
Report: Cloud Criminal Offense growing as Attackers Exploit Trust
Cyber opponents are significantly turning the technologies and relationships organizations trust most– including cloud identities, AI tools, software application dependencies and genuine authentication processes– into paths for intrusion, according to CrowdStrike’s newest threat-hunting research study.
The CrowdStrike 2026 Threat Searching Report, based upon activity observed from July 1, 2025, through June 30, 2026, documents a 171% boost in cloud-conscious eCrime activity as economically inspired enemies pursued qualifications, cryptomining capability, large language model gain access to, and digital monetary assets.
The cloud finding belongs to a wider shift going through the 59-page report. Rather than simply breaking through an external perimeter and moving laterally throughout endpoints, foes are significantly entering through trusted accounts, tokens, applications and software components. When validated, they can run inside cloud and software-as-a-service (SaaS) environments using systems that look like legitimate business activity.
To show the difference in focus given that last year, here is the company’s 2026 highlight infographic:
2026 Report Highlights(source:
CrowdStrike ). Here is the company’s 2025 highlight infographic: [Click image for bigger view.] 2025 Report Emphasizes (source: CrowdStrike).
AI Becomes Tool, Target and Attack Surface Area
Expert system appears throughout the report in numerous distinct functions. Adversaries used generative AI to produce commands, payloads, reconnaissance scripts, and credential-harvesting tools. Other assaulters targeted AI facilities itself to steal access, consume computing resources, or acquire delicate configuration details.
CrowdStrike OverWatch found that AI agent-triggered detection leads were appearing at 2.5 times the rate of human-triggered leads. The finding does not compare the precision or efficiency of AI agents with human hunters. Instead, CrowdStrike presents it as evidence that AI-generated activity is increasing the volume and speed of signals that protectors should examine.
One financially determined opponent used a compromised cloud identity and long-term access key to target a cloud service offering access to structure designs. After checking account approvals and creating short-term credentials, the assailant flooded the service with almost 200,000 application programming interface requests in two minutes.
CrowdStrike identifies such activity as “LLMJacking,” in which a foe gets unapproved access to a company’s large language design resources. The resulting harm can consist of service charges, tired quotas, and operational disruption even if the attacker does not take standard enterprise data.