AI Cyberattack Statistics 2026
By Axis Intelligence Research and Marcus Chen | Last updated: June 18, 2026 | Next scheduled update: Q3 2026 (September) | License: CC BY 4.0
Quick Answer: AI-enabled adversaries attacked 89% more aggressively in 2025 than the year before, and the average time from initial access to lateral movement fell to 29 minutes — with one recorded breakout clocking 27 seconds. U.S. cybercrime losses hit $20.9 billion, the FBI reported $893 million in AI-specific fraud for the first time, and the Verizon DBIR documented something that hadn’t happened in 19 years: vulnerability exploitation surpassed stolen credentials as the leading breach entry point. AI isn’t just speeding up attacks — it’s restructuring how they’re built.
Key Findings
- 89% increase in attacks by AI-enabled adversaries in 2025 vs. 2024, with eCrime breakout time falling to 29 minutes on average — a 65% acceleration — and a fastest-ever recorded breakout of 27 seconds, per the CrowdStrike 2026 Global Threat Report.
- $20.9 billion in U.S. cybercrime losses reported to the FBI in 2025, a 26% increase year-over-year and the first time losses have exceeded $20 billion in IC3’s 25-year history — of which $893 million was directly tied to AI-enabled fraud complaints (22,364 cases), reported for the first time as a distinct category.
- Vulnerability exploitation has become the #1 breach entry point for the first time in 19 years of Verizon DBIR tracking, rising to 31% of all initial access vectors, up from 20% the prior year — with AI accelerating the time from CVE disclosure to active exploit from months to hours.
- The Mandiant M-Trends 2026 report, based on 500,000+ hours of incident response, found that initial access broker handoff time to ransomware affiliates collapsed from hours in 2022 to 22 seconds in 2025 — while global median dwell time rose to 14 days, driven by espionage and DPRK insider operations averaging 122 days undetected.
- 87% of organizations identified AI-related vulnerabilities as the fastest-growing cyber risk in 2025, while 67% of employees accessed AI services through non-corporate accounts on company devices — creating a shadow AI threat surface now triple the size it was a year ago, per the Verizon 2026 DBIR and WEF Global Cybersecurity Outlook 2026.
The Axis AI Attack Time-to-Impact Index (AATI™)
Axis Intelligence Research introduces the AATI™ — a composite index measuring how fast the offensive cyber timeline has compressed from 2020 to 2026, across four dimensions that security teams actually use to plan response.
Speed is the story. Every major threat intelligence report published in 2026 — CrowdStrike, Verizon, Mandiant, IBM — says the same thing with different numbers. AI hasn’t invented new attack categories; it has collapsed the time between each step. The AATI™ puts a single number on that compression.
| Dimension | 2020 Baseline | 2024 | 2025/2026 | Compression Factor |
|---|---|---|---|---|
| eCrime Breakout Time (initial access → lateral movement) | 98 min | 48 min | 29 min (avg) / 27 sec (fastest) | 3.4× faster |
| Time-to-Exploit (CVE disclosure → active wild exploit) | 63 days | 5 days | Hours (some < 36 hrs) | ~150× faster |
| IAB Handoff Time (access broker → ransomware affiliate) | 8+ hours | ~2 hours | 22 seconds | 1,309× faster |
| Median Patch Time (org remediation of critical CVEs) | 32 days | 32 days | 43 days | Getting slower |
AATI™ Score (2026): The index scores each dimension against its 2020 baseline on a 0–100 compression scale (100 = maximum compression). Averaged across four dimensions:
| Dimension | 2020 Score | 2024 Score | 2026 Score |
|---|---|---|---|
| Breakout Time Compression | 0 | 51 | 70 |
| Time-to-Exploit Compression | 0 | 92 | 99 |
| IAB Handoff Compression | 0 | 75 | 100 |
| Defender Response Speed (inverse — slower = worse) | 50 | 50 | 32 |
| AATI™ Composite | 12.5 | 67.0 | 75.3 |
What AATI™ 75.3 means: Attackers are operating at 75% of the theoretical maximum speed compression achievable in each measured dimension — while defender response (patch time) is actually moving in the wrong direction. The attack-defense asymmetry has never been wider.
