exploited before public disclosure.

CrowdStrike2026 Global Threat Report·5mo ago
Zero-DayVulnerabilities

Average eCrime breakout time of 29 minutes was 65% faster than in 2024.

CrowdStrike2026 Global Threat Report·5mo ago
eCrimeeCrime Breakout Time

In one intrusion, data exfiltration began within four minutes of initial access.

CrowdStrike2026 Global Threat Report·5mo ago
Data ExfiltrationInitial Access

State-nexus threat actors increased targeting of cloud environments for intelligence collection by 266%.

CrowdStrike2026 Global Threat Report·5mo ago
Nation-State ActivityCloud SecurityIntelligence Collection

FAMOUS CHOLLIMA activity more than doubled.

CrowdStrike2026 Global Threat Report·5mo ago
Nation-State ActivityFAMOUS CHOLLIMA

AI-enabled adversaries increased their operations by 89% year-over-year.

CrowdStrike2026 Global Threat Report·5mo ago
Threat ActorsAI-Enabled AdversariesAI

Targeting of the logistics vertical by China-nexus actors increased by 85%.

CrowdStrike2026 Global Threat Report·5mo ago
LogisticsNation-State ActivityChina

China-nexus activity increased by 38% in 2025.

CrowdStrike2026 Global Threat Report·5mo ago
Nation-State ActivityChina

67% of exploited vulnerabilities used by China-nexus actors delivered immediate system access.

CrowdStrike2026 Global Threat Report·5mo ago
VulnerabilitiesNation-State ActivityChina

Adversaries exploited legitimate Generative AI tools at more than 90 organizations by injecting malicious prompts.

CrowdStrike2026 Global Threat Report·5mo ago
GenAIMalicious Prompt InjectionLLM Risk

40% of exploited vulnerabilities by China-nexus actors targeted internet-facing edge devices.

CrowdStrike2026 Global Threat Report·5mo ago
Edge DevicesVulnerabilitiesChina

Cloud-conscious intrusions rose by 37% overall.

CrowdStrike2026 Global Threat Report·5mo ago
Cloud Security