Cybersecurity company CrowdStrike said North Korean-linked cybercriminals stole $2.02 billion in digital assets in 2025, as artificial intelligence (AI) made attacks against banks, fintech firms, and cryptocurrency platforms faster and harder to detect.
In its 2026 Financial Services Threat Landscape Report, CrowdStrike said hands-on-keyboard intrusions against financial institutions grew 43% globally and 48% in North America over the past two years. Attackers increasingly abused trusted user accounts and software-as-a-service (SaaS) applications to bypass traditional security tools.
“Financial services organizations face threats from every direction and AI is making each of them harder to stop. The cost to create convincing identities, automate reconnaissance, and accelerate credential theft is near zero,” said Adam Meyers, head of counter adversary operations at CrowdStrike.
The report identified DPRK-linked groups as the main driver behind the surge in crypto theft. CrowdStrike said PRESSURE CHOLLIMA carried out what it described as the largest reported financial theft to date, stealing $1.46 billion in cryptocurrency through compromised software distributed in a supply chain attack.
Another group, GOLDEN CHOLLIMA, used fake recruitment offers to trick employees and gain access to cloud systems at fintech companies in Southeast Asia (SEA) and Canada.
CrowdStrike also said North Korean adversaries are using AI to scale operations. FAMOUS CHOLLIMA reportedly doubled its activity using AI-generated identities to infiltrate cryptocurrency exchanges, fintech platforms, and consumer banks.
STARDUST CHOLLIMA increased its operations threefold by using AI-generated recruiter profiles and fake video conferencing environments to target fintech firms across North America, Europe, and Asia.
China-linked cyber espionage groups also expanded operations globally, according to the report. CrowdStrike said HOLLOW PANDA targeted financial institutions in the Philippines, Indonesia, and Brazil, highlighting SEA’s growing exposure to cyber threats.
Another China-linked group, MURKY PANDA, reportedly operated relay box networks across more than 150 endpoints in 36 countries, targeting 340 organizations across over 30 sectors, including financial services.
The report also pointed to growing ransomware and cyber extortion pressure on the sector. CrowdStrike said 423 financial services organizations appeared on dedicated leak sites in 2025, up 27% year over year.
“Adversaries are using AI to compress the time from initial access to impact, moving through trusted paths faster than legacy defenses can respond. To close that gap, defenders have to meet AI with AI, pairing intelligence with hunting to outpace the adversary,” Meyers said.
For Philippine banks and fintech firms, the findings add pressure to strengthen cloud security, employee verification processes, and AI-driven threat detection as cybercriminals increasingly target digital financial services across the region.