Formula: AATI™ = [(Breakout compression % × 0.30) + (Time-to-exploit compression % × 0.30) + (IAB handoff compression % × 0.25) + (Inverse defender speed score × 0.15)] ÷ 100 × 100
Attribution: The AATI™ is an original Axis Intelligence Research metric. Primary inputs: CrowdStrike 2026 Global Threat Report (breakout time), Mandiant M-Trends 2026 (IAB handoff, dwell time), Mondoo/Mandiant M-Trends 2025 (time-to-exploit historical), Verizon 2026 DBIR (patch time). This composite does not appear in any prior publication. Cite as: “Axis Intelligence Research, AATI™ 2026, June 18, 2026, CC BY 4.0.”
The Speed Revolution: Breakout Time Has Collapsed
The number that changed security planning in 2026 is not a dollar figure. It is 29 minutes.
According to the CrowdStrike 2026 Global Threat Report, the average eCrime breakout time — the interval between an attacker’s initial system access and their first lateral movement to a second system — fell to 29 minutes in 2025. That represents a 65% acceleration from the 48-minute average recorded in 2024, and an 70% drop from the 98-minute average in 2021. The fastest single recorded breakout: 27 seconds. In one documented intrusion, data exfiltration began within four minutes of initial access.
To understand why this matters operationally: a security team that detects an alert at minute 20 and takes 15 minutes to escalate — a realistic timeline in most enterprise SOCs — has already lost. The attacker is on a second system before the Slack message reaches the on-call analyst.
The breakout time trend across reported years:
| Year | Avg. eCrime Breakout Time | YoY Change |
|---|---|---|
| 2021 | 98 minutes | Baseline |
| 2022 | 84 minutes | −14% |
| 2023 | 62 minutes | −26% |
| 2024 | 48 minutes | −23% |
| 2025 | 29 minutes | −40% |
| 2025 (fastest ever) | 27 seconds | Record |
Source: CrowdStrike 2026 Global Threat Report; CrowdStrike 2025 Global Threat Report (prior years).
The Mandiant M-Trends 2026 report, based on over 500,000 hours of incident response conducted across 2025, adds a complementary metric: the time between an Initial Access Broker (IAB) gaining entry and handing off that access to a secondary ransomware affiliate has collapsed from over 8 hours in 2022 to 22 seconds in 2025. This is not a single recorded outlier — it is a measured median across Mandiant’s caseload. Buying access and deploying ransomware is now, operationally, a one-tap transaction.
The Vulnerability Inversion: Exploitation Beats Credentials for the First Time in 19 Years
For 18 consecutive years, the answer to “how did attackers get in?” was the same: stolen credentials. That answer changed definitively in 2025.
The Verizon 2026 Data Breach Investigations Report, based on analysis of 31,000 real-world security incidents and 22,000 confirmed breaches across 145 countries — the largest DBIR dataset ever produced — found that vulnerability exploitation overtook credential abuse as the most common initial access vector for the first time in 19 years of publication.
| Initial Access Vector | 2024 Share | 2025 Share | YoY Change |
|---|---|---|---|
| Vulnerability Exploitation | 20% | 31% | +55% |
| Credential Abuse | 22% | 13% | −41% |
| Phishing | ~15% | 16% | +7% |
| Pretexting | ~5% | 6% | +20% |
Source: Verizon 2026 DBIR.
The IBM 2026 X-Force Threat Intelligence Index, released independently on February 25, 2026, corroborates this finding with its own dataset: vulnerability exploitation accounted for 40% of incidents observed by X-Force in 2025, with attacks beginning with exploitation of public-facing applications rising 44% year-over-year. Among the vulnerabilities X-Force tracked in 2025, 56% required no authentication whatsoever to exploit — meaning attackers could bypass both credentials and MFA entirely.
