THREAT BRIEFING · 09.09.2026 DEENFRES

Strategy & Governance

Cyberattacks with and without AI are becoming more aggressive

By Tobias Massow · March 3, 2025 · 6 min read

The 2025 Global Threat Report by US security firm CrowdStrike highlights a massive increase in cyberattacks and espionage activities from China and North Korea. These attacks are reportedly becoming more aggressive due to AI support.

TL;DR

The new, over 50-page-long Cyber Threat Report 2025 by IT security specialist CrowdStrike reads like a crime thriller. It discusses partly state-directed espionage and sabotage, with many attacks originating from China and Iran and increasingly involving AI.

A central finding: The breakout time – the period between successful intrusion by attackers and jumping to other systems – has decreased to 48 minutes, with an extreme case in 2024 taking only 51 seconds. In 2023, it took an average of 62 minutes, and the year before that, it was 84 minutes.

Negative Highlights

For the new report, CrowdStrike tracked more than 250 actors and 140 activity clusters. Apart from the previously mentioned point, here are the most important negative highlights identified by the IT security company for its Global Threat Report 2025:

Prevention is better than cure

The figures mentioned in the new Global Threat Report 2025 and highlighted in the foreword underscore the importance of vigilance in preempting cyberattacks. To enhance this, companies and government agencies should train their employees accordingly while also implementing advanced technical solutions to detect incidents promptly and reliably. As attackers increasingly use AI, it is also crucial for companies to upgrade and invest in this area.

 

Key Facts at a Glance

Breakout Time 2024: 48 minutes (Minimum: 51 seconds)

Chinese Espionage: +150%, critical industries +200-300%

Vishing Increase: +442% (H1→H2 2024)

Initial Access Brokers: 52% of all vulnerabilities, +50% growth

Malware-Free Attacks: 79% (Previous Year: 40%)

Cloud Incidents: 35% due to misused account data

Source: CrowdStrike Global Threat Report 2025

Fact: The CrowdStrike Global Threat Report 2025 records an average breakout time of just 62 minutes – the fastest ever measured.

Fact: According to Mandiant, 37 percent of all analyzed attack campaigns in 2024 already used AI-supported phishing components.

Frequently Asked Questions

Every question is locked. A tap unlocks the answer.

What is breakout time in cyberattacks?

Breakout time refers to the time between intrusion and spread within the network. In 2024, it was 48 minutes, with an extreme case taking only 51 seconds.

Why are malware-free attacks increasing?

79 percent of all cyber incidents in 2024 occurred without malware. Attackers use valid access data and hands-on-keyboard techniques to remain undetected.

What are Initial Access Brokers?

IABs sell acquired access data as a service. In 2024, they were responsible for 52 percent of observed vulnerabilities, with Access-as-a-Service growing by 50 percent.

What role does AI play in cyberattacks?

AI is used for refined voice phishing, social engineering, and election interference. Vishing increased by 442 percent with AI support.

What should companies do?

Employee training, AI-supported detection, identity threat detection, 2FA, and automated incident response are the most important countermeasures.

Further Reading

Phishing simulations in practice: Phishing Simulations (Security Today)

Cloud security and identity management: cloudmagazin.com

C-level strategies against cyber espionage: digital-chiefs.de

Related Articles

More from the MBF Media Network

cloudmagazincloudmagazinMyBusinessFutureMyBusinessFutureDigital ChiefsDigital Chiefs

Further reading

Strategy & Governance · July 17, 2026

NIS2 Patchwork: Four States Face EU Court

The EU Commission sues Ireland, Spain, France, and the Netherlands over incomplete NIS2 implementation. What this means for CISOs.

A magazine by Evernine Media GmbH