CrowdStrike Says AI-Agent Leads Outpace Human Threats 2.5-to-1

CrowdStrike's threat-hunting team now tracks AI-agent-triggered leads at 2.5 times the rate of human-triggered threats, The Register reported on August 3. The update also described stolen model-API credentials, cost-harvesting attacks and AI supply-chain compromise; CrowdStrike's separate February report supplies the broader 89% annual-growth context.
CrowdStrike's threat-hunting team now tracks AI-agent-triggered leads at 2.5 times the rate of human-triggered threats, according to August 3 reporting by The Register. Adam Meyers, the company's head of counter-adversary operations, said the higher volume spans both government-backed and financially motivated groups.
The same reporting described attacks on AI infrastructure as well as AI-assisted attacks. In one token-theft campaign documented by CrowdStrike, an attacker sent about 200,000 API requests in two minutes. The Register also identified cost harvesting, in which stolen model-API access is used to inflate a victim's bill, and credential theft aimed at frontier-model services.
These figures come from The Register's current reporting of CrowdStrike's threat-hunting observations. They should not be confused with a new edition of CrowdStrike's annual report.
How the current update extends February's report
CrowdStrike's 2026 Global Threat Report, published February 24, said AI-enabled adversary activity rose 89% year over year in 2025. It also reported a 29-minute average eCrime breakout time and a fastest observed breakout of 27 seconds. SC Media independently covered those report findings on February 25.
The August account adds more recent operational detail. CrowdStrike now tracks more than 290 adversary groups, and The Register reported that the North Korea-linked group CrowdStrike calls Famous Chollima showed the most advanced AI use across the second half of 2025 and first half of 2026. Its reported tactics included AI-generated company websites, GitHub accounts and email infrastructure used in fake-worker operations.
The Register also reported that AI supply-chain compromise was the second-most-common MITRE ATLAS technique used for initial access in the activity CrowdStrike described. That claim is attributed to CrowdStrike through The Register; no separate exact-event first-party publication was retrieved for the August update.
What defenders can take from it
For ML platform and security teams, the current evidence connects familiar controls to AI-specific assets: model-API keys, service accounts, agent permissions and development dependencies. A stolen API credential can create both unauthorized access and direct financial exposure, while compromised development tooling can turn trusted AI workflows into an initial-access path.
The practical response is to monitor unusual token volume and cost spikes, shorten credential lifetimes, restrict agent and service-account privileges, and verify packages and development environments. Those are LDS interpretations grounded in the reported attack patterns, not a claim that one control can prevent every incident.
Key Points
- 1CrowdStrike's threat-hunting team tracks AI-agent-triggered leads at 2.5 times the rate of human-triggered threats, according to August 3 reporting by The Register.
- 2One documented token-theft campaign generated about 200,000 API requests in two minutes, linking credential compromise to both access and billing risk.
- 3The 89% increase in AI-enabled activity and 29-minute breakout time come from CrowdStrike's separate February 2026 report, not a new August report.
Scoring Rationale
The current threat-hunting update gives concrete operational indicators for teams securing model APIs, agents and AI development environments. The impact remains below the highest tier because the new 2.5-to-1 and token-abuse observations are company findings reported by one publication, while the broader 89% figure comes from the separate February report.
Sources
Public references used for this report.
Practice with real Telecom & ISP data
90 SQL & Python problems · 15 industry datasets
250 free problems · No credit card
See all Telecom & ISP problems
