Spirit Managed Services is now branded Infotrust.
Cyber Emergency Number:
IT Support Number:
Blog

Key Findings – CrowdStrike Threat Hunting Report 2026

Goran Lepan
September 30, 2026
Home

Let's Get STARTED

CrowdStrike’s latest Threat Hunting Report provides a frontline view of how adversaries are operating and where defenders are being put under the most pressure.

Last year, CrowdStrike described 2025 as the year of the evasive adversary. Attackers were increasingly relying on targeting supply chain partners, upstream developer ecosystems, legitimate software, and employees to gain initial access to avoid detection, while gaps between security controls gave them more room to move unnoticed. That pattern has carried into 2026, with adversaries refining their methods by understanding the gaps between fragmented security controls, often lack of full visibility, targeting identity and credentials, SaaS application, edge devices and unmanaged systems. Adversary are moving quicker now by using AI to accelerate their attacks from early stages of compromise like phishing, reconnaissance, attack execution like initial access, execution, lateral movement, all the way to attack objective of impact and exfiltration. CrowdStrike’s wider 2026 Global Threat Report points to the same shift, with adversaries becoming more evasive and more effective at blending into legitimate activity.

The result is that keeping pace is becoming harder. Traditional detection is less effective when malicious activity is designed to look legitimate or passes between disconnected controls.  In this way, threat hunting increasingly depends on understanding how attackers behave across an environment, rather than waiting for a single alert to provide the full picture.

Drawing on frontline observations from CrowdStrike OverWatch, the 2026 report shows how adversaries are evolving their tradecraft to exploit trust and target gaps in visibility. In many cases, they are moving fast enough to leave defenders very little time to respond. The findings offer a useful view of how threat activity is developing and what organisations need to understand as they adapt their defences.

AI as a Tool, Target and Force Multiplier for Adversaries

AI is changing both the pace of adversary activity and the shape of the attack surface. CrowdStrike reports that AI-enabled adversary activity increased by 89% in 2025, while AI agent-triggered detection leads are now being tracked at 2.5 times the rate of human-triggered leads. This is creating a more complex environment for defenders, particularly where automated activity can blend into legitimate use.

Attackers are not only using AI to support their operations. AI systems themselves are becoming targets. CrowdStrike observed threat actors abusing access to large language models and targeting AI-centric development environments. Vulnerabilities in AI-related server software have also created new routes for compromise. In some cases, infrastructure introduced to improve productivity is also widening the attack surface.

The sector data gives some indication of where this activity is concentrating. Technology remained the most targeted sector for the ninth consecutive year, with intrusion activity increasing by 5%. Financial services recorded an 11% rise, while the academic sector saw the largest year-on-year increase at 17%. CrowdStrike links this interest to the value of the systems and data held within these environments.

The report’s LLMJacking case study shows how quickly compromised AI access can be abused. In May 2026, a financially motivated threat actor used a compromised cloud identity to gain access to large language models. During an initial two-minute burst, the actor sent nearly 200,000 API requests before throttling took effect. CrowdStrike tracked the activity as the actor attempted to work across several models, showing how quickly stolen access could be put to use.

What this demonstrates is that AI services need to sit within the wider security picture rather than being treated as standalone tools. Access should be tightly controlled, while unusual model usage needs to be visible early enough for security teams to investigate before activity escalates.

Frontline Observations and Emerging Trends

CrowdStrike’s frontline observations show how adversaries are finding new ways to exploit trust and move through areas where defenders have less visibility. Several trends stand out in the report:

  • Software supply chain attacks: Developer ecosystems are becoming a more valuable route into downstream organisations. CrowdStrike observed adversaries targeting public package registries and CI/CD pipelines, with stolen developer credentials often providing the initial foothold. These attacks are also becoming more automated, which increases the potential impact of a single compromise across trusted software dependencies.
  • Vishing and phishing operations: Voice phishing has become a far more prominent initial access technique. CrowdStrike recorded a 134% increase in vishing intrusions between 2024 and 2025, while the first half of 2026 saw twice as many vishing-related intrusions as the second half of 2025. These attacks can be difficult to spot because they may avoid the endpoint activity defenders traditionally look for. In one CORDIAL SPIDER case, CrowdStrike OverWatch detected malicious activity within four minutes of a successful vishing attempt, giving the customer time to respond before the intrusion progressed further.
  • Business travel and deliberate victim selection: The report also points to a different kind of risk. OVERCAST PANDA targeted individuals travelling in China and gained physical access to unattended laptops, using bootable media to deploy its FlowCloud backdoor. CrowdStrike says the targeting was deliberate and linked to Chinese state intelligence priorities. For businesses sending staff to higher-risk regions, the practical issue is simple: devices need to stay physically secure, not just digitally protected.

These examples show why threat hunting can no longer stop at the traditional perimeter. CrowdStrike’s recommendations place greater emphasis on understanding activity across the wider environment, particularly where legitimate access can conceal malicious behaviour.

How to Stay Ahead of Evasive Adversaries

One of the clearest findings is that adversaries no longer operate within neat technical boundaries. A single intrusion can move between identity systems, cloud services and trusted access without presenting defenders with one obvious point of failure.

That changes what effective threat hunting looks like. Security teams need enough visibility to recognise unusual behaviour early and follow it across the environment. Controls should also be reviewed against the way adversaries are operating now, rather than assuming that existing detection processes will continue to catch the same signals.

Proactive, intelligence-led hunting is central to that approach. It gives organisations a better chance of identifying activity that sits between traditional controls and understanding where visibility is weakest before an attacker has time to progress.

You can read the full CrowdStrike 2026 Threat Hunting Report for more detail. Meanwhile, if you would like support assessing what these findings mean for your environment, contact Infotrust to book a consultation with our cyber security experts.

‍