CrowdStrike has released its 2026 Financial Services Threat Landscape Report, detailing a sharp rise in cyberattacks targeting financial institutions, cryptocurrency platforms, and fintech companies worldwide.
The report highlights how threat actors are increasingly using AI-powered deception, trusted identities, and cloud-based attack methods to accelerate intrusions and evade traditional security defenses.
Among the report’s findings, CrowdStrike identified North Korean threat groups as major drivers behind large-scale cryptocurrency theft operations in 2025.
Billions lost to digital asset theft
DPRK-linked threat actors reportedly drove a 51% year-over-year increase in digital asset theft in 2025, resulting in losses of around USD2.02 billion across the sector.
PRESSURE CHOLLIMA was identified as the group behind what CrowdStrike described as the largest reported cryptocurrency theft to date, allegedly stealing USD1.46 billion through trojanized software distributed via a supply chain compromise.
Another threat group, GOLDEN CHOLLIMA, reportedly used recruitment-themed lures to gain access to cloud environments and divert cryptocurrency funds from fintech organizations in Southeast Asia and Canada.

AI accelerates cybercrime operations
The report also highlights how AI tools are enabling adversaries to scale cybercrime operations more rapidly.
FAMOUS CHOLLIMA allegedly used AI-generated identities to infiltrate cryptocurrency exchanges, fintech platforms, and consumer banks, while STARDUST CHOLLIMA increased operations using synthetic recruiter personas and AI-generated video conferencing environments.
These tactics are helping attackers shorten the time between initial access and operational impact, making traditional security defenses harder to maintain.
Financial institutions face growing pressure
Beyond cryptocurrency theft, the report points to growing ransomware and espionage activity targeting financial organizations.
China-linked threat actors reportedly expanded intelligence collection operations globally. HOLLOW PANDA conducted intrusions targeting financial institutions in the Philippines, Indonesia, and Brazil, while MURKY PANDA deployed operational relay box networks across more than 150 endpoints in 36 countries.
The report also documented a rise in ransomware-related activity, with 423 financial services organizations appearing on dedicated leak sites during the reporting period.
MUTANT SPIDER reportedly drove high intrusion volumes through vishing campaigns before selling access to ransomware groups, while SCATTERED SPIDER resumed aggressive ransomware operations targeting insurance organizations after a temporary pause.
AI versus AI in cybersecurity
Adam Meyers, head of counter adversary operations at CrowdStrike, said AI is dramatically changing how cyberattacks are executed.
“Adversaries are using AI to compress the time from initial access to impact, moving through trusted paths faster than legacy defenses can respond,” Meyers said.
He added that organizations will increasingly need AI-driven threat intelligence and proactive threat hunting capabilities to keep pace with evolving attacks.