As artificial intelligence reshapes the boundaries of economic and military power, the laboratories and server rooms of the technology sector have become the new contested terrain of great-power rivalry. CrowdStrike's latest annual threat assessment finds Chinese state-linked hackers at the forefront of a sustained espionage campaign targeting the intellectual foundations of the AI age — semiconductors, software, and frontier research — in direct alignment with Beijing's ambition to lead the world in artificial intelligence by 2030. The finding arrives not as a surprise but as a clarification:
Chinese hackers pose biggest espionage threat to tech firms: CrowdStrike
An AI arms race is occurring, and China intends dominance by 2030
So CrowdStrike is saying Chinese hackers are the biggest threat. But what does "biggest" actually mean here? Are we talking about the number of attacks, the damage caused, or something else?
The report covers a full year of data and looks at espionage campaigns specifically—so it's about who's conducting the most sustained, coordinated intelligence collection against tech firms. China-linked operations came out on top in that category.
But CrowdStrike didn't name specific companies that were hit, right? So we don't actually know which firms were targeted or how successful the intrusions were.
That's correct. The report identifies the sectors—semiconductors, software, hardware development, IT services—but not individual targets. We know the threat is real and systematic, but the granular details aren't public.
The North Korea angle is interesting. They're using fake identities to get IT jobs. How widespread is that actually?
The report calls it a "major threat" and describes it as a scheme, but doesn't give numbers on how many operatives are embedded this way or how many companies have been compromised through this method.
So we have a characterization of severity but not a count. That's important to note—we know it's happening, we know it's deliberate, but the scale is still somewhat opaque.
And the AI angle—is that new, or has China always been targeting tech companies for intellectual property?
The IP theft has been ongoing for years, but what's new is the explicit focus on AI models and frontier AI labs. The White House called out industrial-scale campaigns to extract American AI models specifically. That's a shift in priority.
Though we should note: the White House made that accusation in April, and CrowdStrike's data ends in March. So there's some overlap but not complete alignment in timing.
What about the Chinese government's response? Do they deny this is happening?
They deny it categorically. The embassy said China opposes hacking and fights it, and called the report a smear. They also pivoted to saying both countries should cooperate on AI governance.
Which is a diplomatic response, not a factual rebuttal. They didn't address the specific findings—they rejected the framing.
Il Polso
- CrowdStrike's year-long assessment names Chinese state-linked hackers as the single greatest espionage threat to technology companies globally, with campaigns surgically aligned to Beijing's AI and semiconductor ambitions.
- The technology sector — spanning hardware R&D, semiconductors, IT services, and software — has become the world's most targeted industry, as historic AI investment levels make its intellectual property extraordinarily valuable to foreign governments.
- North Korean operatives are quietly embedding themselves inside tech firms using fabricated identities, siphoning salaries back to Pyongyang while opening intelligence footholds from within — a threat that is unconventional, patient, and difficult to detect.
- A 30 percent surge in underground advertisements selling access to compromised tech targets signals that espionage infrastructure is being commercialized, lowering the barrier for actors of every sophistication level to join the assault.
- Beijing has rejected the findings as vilification while simultaneously signaling openness to government-to-government AI dialogue — a diplomatic posture that holds tension with the operational picture the report describes.
- The threat landscape has fundamentally shifted: technology companies now face simultaneous, multi-directional pressure from state intelligence services and criminal networks, with no clear sign of relief on the horizon.
As artificial intelligence reshapes the boundaries of economic and military power, the laboratories and server rooms of the technology sector have become the new contested terrain of great-power rivalry. CrowdStrike's latest annual threat assessment finds Chinese state-linked hackers at the forefront of a sustained espionage campaign targeting the intellectual foundations of the AI age — semiconductors, software, and frontier research — in direct alignment with Beijing's ambition to lead the world in artificial intelligence by 2030. The finding arrives not as a surprise but as a clarification: what once looked like opportunistic digital theft has matured into something more deliberate, more strategic, and more difficult to separate from the broader arc of U.S.-China competition.
A new annual threat assessment from cybersecurity firm CrowdStrike has identified Chinese state-linked hackers as the dominant espionage force targeting the global technology industry. Drawing on data spanning April 2025 through March 2026, the report finds these campaigns are not incidental — they map directly onto Beijing's declared strategic priorities: advanced technology acquisition, intellectual property collection, and intelligence with both economic and geopolitical weight. The technology sector, encompassing semiconductors, software, IT services, and hardware research, ranked as the most heavily targeted industry worldwide.
