For years the sales pitch around artificial intelligence in cybersecurity ran in one direction. AI was the thing defenders bought to keep pace with a rising tide of threats. CrowdStrike’s newest research reframes that story, arguing that the same tools now sit on both sides of the fight, and that the attackers have been quick studies.
The security vendor’s 2026 Threat Hunting Report tracks what it describes as a marked rise in AI-driven cyberattacks, the sort of campaigns where generative tools are woven into the day to day mechanics of intrusion rather than bolted on as a novelty. The finding lands at a moment when Australian organisations, from banks and miners to hospitals and government agencies, are pouring money into their own AI programs, and it complicates the comfortable assumption that automation is a defender’s advantage first.
What the research found
CrowdStrike’s threat hunting reports draw on the telemetry the company gathers from monitoring endpoints and cloud environments across its global customer base, combined with the work of its human hunting teams who chase adversaries in real time. That gives the annual document a particular flavour. It is less a survey of opinion and more a field report from teams who spend their days watching intrusions unfold.
The through line of the 2026 edition is that adversaries have industrialised parts of their craft with AI. Where a phishing lure once betrayed itself through clumsy grammar or an obvious template, generative text now produces fluent, tailored messages at scale. Reconnaissance that used to take an operator days can be compressed into hours. And the barrier to entry has dropped, letting less skilled actors reach for capabilities that were previously the preserve of well-resourced crews.
The report also picks up on the growing focus among attackers on identity and cloud infrastructure rather than the old model of dropping malware on a laptop and hoping to spread. Stolen credentials, abused access tokens and social engineering aimed at help desks have become the favoured way in, and AI makes each of those techniques cheaper and more convincing. For defenders, that shift is awkward, because it moves the fight away from the file-based signatures that traditional antivirus was built to catch.
Two ways to read it
There are competing interpretations of research like this, and both deserve airing. The optimistic reading is that AI changes the tempo of attacks without fundamentally rewriting the rules. The techniques underneath, stolen passwords, unpatched systems, tricked employees, are familiar, and the defensive playbook of strong identity controls, rapid patching and constant monitoring still works. On this view, AI is an accelerant rather than a new category of threat, and organisations that already do the basics well have less to fear than the headlines suggest.
The more sober reading is that speed itself is the danger. When an attacker can move from initial foothold to serious damage in a fraction of the time it once took, the window for a human defender to notice and respond shrinks accordingly. That puts pressure on organisations to automate their own detection and response, which loops back to the uncomfortable truth that both sides are now in an AI arms race. It is worth remembering, too, that a security vendor publishing research on rising threats has a commercial interest in the alarm, since CrowdStrike sells the products meant to counter exactly these campaigns. That does not make the findings wrong, but it is a reason to read the framing with the usual scepticism and to weigh it against independent voices.
Why it matters for Australia
Australia has spent the past few years as a case study in what happens when cyber defences fail. The Optus and Medibank breaches of 2022 reshaped the national conversation and prompted a wave of regulatory reform, including the Cyber Security Act passed late in 2024 and mandatory ransomware payment reporting for larger businesses. Against that backdrop, a report arguing that attackers are getting faster and cheaper to operate is not an abstract warning. It speaks directly to the risk calculus facing Australian boards.
The Australian Signals Directorate has been consistent in its own annual cyber threat reporting, noting that a cybercrime is reported roughly every six minutes and that state-sponsored actors continue to probe critical infrastructure. Layer AI-driven efficiency on top of that baseline and the exposure grows for exactly the sectors Australia most wants to protect, energy, health, financial services and the data centres now being built out at speed to power the country’s own AI ambitions. The same firms racing to deploy AI internally, several of which FluentSea has covered in recent weeks, are the ones that need to think hardest about how those systems widen the attack surface.
There is a skills dimension as well. Australia’s cyber workforce shortage has been documented for years, and if the effect of AI is to compress the time defenders have to react, then the pressure on already stretched security teams intensifies. That strengthens the case, at least commercially, for the automated detection and managed services that vendors including CrowdStrike, Arctic Wolf and others are pitching hard into the local market. For smaller businesses without a dedicated security function, the gap between the sophistication of the threats and the resources to meet them is the part of this story that should worry policymakers most.
What comes next
Expect the findings to feed straight into the procurement conversations already under way across corporate Australia and the public sector. The practical takeaways are unglamorous but familiar: tighten identity and access management, treat multi-factor authentication as a floor rather than a ceiling, shorten patching cycles and rehearse incident response so that the human parts of the machine can keep up when the automated parts of an attack do not wait.
The larger question the report leaves open is one of pace. If AI genuinely shifts the economics of attacking faster than it shifts the economics of defending, the advantage tilts toward the offence, at least for a while. Australian regulators, insurers and boards will be watching the next few reporting cycles closely to see whether that gap widens or whether defensive tooling catches up. For now, the message from CrowdStrike’s threat hunters is blunt enough. The tools that were meant to save security teams time are now being used to take it away.
Sources: CRN Australia.



















































