CrowdStrike Global Threat Report 2026 vs 2025: What Changed?
The 2026 edition shifts from generative AI as an emerging force multiplier to AI as an operational accelerator across phishing, reconnaissance, malware development, and attacks on AI systems themselves.

This article compares the CrowdStrike — Global Threat Report — 2026 with the CrowdStrike — Global Threat Report — 2025. The anchor is the 2026 edition, which places stronger emphasis on AI-accelerated adversary operations, faster eCrime breakout times, interactive intrusions, cloud and edge environments, China-nexus activity, zero-day exploitation, supply chain attacks, and identity-based access.
The 2025 edition focused on enterprising adversaries, generative AI, social engineering, China-nexus cyber operations, cloud exploitation, vulnerability exploitation, insider threats, election disinformation, remote monitoring and management (RMM) tools, and the continued shift toward malware-free activity.
Together, the two editions show how CrowdStrike's view of the threat landscape moved from adversaries adopting generative AI and human-centric access methods in 2024 to adversaries using AI, identity, cloud, edge devices, and supply chain compromise in more operationally integrated ways during 2025.
This comparison is useful for CISOs, SOC leaders, threat intelligence teams, risk leaders, incident response teams, and security architects who want to understand what changed between the two editions and which parts of the 2026 report deserve priority attention.
Short answer
The CrowdStrike — Global Threat Report — 2026 shifts the focus from generative AI as an emerging force multiplier to AI as a broader operational accelerator across phishing, reconnaissance, malware development, post-exploitation, and attacks on AI systems themselves.
Compared with the 2025 edition, the 2026 report gives more attention to cross-domain intrusions, cloud and SaaS trust abuse, edge device exploitation, supply chain compromise, and rapid adversary movement.
Both editions emphasize China-nexus activity, identity compromise, social engineering, vulnerability exploitation, and cloud security. The main change is that the 2026 edition presents these issues as more connected across domains and more dependent on speed, visibility gaps, and trusted access.
What this report series covers
The CrowdStrike Global Threat Report series analyzes observed adversary behavior, intrusion patterns, threat actor activity, attack techniques, and defensive priorities.
The 2025 edition describes a threat environment shaped by enterprising adversaries, generative AI adoption, vishing, access brokers, cloud exploitation, vulnerability exploitation, malware-free attacks, and China-nexus operational growth. It highlights the rise of human-centric tradecraft, including voice phishing, help desk social engineering, RMM tool use, and insider threat operations linked to FAMOUS CHOLLIMA.
The 2026 edition continues several of those themes but frames them around faster, more adaptive, and more cross-domain adversary operations. It highlights AI-accelerated cyber operations, interactive intrusions, cloud-conscious intrusions, China-nexus targeting of edge devices, zero-day exploitation, supply chain attacks, and valid account abuse in cloud incidents.
The series is especially useful for readers who want to understand how adversaries operate, rather than only which vulnerabilities or malware families appeared during the year.
What changed across editions?
1. The treatment of AI
In the 2025 edition, CrowdStrike describes generative AI as a growing but still largely iterative and evolutionary tool. The report links GenAI to social engineering, fake IT worker schemes, disinformation campaigns, phishing content, malicious scripts, decoy websites, and possible exploit development. The tone is cautious: malicious AI use is growing, but confirmed novel use cases appear limited.
In the 2026 edition, AI becomes a central operational theme. The report describes adversaries using AI to accelerate phishing, automate reconnaissance, shorten the time from initial access to impact, support malware development, generate scripts for post-exploitation, and target AI systems directly. It also discusses prompt injection, malicious AI tooling, abuse of AI development platforms, and the risk of compromised autonomous AI agents.
2. Speed
The 2025 edition reports an average breakout time of 48 minutes, with the fastest observed breakout at 51 seconds. The 2026 edition says average eCrime breakout time dropped further to 29 minutes in 2025, with the fastest breakout reported as 27 seconds.
CrowdStrike's emphasis moves from rapid breakout as a major warning sign to rapid breakout as an operational baseline defenders must assume.
3. Cross-domain intrusions
The 2025 edition already describes malware-free activity, identity compromise, cloud exploitation, SaaS access, RMM tool use, and social engineering. The 2026 edition connects these more explicitly across traditional servers, hypervisors, cloud environments, unmanaged hosts, SaaS applications, edge devices, and identity systems. This makes the 2026 edition more useful for readers studying how adversaries move between security domains.
