---
title: "The 2026 Global Threat Report: what eight numbers can support | TauX"
description: "Eight headline figures from the CrowdStrike 2026 Global Threat Report, how each was measured, and what that means for how far it generalises."
url: "https://taux.io/en-US/threat-landscape"
locale: "en-US"
alternates:
  ja-JP: "https://taux.io/ja-JP/threat-landscape"
  ko-KR: "https://taux.io/ko-KR/threat-landscape"
  zh-Hans-CN: "https://taux.io/zh-Hans-CN/threat-landscape"
  zh-Hant-TW: "https://taux.io/zh-Hant-TW/threat-landscape"
---

# Threat Landscape 2026

Eight headline numbers from the CrowdStrike 2026 Global Threat Report, and how each was measured — which is what decides how far it generalises. 

Contents

*   [Read it right first](https://taux.io/en-US/threat-landscape#how-to-read)
*   [The eight numbers](https://taux.io/en-US/threat-landscape#numbers)
*   [Speed](https://taux.io/en-US/threat-landscape#speed)
*   [Malware-free](https://taux.io/en-US/threat-landscape#malware-free)
*   [AI-assisted attacks](https://taux.io/en-US/threat-landscape#ai)
*   [Nation-state actors](https://taux.io/en-US/threat-landscape#nation-state)
*   [What it means for defenders](https://taux.io/en-US/threat-landscape#what-it-means)
*   [Source and limits](https://taux.io/en-US/threat-landscape#source)

00

## Read it right, then look at the numbers

The numbers are worth reading and they are not a census. **A vendor threat report is built from that vendor's own product telemetry and incident response caseload**, so the population is its customer base — organisations running EDR, which mostly means organisations with the budget to. 

That is not an accusation. It is that every figure carries three conditions: **the environment it was measured in, the tool that measured it, and what that tool can see**. Ignore those and you read "what EDR-equipped environments look like" as "what the world looks like". 

A usable rule

Use these reports as **intelligence on technique and trend** — that part is solid, because it comes from cases actually worked. **Do not** use the percentages as the statistical basis for your own risk. That needs data from your environment. 

01

## The eight numbers

All figures are from the public pages of the CrowdStrike 2026 Global Threat Report, covering observations from 2025. 

| Figure     | What it is                                                                                                                      |
| ---------- | ------------------------------------------------------------------------------------------------------------------------------- |
| 27 seconds | [Fastest eCrime breakout time](https://taux.io/en-US/threat-landscape#speed) — the fastest recorded, not an average             |
| +65%       | [Year-on-year increase in average breakout speed](https://taux.io/en-US/threat-landscape#speed)                                 |
| 82%        | [of 2025 detections were malware-free](https://taux.io/en-US/threat-landscape#malware-free)                                     |
| +89%       | [Increase in attacks by AI-assisted adversaries](https://taux.io/en-US/threat-landscape#ai)                                     |
| 90+        | [organisations had legitimate AI tools abused](https://taux.io/en-US/threat-landscape#ai) to generate malicious instructions    |
| +550%      | [more mentions of ChatGPT on criminal forums](https://taux.io/en-US/threat-landscape#ai) than any other model                   |
| 40%        | [of vulnerabilities exploited by China-nexus actors targeted edge devices](https://taux.io/en-US/threat-landscape#nation-state) |
| +266%      | [Increase in cloud-directed intrusions by nation-state actors](https://taux.io/en-US/threat-landscape#nation-state)             |

02

## Speed: 27 seconds and +65%

What it measures

**Breakout time** is how long an attacker takes to move laterally from the first host they compromise to a second one. It measures the defender's **time budget**: detection, triage and containment all have to happen inside it. The fastest recorded was 27 seconds, with average speed up 65% year on year. 

How to read it

**27 seconds is the fastest, not the average.** Reading it as an average badly misstates your position — most intrusions are nothing like that quick. But it has an honest use: it bounds **the worst case**, and any response process that waits for a human to look first does not fit inside it. 

"+65%" is far more useful than "27 seconds", because it compares the same measurement method across two years — **the same ruler used twice, so the ruler's own bias cancels**. Year-on-year change is the most trustworthy category of figure in any vendor report. 