AI is driving this shift directly. As IBM Global Managing Partner Mark Hughes stated in the report release: “Attackers aren’t reinventing playbooks — they’re speeding them up with AI. The difference now is speed. With so many vulnerabilities requiring no credentials, attackers can bypass humans and move straight from scanning to impact.”
The Mandiant M-Trends 2026 data confirms that exploitation of internet-facing systems was the leading initial infection vector for the sixth consecutive year, accounting for 32% of intrusions where Mandiant could identify the entry point. The three most-exploited vulnerabilities in 2025 Mandiant investigations were all zero-days:
- CVE-2025-31324 — SAP NetWeaver Visual Composer (unauthenticated file upload)
- CVE-2025-61882 — Oracle E-Business Suite (unauthenticated remote code execution, attributed to suspected FIN11/CL0P cluster)
- CVE-2025-53770 — Microsoft SharePoint (ToolShell)
Critically, 28.3% of CVEs tracked by Mandiant’s M-Trends 2026 report were exploited before any public disclosure or patch existed — meaning defenders had zero warning window.
AI as Offensive Weapon: 89% More Attacks, Three Nation-State Vectors Documented
The CrowdStrike 2026 Global Threat Report tracks more than 280 named adversaries. Its 2025 data found that AI-enabled adversaries increased their operations by 89% year-over-year — with documented AI use spanning reconnaissance automation, credential dumping, social engineering, malware generation, and forensic evidence erasure.
Three nation-state threat actors documented using AI offensively in 2025:
FANCY BEAR (Russia-nexus): Deployed LAMEHUG — LLM-enabled malware that uses the Qwen2.5-Coder-32B-Instruct model via the Hugging Face API to generate real-time reconnaissance commands. Rather than using hardcoded scripts, LAMEHUG queries an LLM mid-execution to produce host-specific commands, making it harder to detect via signature-based tools.
PUNK SPIDER (eCrime): Used AI-generated scripts to accelerate credential dumping and — critically — erase forensic evidence post-compromise. AI was not used to attack; it was used to clean up.
FAMOUS CHOLLIMA (DPRK-nexus): Leveraged AI-generated personas to scale insider operations — creating convincing fake Western engineer identities to secure employment at technology companies, with a median dwell time of 122 days undetected per Mandiant M-Trends 2026.
Beyond using AI as a tool, adversaries are now directly attacking AI systems. CrowdStrike documented prompt injection attacks against legitimate GenAI tools at more than 90 organizations — injecting malicious commands into enterprise AI assistants to steal credentials and cryptocurrency. ChatGPT was mentioned in criminal forums 550% more than any other AI model.
The IBM X-Force 2026 report adds that infostealers harvested over 300,000 ChatGPT credentials in 2025, advertised for sale on dark web marketplaces. AI platforms have reached the same credential risk profile as core enterprise SaaS systems.
The Mandiant M-Trends 2026 report identified two new AI-specific malware families in 2025 investigations:
- PROMPTFLUX — queries LLMs mid-execution to evade behavioral detection
- PROMPTSTEAL — uses LLM queries to identify and extract configuration files
- QUIETVAULT (credential stealer) — checks compromised machines for local AI CLI tools, then executes predefined prompts to search for sensitive configuration data
FBI IC3 2025: $20.9 Billion, AI Fraud Debuts as a Category
The FBI’s 2025 Internet Crime Complaint Center Annual Report, released April 6, 2026, establishes the financial scale of AI-enabled cybercrime with primary-source government data for the first time.
Total 2025 cybercrime losses reported to the FBI: $20.877 billion — a 26% increase from $16.6 billion in 2024 and the first time annual losses have exceeded $20 billion in IC3’s 25-year history. The IC3 received 1,008,597 complaints — also the first time complaint volume has exceeded one million.
