Report by CrowdStrike

CrowdStrike 2026 Technology Threat Landscape Report

8 FINDINGS
View Original Report →

Key Findings

China-nexus adversaries drove more than 58% of state-sponsored targeted intrusions against the technology sector.

State-Sponsored EspionageTechnology Sector

The Axios NPM package was downloaded 100 million times per week.

Open SourceSupply ChainSoftware Distribution

Malware operators compromised 350 GitHub repositories to inject malicious code into JavaScript and Python projects.

Supply ChainOpen SourceSoftware SecurityGitHub

Initial access brokers advertised access to 277 technology organizations, a nearly 30% increase.

Initial Access BrokersTechnology Sector

MURKY PANDA's password-spraying campaign impacted more than 340 U.S.-based entities.

MURKY PANDACredential AttacksUS

FAMOUS CHOLLIMA accounted for 47% of all state-sponsored interactive intrusions against the technology sector.

State-Sponsored EspionageFAMOUS CHOLLIMATechnology Sector

Big game hunting adversaries named 572 technology entities on dedicated leak sites for extortion.

ExtortionRansomwareTechnology Sector

Financially motivated attacks accounted for 65% of all interactive operations against the technology sector.

ExtortionTechnology Sector