CrowdStrike Reports Surge in AI-Enabled Cyberattacks

CrowdStrike reported that AI-enabled adversary activity rose 89% in 2025, while its threat-hunting team tracked AI agent-triggered leads at 2.5 times the rate of human-triggered threats. The Register reports that attackers are using AI across the attack chain and targeting AI infrastructure through credential theft, API abuse, and software supply-chain compromise.
CrowdStrike reported an 89% increase in AI-enabled adversary activity in 2025, describing AI as both a tool for attackers and an increasingly valuable attack surface. The Register's coverage of CrowdStrike's threat-hunting findings identifies credential theft for frontier-model APIs, inflated-usage attacks known as cost harvesting, and software supply-chain compromise among the observed threats.
CrowdStrike counter adversary division senior vice president Adam Meyers told reporters, "AI is both the weapon and the target." According to The Register, the company documented one token-theft campaign that issued about 200,000 API requests in two minutes, an example of attackers using stolen access to generate costs for an affected organization.
AI infrastructure joins the attack surface
The Register reported that CrowdStrike's threat-hunting team is tracking AI agent-triggered leads at 2.5 times the rate of human-triggered threats. It also reported that CrowdStrike tracks more than 290 adversary groups and identified the North Korea-linked group it calls Famous Chollima as showing the most advanced AI use during the second half of 2025 and first half of 2026.
According to the report as described by The Register, the group created fake companies using AI-generated websites, GitHub accounts, and email infrastructure to support insider-threat operations. The publication also reported that AI supply-chain compromise ranked as the second most common technique attackers used for initial access, citing a campaign against AI-focused development environments.
The reported activity puts corporate credentials, frontier-model APIs, AI infrastructure, and software packages in focus around AI workloads.
Faster intrusions reduce response time
Separate February coverage by SC Media, also based on CrowdStrike's 2026 Global Threat Report, reported that the average breakout time from initial access to lateral movement had fallen to 29 minutes, with the fastest observed breakout occurring in 27 seconds. SC Media reported a 42% year-over-year increase in zero-day attacks from 2024 to 2025 and said that 35% of cloud incidents involved valid-account abuse.
For ML platform and security engineering teams, the reported activity reinforces the importance of treating API credentials, service accounts, agent tool permissions, and package dependencies as production security assets. Organizations facing similar attack patterns typically benefit from short-lived credentials, anomalous token-usage alerts, least-privilege agent access, dependency verification, and tested incident-response paths for compromised AI accounts.
Key Points
- 1CrowdStrike recorded an 89% rise in AI-enabled activity, showing that AI tools and infrastructure are both part of the attack surface.
- 2Credential theft and cost harvesting expose API billing and access controls as security boundaries for teams operating frontier-model workloads.
- 3As reported breakout times fall below 30 minutes, the shorter response window makes attacks more difficult to detect.
Scoring Rationale
The report provides material threat-intelligence indicators for teams deploying AI agents, APIs, and cloud-based model services. Its relevance is broad because it connects AI-specific abuse with established identity, cost-control, and software supply-chain risks.
Sources
Public references used for this report.
Practice with real Telecom & ISP data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Telecom & ISP problems