For the first time in its history, the FBI IC3 report includes a dedicated section on artificial intelligence:
| AI Cybercrime Metric | 2025 Figure |
|---|---|
| AI-related complaints received | 22,364 |
| Reported losses tied to AI-related complaints | $893 million |
| AI used in: deepfake fraud, voice cloning, synthetic identity documents | First documented at scale |
| BEC losses with confirmed AI component | $30+ million (subset) |
The broader cybercrime picture from FBI IC3 2025:
| Crime Category | 2025 Losses | Notes |
|---|---|---|
| Investment Fraud | $8.65 billion | Crypto pig-butchering dominant |
| Business Email Compromise (BEC) | $3.046 billion | AI accelerating impersonation quality |
| Tech Support Scams | $2.1 billion | Voice cloning increasingly used |
| Phishing / Spoofing | $215.8 million | +208% from $70M in 2024 |
| Ransomware (reported only) | $32 million | Excludes disruption costs |
| AI-specific complaints | $893 million | First-ever dedicated tracking |
| Total all cybercrime | $20.877 billion | +26% YoY; 5-year losses: $71B |
Source: FBI IC3 2025 Annual Report; FBI press release.
A critical caveat: the FBI estimates actual cybercrime losses may be 3–4× higher than reported figures, as many organizations do not file complaints to avoid regulatory or reputational exposure. The $20.9 billion figure may represent as little as 25% of true losses — implying a real 2025 cybercrime impact approaching $80 billion in the United States alone.
The Shadow AI Threat: Inside the Firewall
The AI threat surface has moved inside the firewall. The Verizon 2026 DBIR, in collaboration with Anthropic (analyzing data from 793 threat actors who received enforcement action for policy violations between March 2025 and February 2026), found:
- 67% of employees accessed AI services through non-corporate accounts on company devices
- 45% of employees are now regular AI users on corporate devices — up from just 15% the prior year (a 200% increase in 12 months)
- Shadow AI has become the third most common non-malicious insider DLP event, a 4× increase year-over-year
- More than 15% of corporate users have unauthorized AI browser extensions installed — extensions that silently collect browsing context, including sessions on internal systems
- In 3.2% of DLP policy violations, employees uploaded research and technical documentation to external AI tools
The content employees are uploading to unauthorized AI tools includes source code, technical documents, strategy materials, and internal data used for context — creating intellectual property exposure without any external attack required.
The IBM X-Force 2026 report frames it simply: AI tools entered the enterprise at consumer speed. Security governance moved at enterprise speed. The gap between them is where the exposure lives.
Ransomware in 2026: Fragmented, Faster, Recovery-Denial Focused
The ransomware ecosystem underwent structural fragmentation in 2025, according to converging primary-source data:
IBM X-Force 2026: Active ransomware and extortion groups surged 49% year-over-year, rising from 73 distinct groups in 2024 to 109 in 2025. The top 10 groups’ share of total activity fell 25%, meaning the ecosystem became significantly more distributed and harder to attribute. Leaked builder kits from LockBit and Babuk enabled new groups to stand up operations without dedicated development teams.
Verizon DBIR 2026: Ransomware was present in 48% of all breaches analyzed in 2025, up from 44%. A notable positive: 69% of ransomware victims did not pay. However, 96% of SMB ransomware victims (where organization size was known) were small and medium-sized businesses — confirming that ransomware has become primarily a tax on organizations with limited security resources.
Mandiant M-Trends 2026: Ransomware operators shifted their primary objective from data theft and extortion to recovery denial — targeting backup infrastructure, virtualization platforms, and disaster recovery systems to eliminate the victim’s ability to restore without paying. The most frequently observed ransomware family in 2025 Mandiant investigations was REDBIKE (Akira). 73% of ransomware victims had an associated infostealer infection or credential leak event in the year prior to the attack — confirming the infostealer-to-ransomware pipeline.
