CrowdStrike’s latest 2026 Technology Threat Landscape Report shows a clear shift in cyberattacks: artificial intelligence (AI) has become one of the most targeted assets in the world, with hackers going after it to steal technology, money, and access.

The cybersecurity company said China-linked hacking groups are aggressively targeting tech companies to steal AI systems and software they cannot build quickly on their own. At the same time, North Korea-linked actors are using fake remote IT jobs to get inside companies and secretly earn money for the regime. Criminal hackers are also using AI tools to make their attacks faster and harder to stop.

“Technology organizations are building the most valuable and most targeted assets in the world. Every AI breakthrough creates a competitive advantage and new attack surface at the same time,” said Adam Meyers, head of counter adversary operations at CrowdStrike. “China runs cyberespionage as industrial policy to try to close the AI innovation gap, demonstrating that AI capabilities are the prize adversaries are after. Whether you’re building AI or adopting it, security has to be built in from the start.”

CrowdStrike said tech companies are now the most attacked industry globally, with China-linked groups responsible for more than 58% of government-backed hacking attempts against the sector.

The report identified several China-linked hacking groups, including MURKY PANDA, MUSTANG PANDA, OVERCAST PANDA, SUNRISE PANDA, and WARP PANDA. One campaign by MURKY PANDA used password guessing attacks and hit more than 340 US organizations.

North Korea-linked group FAMOUS CHOLLIMA was also found using fake identities and AI-generated profiles to land remote IT jobs inside tech companies. These schemes made up 47% of government-linked intrusions in the sector and are believed to help fund weapons programs.

On the criminal side, 65% of attacks were financially motivated. Hackers were seen selling access to 277 tech companies, up nearly 30%, while extortion groups publicly listed 572 companies on leak sites to pressure victims into paying.

CrowdStrike also warned that hackers are now using AI to speed up attacks, including writing scripts that steal passwords and erase traces of their activity. Some malware is being spread through fake AI tools and fake browser extensions pretending to be legitimate software.

Developer tools are also being targeted. One case involved a compromised software package called Axios on NPM, downloaded about 100 million times per week, which could have exposed millions of users. Hackers also injected malicious code into 350 GitHub projects used by developers worldwide.

In the Philippines, where many companies rely on remote developers and open-source software, the report indicates escalating risk as AI adoption increases and more systems connect to global platforms.

Discover more from Back End News

Subscribe now to keep reading and get access to the full archive.

Continue reading