CrowdStrike has warned that artificial intelligence is dramatically widening the digital attack surface for businesses, with AI-enabled intrusions surging at what it calls an “alarming” rate.
In its 2026 Global Threat Report, the US-based cybersecurity firm recorded an 89 per cent increase in attacks leveraging AI over the past year. The findings indicate a significant shift in criminal tactics: rather than simply using AI to refine traditional hacking methods, threat actors are increasingly targeting AI systems themselves.
According to the report, investigators uncovered incidents at more than 90 companies where cyber criminals injected malicious prompts into legitimate generative AI platforms. These manipulated systems were tricked into producing unauthorised commands, including instructions designed to steal login credentials and cryptocurrency assets.
The research also highlights vulnerabilities in AI development environments. In several cases, attackers exploited weaknesses within these systems to establish persistence inside corporate networks before deploying ransomware. Elsewhere, criminals created fake AI servers masquerading as trusted services, enabling them to intercept sensitive enterprise data as it moved through internal systems.
George Kurtz, Chief Executive of CrowdStrike, said the rapid integration of AI into development pipelines, SaaS platforms and operational workflows has fundamentally changed the cybersecurity landscape. As AI becomes embedded in business infrastructure, it effectively becomes part of the attack surface.
He noted that adversaries are exploiting legitimate AI tools by inserting malicious prompts capable of generating unauthorised commands, warning that exploitation is accelerating in step with innovation.
The findings underscore a growing concern within the cybersecurity industry: as organisations race to adopt AI technologies to boost productivity and efficiency, criminals are evolving just as quickly. Without stronger safeguards, monitoring systems and secure development practices, AI-driven threats are expected to grow in scale, complexity and impact.
For businesses, the message is clear — integrating AI must be matched with robust security strategies, or the very tools designed to enhance performance could become gateways for sophisticated cyber attacks.