4. China-nexus activity
The 2025 edition highlights a +150% increase in China-nexus activity across sectors compared with 2023, including major increases in financial services, media, manufacturing, and industrials and engineering. It also emphasizes operational security, ORB networks, and more specialized China-nexus operations.
The 2026 edition reports a +38% increase in China-nexus targeted intrusion activity in 2025 compared with 2024, with noted increases in logistics, telecommunications, and financial services. It places particular emphasis on network perimeter and edge device targeting, rapid weaponization of newly disclosed vulnerabilities, long-term access, and intelligence collection objectives.
5. Supply chain
The 2025 edition includes supply chain risk in the context of RMM tools, third-party software, SaaS access, and cloud applications. The 2026 edition expands this into a more prominent theme, including upstream provider compromise, npm repository attacks, malicious packages, compromised update mechanisms, SaaS OAuth token abuse, and the Safe{Wallet} compromise affecting Bybit.
Themes that became more prominent
AI Security & AI Governance
AI becomes more prominent in the 2026 edition. The 2025 report treats GenAI mainly as an emerging tool for social engineering, information operations, coding assistance, and adversary productivity. The 2026 report expands this into AI-enabled adversary operations, direct targeting of AI systems, prompt injection, malicious AI tooling, AI-generated malware support, and risks from autonomous AI agents.
Cloud Security
Cloud security is important in both editions, but the 2026 edition gives it greater operational depth. The 2025 report discusses valid account abuse, SaaS exploitation, cloud account compromise, trusted relationships, and cloud defense evasion. The 2026 report adds a reported +37% rise in cloud-conscious intrusions and a +266% increase among state-nexus threat actors, while also emphasizing SaaS, Entra ID, hybrid identity, cloud trust abuse, and cloud-based data exfiltration.
Identity, Phishing & Access Security
Identity remains central, but the 2026 edition presents it as even more connected to cloud, SaaS, ransomware, and cross-domain intrusion. The 2025 report emphasizes vishing, help desk social engineering, MFA manipulation, access brokers, valid accounts, and SSO compromise. The 2026 report continues those patterns and highlights valid account abuse in 35% of cloud incidents, hybrid identity targeting, AiTM phishing, trusted OAuth flows, non-human identities, and cloud identity abuse.
Software & Supply Chain Security
Supply chain risk becomes more prominent in the 2026 report. The provided material describes upstream provider compromise, public code repository attacks, npm package compromise, malicious packages, SaaS token theft, compromised update processes, and software provider targeting. This is broader than the 2025 edition's supply chain references, which appear more tied to RMM tools, SaaS access, cloud applications, and third-party software dependencies.
Vulnerability & Exposure Management
Vulnerability exploitation is a consistent theme, but the 2026 edition gives more attention to zero-day exploitation before disclosure, edge device exploitation, rapid operationalization of newly disclosed vulnerabilities, and long-term persistence through perimeter infrastructure. The 2025 report already highlights network periphery targeting, exploit chaining, known vulnerability reuse, and the importance of patching public-facing services.
Threat Actors, Geopolitics & Intelligence
Both editions give significant attention to nation-state and state-nexus activity. The 2026 edition appears to deepen the focus on China-nexus operations, edge device targeting, ORB infrastructure, telecommunications, logistics, financial services, and long-term intelligence collection. It also discusses Russia-nexus and DPRK-nexus activity in AI, malware, cloud, and supply chain contexts.
Themes that remained consistent
Faster adversary movement
Both editions emphasize that adversaries are moving quickly. Average breakout time compressed from 48 → 29 minutes, and the fastest observed breakout from 51 → 27 seconds. The consistent message: defenders need detection and response processes that can operate quickly enough to interrupt early-stage intrusion activity.
Human-centric access
Social engineering, phishing, vishing, help desk abuse, and identity compromise remain central across both editions. The 2025 edition highlights a +442% increase in vishing attacks between the first and second half of 2024. The 2026 edition continues to discuss phishing, vishing, trust abuse, AiTM phishing, and identity-centered intrusion paths.
