CrowdStrike says China-linked hacking groups were the top espionage threat to technology companies from April 1, 2025 to March 31, 2026, driven by strategic interest in AI and related technologies. The report flags hardware, semiconductors, software and IT services as primary targets and warns that both major AI labs and smaller model developers face heightened risk. It also highlights North Korean insider schemes, ongoing Russian and Iran-linked activity, and a 30% rise in criminal ads selling access to corporate systems.
CrowdStrike: China-Linked Hackers Top Espionage Threat to Tech Firms Amid AI Boom

CrowdStrike, the cybersecurity firm, reported that China-linked hacking groups represented the leading espionage threat to technology companies from April 1, 2025 to March 31, 2026 — a period marked by heavy investment and frenzied valuations in artificial intelligence.
The company said the campaigns align with Beijing's strategic priorities and reflect sustained interest in technology development, intellectual property and other information with strategic or economic value. The technology sector — including hardware, semiconductors, software, IT services and consulting — remained the most heavily targeted by both state-backed actors and cybercriminals.
Key Findings and Context
CrowdStrike did not disclose the names of specific victim companies but highlighted that both large frontier AI labs and smaller, domain-specific model developers are high-value targets amid the current AI investment surge.
"There is an AI arms race occurring between the U.S. and China, and China intends to achieve global dominance by 2030," said Adam Meyers, CrowdStrike's senior vice president and head of counter adversary operations, warning that major and niche model developers face elevated risk.
On April 23, the White House Office of Science and Technology Policy publicly accused China-based entities of mounting "deliberate, industrial-scale campaigns" to surreptitiously extract U.S.-developed AI models for their own use, citing recent instances as evidence.
Other Threat Actors
The report also highlighted a major threat from North Korean operations that use fabricated identities to obtain remote IT positions at technology firms. Salaries are reportedly funneled back to the Pyongyang government, while the compromised roles create internal footholds for intelligence collection.
Groups linked to Russia and Iran continue to target the tech sector for intelligence collection and, in some incidents, destructive malware attacks. At the same time, financially motivated criminal groups have increased activity, with CrowdStrike noting a roughly 30% rise in advertisements offering access to corporate networks during the report period.
Responses
A Chinese Embassy spokesperson in Washington dismissed the report, saying, "China opposes hacking activities and fights such activities in accordance with the law," and accused critics of vilification under the pretext of cybersecurity. The spokesperson called for U.S.-China cooperation on AI development and governance and referenced recent constructive exchanges between leaders as a basis for launching government-to-government dialogue on AI.
The findings underscore the interplay between geopolitical strategy and cyber espionage as nations and non-state actors compete for advantage in the rapidly evolving AI landscape.
Reporting by AJ Vicens in Detroit; Editing by Sanjeev Miglani.
Help us improve.


