FBI IC3 2025: The FBI identified 63 new ransomware variants in 2025 — averaging 5.25 new variants per month. The top reported variants: Akira, Qilin, Ransomhub, Lockbit, and Medusa. Healthcare, manufacturing, and government facilities were the most impacted critical sectors.
Supply Chain & Third-Party: The 48% Problem
Nearly half of all breaches in 2025 started outside the victim organization’s own environment.
The Verizon 2026 DBIR found third-party involvement in breaches surged 60% year-over-year, reaching 48% of all confirmed breaches.
IBM X-Force 2026: Large supply chain and third-party compromises have nearly quadrupled since 2020, driven by attackers exploiting CI/CD automation, trusted developer identities, and SaaS integration trust relationships. X-Force observed rising attacks on GitHub, GitLab, npm, and cloud providers that underpin development operations.
Every vendor a company relies on is another entry point. IBM X-Force found that large supply chain and third-party compromises have nearly quadrupled since 2020, with attackers targeting CI/CD pipelines, developer identities, and SaaS integration trust relationships. X-Force tracked rising intrusions into GitHub, GitLab, npm, and cloud providers that sit underneath development workflows. AI-powered coding tools add pressure on top: they accelerate software creation while occasionally introducing unvetted code, expanding the number of potentially vulnerable packages in open-source ecosystems.
Mandiant M-Trends 2026 adds a detail that reframes the entire ransomware conversation: prior compromise was the most frequently confirmed initial infection vector for ransomware in 2025, at 30% of cases — double the prior year. Attackers are buying existing footholds, not breaking fresh ones. A patch deployed on the day of the ransomware event would have done nothing, because the breach happened weeks earlier through a third-party vendor.
Nation-State Activity: China +38%, DPRK +130%, Cloud +266%
The geopolitical dimension of AI cyberattacks intensified significantly in 2025, per CrowdStrike 2026 Global Threat Report data:
| Nation-State Activity | 2025 Change |
|---|---|
| China-nexus intrusion activity | +38% YoY |
| China-nexus targeting of logistics sector | +85% (largest vertical increase) |
| DPRK-nexus threat activity | +130% YoY |
| Cloud-conscious attacks (all actors) | +37% YoY |
| Cloud-focused attacks by nation-state actors | +266% YoY |
| China-nexus vulnerabilities targeting edge devices | 40% of their exploited CVEs |
| Zero-day vulnerabilities exploited before disclosure | +42% YoY |
Source: CrowdStrike 2026 Global Threat Report.
The WEF Global Cybersecurity Outlook 2026, written in collaboration with Accenture, notes that 64% of organizations are now accounting for geopolitically motivated cyberattacks — such as critical infrastructure disruption or espionage — in their risk mitigation strategies. 91% of the largest organizations have changed their cybersecurity strategies due to geopolitical volatility.
The ClickFix social engineering technique — which uses fake browser error messages to trick users into running malicious PowerShell commands — saw a 563% increase in fake CAPTCHA-themed lures between 2024 and 2025 per CrowdStrike, with Russia-based group Renaissance Spider using AI to translate ClickFix lures into Ukrainian for targeted campaigns.
The Defense Gap: Why Patch Time Is Getting Worse, Not Better
The Verizon 2026 DBIR contains a finding that contextualizes the AATI™ asymmetry metric: organizations are actually getting slower at patching, not faster, even as exploit windows collapse.
- Median remediation time for critical CVEs increased from 32 days in 2024 to 43 days in 2025
- Only 26% of critical vulnerabilities in CISA’s Known Exploited Vulnerabilities (KEV) catalog were fully remediated in 2025, down from 38% the prior year
- The volume of vulnerability records has grown roughly eightfold in the DBIR dataset over recent years
- Edge devices (VPNs, firewalls) now account for 22% of vulnerability-exploitation breaches, up from 3% the prior year — a 7× increase — while typically having limited EDR visibility
- CISA’s KEV catalog grew by 50% more vulnerabilities year-over-year that organizations need to remediate
Exploit windows have shrunk from 63 days to hours. Remediation time has grown from 32 to 43 days. Those two curves are moving in opposite directions, and the gap between them widens every quarter.
