By By David Ramel08/03/2026
Publication Date: 2026-08-03 00:00:00
CrowdStrike: Cloud Crime Surges as Attackers Turn Trust Against Defenders
Cyberattackers are increasingly turning the technologies and relationships enterprises trust most — including cloud identities, AI tools, software dependencies and legitimate authentication processes — into paths for intrusion, according to CrowdStrike’s latest threat-hunting research.
The CrowdStrike 2026 Threat Hunting Report, based on activity observed from July 1, 2025, through June 30, 2026, documents a 171% increase in cloud-conscious eCrime activity as financially motivated adversaries pursued credentials, cryptomining capacity, large language model access and digital financial assets.
The cloud finding is part of a broader shift running through the 59-page report. Rather than simply breaking through an external perimeter and moving laterally across endpoints, adversaries are increasingly entering through trusted accounts, tokens, applications and software components. Once authenticated, they can operate inside cloud and software-as-a-service (SaaS) environments using mechanisms that resemble legitimate business activity.
To demonstrate the difference in focus since last year, here is the company’s 2026 highlight infographic: