A new report from CrowdStrike claims that we have entered the “age of the AI adversary”, highlighting new types of attack that companies must be wary of.
In its 2026 Global Threat Report, the security firm claims “AI-enabled adversaries” increased attacks by 89% year-on-year, with AI helping with all manner of nefarious tasks, such as creating fake companies, phishing attacks and writing malware. AI systems themselves are also coming under attack within targeted firms.
AI assistance is helping attackers break into victims’ systems at record speed. The average eCrime breakout time was down to 29 minutes in 2025, according to CrowdStrike, an increase in speed of 65% on 2024.
AI increasing credibility
Language barriers have always been a problem for foreign adversaries who don’t speak the same language(s) as employees in the companies they’re targeting. We’re all familiar with receiving badly spelt, grammatically wonky phishing emails that clearly mark them out as fakes.
However, the increased use of AI for social engineering is making such attacks far more credible and harder to detect. CrowdStrike cites the example of the Chinese intelligence services using AI to “create credible consulting firms to target former US government employees on job recruitment platforms,” for example.
Threat actors are also using AI to get jobs within companies. The North Korea-linked Famous Chollima group used AI to double its activity in 2025, CrowdStrike reports. Famous Chollima “conducts operations to illicitly obtain freelance or full-time equivalent work to earn a salary that can be funneled to North Korea,” CrowdStrike claims on its website.
The group reportedly used multiple AI tools, including ChatGPT and Gemini, to create fake personas, manage multiple messaging accounts and to create agents that were capable of performing legitimate job functions. The attacked companies didn’t know they were hiring AI bots.
AI systems under attack
AI tools aren’t only used by threat actors to launch attacks: they’re coming under attack themselves.
CrowdStrike cites an incident that took place in August last year, when a threat actor managed to bypass security mechanisms and used a JavaScript-based attack to target victims’ own local AI command line interface tools, such as Claude and Gemini. They used commands to steal authentication details and crypto assets. CrowdStrike said it saw more than 90 customers targeted by this attack alone.
Prompt-injection threats are also on the increase. The report highlights one case where adversaries hid prompt content within a phishing email, so that when employees used AI tools to triage their email, the malicious message would have an increased chance of evading detection.
The good news is that “these techniques have not yet demonstrated consistent effectiveness at scale,” according to CrowdStrike, but they do “illustrate how attackers may seek to manipulate AI systems indirectly by targeting their inputs rather than exploiting the systems themselves”.
Related articles