The CrowdStrike 2026 finding that 82% of detections are now malware-free — meaning attackers use legitimate credentials, trusted admin tools, and approved SaaS integrations rather than traditional malicious code — means that signature-based detection is no longer the primary defense line. Identity monitoring and cross-domain correlation have become the front line.
The Axis Cross-Reference: What Four Reports Say Simultaneously
CrowdStrike, Verizon, IBM, and Mandiant each draw on different datasets and methodologies — which is exactly why reading them together reveals things none of them state alone. Axis Intelligence Research mapped where the four 2025–2026 primary reports agree, where they diverge, and what their combined data shows:
| Finding | CrowdStrike 2026 GTR | Verizon 2026 DBIR | IBM X-Force 2026 | Mandiant M-Trends 2026 |
|---|---|---|---|---|
| Primary initial access vector | Identity / credential abuse | Vulnerability exploitation (31%) | Vulnerability exploitation (40%) | Exploit (32%), Voice phishing rising |
| AI role in attacks | Amplifier (89% increase) | Operational tool (scaling known TTPs) | Speed accelerator | Mostly amplifier; novel malware families emerging |
| Malware-free / credential attacks | 82% of detections | 62% human element | Credential-driven ops persistent | Identity abuse in cloud dominant |
| Ransomware trend | Speed + evasion | 48% of breaches; 69% didn’t pay | 109 groups (+49%) | Recovery-denial focus; 73% had prior infostealer |
| Nation-state standout | DPRK +130%, China +38% | Third-party +60% | Supply chain 4× since 2020 | Espionage dwell 122 days |
| Shadow AI / insider risk | AI tools exploited at 90+ orgs | Shadow AI 3× YoY; 45% employees | 300K+ ChatGPT creds stolen | LLM-querying malware observed |
Original Axis cross-source finding: Combining the CrowdStrike breakout time (29 min) with the Mandiant IAB handoff time (22 sec) and the Verizon data showing 43-day median patch cycles, Axis Intelligence Research calculates the effective attacker-defender time gap as follows: an attacker with an existing foothold (purchased from an IAB) can gain full lateral movement access in under 30 minutes, while the defender’s environment contains a backlog of critical CVEs that will take 43 days to remediate — a ratio of approximately 2,064:1 in time advantage to the attacker. This ratio does not appear in any primary source. Cite as: “Axis Intelligence Research cross-analysis of CrowdStrike 2026 GTR, Mandiant M-Trends 2026, and Verizon 2026 DBIR, June 2026.”
Methodology
Data collection period: Full-year 2025 incident data (as covered by the five primary annual reports) plus real-time 2026 developments through June 18, 2026.
AATI™ construction: The index aggregates four measurable dimensions of offensive timeline compression against their 2020 baselines: eCrime breakout time (CrowdStrike GTR historical series), time-to-exploit (Mandiant M-Trends / Mondoo 2026 State of Vulnerabilities), IAB handoff time (Mandiant M-Trends 2026), and defender patch time (Verizon DBIR historical series, inverted so that slower patching = lower score). Each dimension is normalized to a 0–100 scale, weighted by operational materiality.
Cross-reference methodology: Where two or more primary-source reports independently confirm a finding (e.g., vulnerability exploitation as #1 vector, confirmed by Verizon DBIR and IBM X-Force), Axis Intelligence Research labels it “convergent primary finding.” Where Axis derives a metric by combining inputs from multiple primary sources (e.g., the 2,064:1 attacker-defender time gap), this is labeled “Axis cross-source calculation” and the methodology is disclosed in full.