03

## Malware-free: 82%

What it measures

82% of 2025 detections were malware-free: no malicious file written to disk. The attacker used built-in tooling, legitimate software and stolen credentials instead.

How to read it

This is **the figure to be most careful with**, because it reflects two things at once: 

1.  01Attacker behaviour genuinely is changing — there is plenty of independent evidence for that.
2.  02**Detection capability itself.** Seeing fileless activity is precisely what EDR is sold on. A product that sees files and not behaviour would report a malware-free rate of zero — not because those attacks are absent, but because it cannot see them.

So the proportion reliably describes **what you see in an EDR-equipped environment**, and does not extrapolate to the global composition of attacks. 

The practical conclusion holds anyway

Whether the true share is 82% or something else, the direction is clear: **signature-based antivirus does not cover most of what gets detected**. That conclusion does not need the percentage to be exact. 

04

## AI-assisted attacks: +89%, 90+, +550%

What it measures

Attacks by AI-assisted adversaries up 89%. More than 90 organisations had **legitimate AI tools** abused to generate malicious instructions. ChatGPT mentioned on criminal forums 550% more than any other model. 

How to read it

What counts as "AI-assisted" is **the vendor's own definition**, and it is not comparable across reports. Treat "+89%" as a trend signal within this report, not a number to line up beside somebody else's. 

"+550%" counts **forum mentions** — a proxy for how much something is talked about, not how often it is used in an attack. ChatGPT leading that count largely reflects that it is the most widely used. 

**"90+ organisations had legitimate AI tools abused" is the sturdiest of the three** — it counts events rather than proportions, and needs no definitional judgement to establish. It also points at what another page here is about: the problem is not the model, it is **who can feed it what, and what it is authorised to do**. 

Related For defending LLM applications you deploy yourself, see [OWASP LLM Top 10](https://taux.io/en-US/owasp-llm-top-10) — particularly prompt injection and excessive agency. 

05

## Nation-state actors: 40% and +266%

What it measures

40% of vulnerabilities exploited by China-nexus actors targeted **edge devices**. **Cloud-directed intrusions** by nation-state actors rose 266%. Named adversaries include OPERATOR PANDA (China), FAMOUS CHOLLIMA (North Korea) and PUNK SPIDER (eCrime).

How to read it

Attribution to a particular country rests on **the vendor's own intelligence methodology**, which is not fully published. That is normal in this field rather than a flaw — but it does mean the classification cannot be independently checked from outside. 

For most organisations, **"40% targeted edge devices" matters far more than the attribution does**. Edge devices — VPN gateways, firewalls, routers, NAS — usually sit outside endpoint protection, patch slowly, and once compromised are already inside the perimeter. That is actionable without knowing who did it, and it can be acted on immediately. 

06

## What it means for defenders

Discount every caveat above and the direction still holds, because none of it depends on a percentage being exact: 

1.  01**Response speed is a design problem, not a staffing one.** A process that waits for someone to look first cannot keep pace with lateral movement measured in seconds.
2.  02**Identity and credentials are where this is fought.** The less an attacker writes to disk, the more they rely on a login that looks legitimate.
3.  03**Edge devices belong in the inventory.** They are frequently on no asset list at all, which is exactly why they get picked.
4.  04**The AI tools you adopted are a new attack surface.** Those ninety-odd organisations with legitimate AI tools abused were using software they had bought themselves.

None of the four needs the figures to be accurate. **If a report's value depends on its percentages being precise, it is probably not something to make decisions from.** 

Source and limits

## Where these numbers come from

All figures are taken from the public pages of the [CrowdStrike 2026 Global Threat Report](https://www.crowdstrike.com/en-us/global-threat-report/), **checked on 2026-08-06**. The report covers observations from 2025 and is copyright CrowdStrike. 

This page **summarises publicly released findings and adds commentary**. It reproduces nothing, and neither the data nor the research is ours. For the full methodology, charts and adversary profiles, read the original. 

The reading, the terminology and the recommendations are TauX's and **do not represent CrowdStrike's position**. Noting the limits of a data source is not questioning its integrity — it is what you do with any telemetry, including our own. 

## Want to know what this means for your environment?

The report describes a global picture. What you need is your own asset list and exposure — which starts with an inventory. 

[Book a consultation](mailto:hello@taux.io) [See data governance](https://taux.io/en-US/data-governance)