Malware-free and interactive activity
The 2025 edition reports that malware-free activity accounted for 79% of detections in 2024 and describes a +35% year-over-year increase in interactive intrusion campaigns. The 2026 edition says interactive intrusions rose +37% in 2025, with a +266% increase among state-nexus adversaries. Both editions suggest that security teams should not rely only on malware detection when assessing adversary activity.
China-nexus operations
China-nexus activity is a major theme in both editions. The 2025 edition emphasizes broad growth, maturing operations, ORB network use, and sector targeting. The 2026 edition continues the theme with a lower but still significant reported increase, while shifting attention toward edge devices, zero-day and recently disclosed vulnerabilities, long-term persistence, telecommunications, logistics, and intelligence collection.
Cloud and SaaS exposure
Both reports treat cloud and SaaS environments as important targets. The 2025 edition focuses on valid account abuse, SaaS data access, cloud control plane activity, trusted relationships, and MFA bypass. The 2026 edition continues those topics and adds stronger emphasis on cloud-conscious intrusions, hybrid identity, Entra ID, OAuth token abuse, and SaaS integrations.
Vulnerability exploitation at the edge
Both editions discuss adversary interest in perimeter and network edge devices. The 2025 edition highlights network appliances, exploit chaining, public vulnerability research, and known vulnerabilities. The 2026 edition expands the theme with China-nexus targeting of VPNs, firewalls, gateways, mail servers, routers, and other internet-facing systems.
What this means for security teams
Security teams should read the 2026 edition as a signal that separate security domains are increasingly difficult to defend in isolation.
The report suggests that adversaries are combining identity compromise, cloud access, SaaS abuse, unmanaged infrastructure, social engineering, vulnerability exploitation, and supply chain compromise. That matters because each part of the attack may appear in a different tool, team queue, or operational workflow.
- SOC and detection teams: correlate endpoint, identity, cloud, SaaS, network, and threat intelligence data. Cross-domain intrusions mean isolated alerts may not show the full attack path quickly enough.
- Identity and cloud teams: valid accounts, SSO compromise, MFA manipulation, hybrid identity abuse, and trusted relationships remain important intrusion paths. The 35% valid account abuse in cloud incidents figure reinforces identity as a cloud security priority.
- Vulnerability and exposure management teams: internet-facing systems and edge devices deserve special attention. China-nexus operationalization of newly disclosed vulnerabilities and zero-day exploitation points to the need for faster prioritization around perimeter infrastructure.
- Risk leaders and CISOs: the change between editions is not only about new tools or new adversaries — it is about operational compression: less time between access and impact, more ways to move between domains, and more reliance on trusted systems and accounts.
Which edition should you read?
Read the CrowdStrike — Global Threat Report — 2026 first if you want the most current view. It is the better anchor for understanding AI-accelerated adversary activity, cross-domain intrusions, cloud-conscious threats, China-nexus edge targeting, zero-day exploitation, supply chain compromise, and defensive priorities for 2026.
Read the CrowdStrike — Global Threat Report — 2025 if you want context on how these themes developed. It is especially useful for understanding the earlier framing of generative AI misuse, the rise of vishing, help desk social engineering, malware-free activity, RMM tool abuse, insider threat operations, and the 2024 surge in China-nexus activity.
Read both editions together if you are building a year-over-year threat briefing. The 2025 edition explains the emergence and acceleration of several patterns, while the 2026 edition shows how those patterns became more integrated across AI, identity, cloud, SaaS, edge infrastructure, and supply chain activity.
Related reading
- CrowdStrike 2026 Global Threat Report — the anchor edition for this comparison.
- CrowdStrike 2025 Global Threat Report — the prior-year baseline.
Reports mentioned in this article

CrowdStrike — CrowdStrike 2026 Global Threat Report
The 2026 Global Threat Report highlights the rise of AI-accelerated adversaries, the increasing speed of eCrime breakout times, and the dominance of interactive intrusions. It emphasizes the need for rapid detection and response to counter evasive tactics, particularly in cloud and edge environments. The report also details the growing threat from China-nexus adversaries and the strategic use of AI in cyber operations.

CrowdStrike — CrowdStrike 2025 Global Threat Report
The 2025 Global Threat Report highlights the growing sophistication of cyber adversaries, emphasizing the rise of enterprising adversaries leveraging generative AI, social engineering, and advanced tactics. It underscores the need for proactive defense strategies and AI-native approaches to counter evolving threats.