Limitations: All financial figures from FBI IC3 are self-reported losses; the FBI acknowledges actual losses may be 3–4× higher. CrowdStrike breakout time data covers eCrime adversaries specifically (not all threat actors). Mandiant IAB handoff time represents a median across observed cases, not an average across all ransomware attacks. Shadow AI figures from the DBIR reflect corporate device DLP telemetry, not a representative population survey.
Verification standard: Every statistic in this article is traced to a primary institutional source — FBI, CrowdStrike, Verizon, Mandiant (Google Cloud), IBM, or WEF. No tech blog aggregators were used. Where a statistic appears in a secondary source, Axis Intelligence Research has verified it against the primary report cited.
About This Dataset
Title: AI Cyberattack Statistics 2026 — AATI™ Quarterly Tracker
License: Creative Commons Attribution 4.0 International (CC BY 4.0)
Download: CSV Dataset — free, no registration required
Update cadence: Quarterly — next update September 2026
Coverage: United States and global (per source geography)
Published by: Axis Intelligence Research & Marcus Chen, June 18, 2026
Citation Block
APA: Axis Intelligence Research & Chen, M. (2026, June 18). AI cyberattack statistics 2026: The year attackers got faster than defenders — AATI™ index. Axis Intelligence. https://axis-intelligence.com/ai-cyberattack-statistics/
MLA: Axis Intelligence Research and Marcus Chen. “AI Cyberattack Statistics 2026: The Year Attackers Got Faster Than Defenders.” Axis Intelligence, 18 June 2026, axis-intelligence.com/ai-cyberattack-statistics/.
Chicago: Axis Intelligence Research and Marcus Chen. “AI Cyberattack Statistics 2026: The Year Attackers Got Faster Than Defenders.” Axis Intelligence, June 18, 2026. https://axis-intelligence.com/ai-cyberattack-statistics/.
Cite This Research (Embed Block)
<blockquote style="border-left:4px solid #0057FF;padding:12px 20px;margin:24px 0;font-family:sans-serif;">
<p style="margin:0 0 8px;font-size:15px;"><strong>AI Cyberattack Statistics 2026 — AATI™</strong></p>
<p style="margin:0 0 8px;font-size:14px;">AI-enabled attacks +89% YoY. Breakout time: 29 min avg / 27 sec fastest. FBI cybercrime losses: $20.9B. Vulnerability exploitation #1 vector for first time in 19 years. AATI™ score: 75.3/100.</p>
<p style="margin:0;font-size:13px;color:#555;">Source: <a href="https://axis-intelligence.com/ai-cyberattack-statistics/" style="color:#0057FF;">Axis Intelligence Research & Marcus Chen</a> — CC BY 4.0. Last updated June 18, 2026.</p>
</blockquote>
Frequently Asked Questions
How much did AI-enabled cyberattacks increase in 2025?
AI-enabled adversary operations increased 89% year-over-year in 2025, according to the CrowdStrike 2026 Global Threat Report, which tracks more than 280 named adversaries. This figure measures the increase in attack volume from adversaries who integrated AI into their operations, compared to 2024. Separately, the FBI IC3 2025 Annual Report documented 22,364 AI-related complaints generating $893 million in losses — the first time AI cybercrime has been tracked as a distinct category in the report’s 25-year history.
What is the fastest recorded cyberattack breakout time in 2026?
The fastest recorded eCrime breakout time — the interval between initial access and lateral movement to a second system — is 27 seconds, documented in the CrowdStrike 2026 Global Threat Report. The average in 2025 was 29 minutes, down from 48 minutes in 2024, representing a 65% acceleration in a single year. In one documented 2025 intrusion, data exfiltration began within four minutes of initial access.
What is the AATI™ and what does a score of 75.3 mean?
