Cloud Intrusions and AI Threats Soar by 136%, Says CrowdStrike Report

CrowdStrike’s 2025 Threat Hunting Report highlights a dramatic escalation in cyber threats, painting a vivid picture of the evolving danger landscape. From January to June 2025, the company observed a 136% spike in cloud intrusions compared to the entire year of 2024. This surge underscores how adeptly cyber adversaries are now breaching workload environments, services, and control-plane assets in both public and hybrid clouds.

Moreover, interactive intrusions involving direct keyboard interaction are becoming more frequent and sophisticated. These increased by 27% year-over-year, with 73% tied to financially-driven e-crime actors. This rise reflects the booming business of ransomware-as-a-service ecosystems and access-broker marketplaces.

Voice phishing, or vishing, emerges as one of the fastest-growing cybercrime tactics. Notably, these attacks soared by 442% from the first to the second half of 2024 and have already exceeded last year’s total in just the first half of 2025. Groups like SCATTERED SPIDER are quickly moving from initial account takeovers to ransomware deployment, operating 32% faster than in 2024.

National-level espionage remains a prime concern. China-nexus operators have fueled a 130% increase in espionage activities targeting the telecommunications sector, while Russia-linked adversaries are responsible for a 185% increase in government-sector intrusions. CrowdStrike notes that sophisticated actors such as BLOCKADE SPIDER and OPERATOR PANDA excel at remaining undercover by swiftly maneuvering across identity, endpoint, and cloud domains until late in their attacks.

Generative AI now plays a crucial role in several campaigns. The report highlights DPRK-aligned FAMOUS CHOLLIMA, which infiltrated over 320 companies during this period, marking a 220% increase from the previous year. These actors use large-language-model services to create fake résumés, deepfake identities, and even real-time interview responses. Once hired, they utilize AI coding assistants and translation tools to manage multiple remote developer roles while exfiltrating intellectual property.

To combat these threats, CrowdStrike advises enhanced identity verification during recruitment, real-time deepfake checks in interviews, and tighter monitoring of remote-access activities. Continuous threat hunting across identity, endpoint, and cloud environments is crucial. Although defenders are increasingly employing their own machine-learning tools, it’s vital to train AI models using curated, trusted data to prevent manipulation and poisoning attempts.