The AATI™ (AI Attack Time-to-Impact Index) is a proprietary composite index created by Axis Intelligence Research measuring the compression of the offensive cyber timeline across four dimensions: eCrime breakout time, time-to-exploit CVEs, initial access broker handoff time, and defender patch time (inverted). A score of 75.3 out of 100 means attackers are operating at 75% of the theoretical maximum speed compression in each dimension — while organizations are actually patching slower in 2025 than they were in 2024.
Why has vulnerability exploitation overtaken stolen credentials as the #1 breach entry point?
For the first time in 19 years of Verizon DBIR publication, vulnerability exploitation (31%) overtook credential abuse (13%) as the most common initial breach entry point in 2025. The primary driver is AI: attackers now use AI tools to scan for, identify, and weaponize software vulnerabilities faster than organizations can patch them. IBM X-Force found that 56% of tracked vulnerabilities in 2025 required no authentication to exploit, allowing attackers to bypass credential-based defenses entirely. The time from CVE disclosure to active exploitation has collapsed from 63 days in 2018–2019 to hours in some 2025 cases.
How many cybercrime losses did the FBI record in 2025?
The FBI Internet Crime Complaint Center (IC3) received 1,008,597 complaints in 2025 — the first time annual complaint volume exceeded one million — and recorded $20.877 billion in total reported cybercrime losses, a 26% increase from $16.6 billion in 2024 and the highest figure since IC3 began tracking in 2000. The FBI estimates actual losses may be 3–4× higher than reported figures, potentially approaching $80 billion when accounting for unreported incidents.
What is shadow AI and why is it a cybersecurity threat?
Shadow AI refers to employees using AI tools — including external chatbots, AI coding assistants, and AI browser extensions — on corporate devices without authorization or IT oversight. The Verizon 2026 DBIR found that 67% of employees accessed AI services through non-corporate accounts on company devices, and 45% are now regular AI users on corporate devices, up from just 15% a year prior. Employees are uploading source code, technical documents, and proprietary data to external AI platforms, creating intellectual property exposure and new attack surfaces. IBM X-Force found over 300,000 ChatGPT credentials harvested by infostealers and sold on dark web markets in 2025.
How fast is initial access handed off to ransomware groups?
According to Mandiant M-Trends 2026, the median time between an initial access broker (IAB) gaining entry to a network and handing that access to a ransomware affiliate has collapsed from over 8 hours in 2022 to 22 seconds in 2025. This represents a 1,309-fold acceleration in under three years, enabled by automated APIs that allow ransomware affiliates to purchase access and trigger deployment scripts instantly.
Which nation-state actors are using AI in cyberattacks?
The CrowdStrike 2026 Global Threat Report documents three confirmed nation-state AI deployments: Russia-nexus FANCY BEAR deployed LAMEHUG — LLM-powered malware using Qwen2.5-Coder to generate live reconnaissance commands; DPRK-nexus FAMOUS CHOLLIMA used AI-generated personas to infiltrate Western technology companies as insider threats (median dwell time 122 days); and eCrime actor PUNK SPIDER used AI-generated scripts to accelerate credential dumping and erase forensic evidence. China-nexus activity increased 38% overall, with cloud-focused attacks by nation-state actors rising 266%.
What is the current state of ransomware in 2026?
Ransomware was present in 48% of all breaches in the Verizon 2026 DBIR dataset — up from 44% the prior year. However, 69% of ransomware victims did not pay, and 96% of victims (where size was known) were SMBs. The IBM X-Force 2026 report found 109 active ransomware and extortion groups in 2025, up 49% from 73 in 2024, with the top 10 groups’ share of total activity falling 25% as the ecosystem fragmented into smaller cells. Mandiant M-Trends 2026 found that ransomware operators shifted focus from data theft to recovery denial — actively targeting backup infrastructure and virtualization platforms to eliminate victims’ ability to restore without paying.
Axis Intelligence Research · AI Cyberattack Statistics 2026 Published: June 18, 2026 | Next update: September 2026 | License: CC BY 4.0