The backdrop is an accelerating AI arms race. CrowdStrike's senior vice president for counter adversary operations, Adam Meyers, pointed to Beijing's explicit goal of achieving global AI dominance by 2030 as the engine driving heightened interest in frontier AI laboratories and specialized model developers. The White House had already accused Chinese entities earlier this year of running industrial-scale campaigns to extract and repurpose American-developed AI systems.
North Korea has carved out its own niche in this landscape through a quieter method: placing operatives with fabricated identities into remote IT roles at technology companies. These embedded workers redirect their earnings to Pyongyang while maintaining intelligence access inside their employers' networks. Russian and Iranian groups have similarly intensified their focus on American and allied tech infrastructure, at times pairing espionage with destructive malware.
The criminal ecosystem has grown alongside state activity. The same period saw a 30 percent rise in underground advertisements offering access to compromised technology targets — a commercialization of intrusion that has effectively opened the sector to a wider range of adversaries.
Beijing's embassy in Washington rejected the report's conclusions, calling them vilification under a cybersecurity pretext, and pointed to recent diplomatic exchanges in which both nations agreed to explore government-to-government AI governance dialogue. The contrast between that diplomatic posture and the operational picture CrowdStrike describes captures the central tension of the moment: technology companies now sit at the intersection of great-power competition, criminal enterprise, and an AI investment boom — facing threats from multiple directions with little prospect of the pressure easing.
A cybersecurity firm's annual threat assessment, released this week, has placed Chinese state-linked hackers at the center of a widening espionage campaign against technology companies worldwide. The finding arrives as artificial intelligence investments have surged to historic levels, making the sector an increasingly valuable target for foreign governments and criminal networks alike.
CrowdStrike, which compiled data from April 2025 through March 2026, determined that hacking operations traced to China represented the single largest espionage threat facing the technology industry during that period. The campaigns, the firm said, align directly with Beijing's stated strategic priorities: acquiring advanced technology, securing intellectual property, and obtaining information with both economic and geopolitical value. The technology sector itself—encompassing hardware research and development, IT services, semiconductors, and software—emerged as the most heavily targeted industry globally, ahead of all other sectors.
The timing of this threat surge coincides with what Adam Meyers, CrowdStrike's senior vice president for counter adversary operations, described as an accelerating artificial intelligence arms race between the United States and China. Meyers noted that Beijing has explicitly stated an intention to achieve global dominance in AI by 2030, a goal that makes frontier AI laboratories and smaller, specialized model developers particularly attractive targets. In April, the White House Office of Science and Technology Policy had already accused Chinese entities of conducting "deliberate, industrial-scale campaigns" to extract and repurpose American-developed AI models for their own advancement.
North Korea has emerged as a secondary but significant threat through an unconventional method: operatives using fabricated identities to secure remote IT positions within technology companies. Once embedded, these workers funnel their salaries back to the Pyongyang government while simultaneously providing intelligence footholds inside their employers' networks. Russian and Iranian hacking groups have also intensified their targeting of American and allied technology infrastructure, combining espionage operations with occasional destructive malware deployments.
Financially motivated cybercriminals have not been idle. The same reporting period saw a 30 percent increase in the volume of advertisements from hacking groups openly selling access to compromised technology targets, indicating a thriving underground market for stolen credentials and network entry points. This commercialization of access has effectively democratized the threat landscape, allowing actors with varying levels of sophistication and resources to participate in targeting the sector.
The Chinese Embassy in Washington dismissed the CrowdStrike findings, stating that China opposes hacking and fights such activities within its legal framework. A spokesperson rejected what the embassy characterized as "vilification and smears under the pretext of cybersecurity," and called for collaborative U.S.-China work on artificial intelligence development and governance. The statement referenced recent diplomatic exchanges between the two nations' leaders, during which both sides reportedly agreed to establish a government-to-government dialogue on AI policy.
The report underscores a fundamental shift in the nature of technology sector risk. Where cybersecurity threats once centered primarily on financial theft or service disruption, the current landscape is dominated by state-sponsored intelligence collection tied to specific geopolitical and economic objectives. The convergence of AI investment booms, intensifying great-power competition, and the proliferation of both state and criminal hacking capabilities has created an environment in which technology companies face threats from multiple directions simultaneously—and with little sign of abatement.
Citazioni salienti
There is an AI arms race occurring between the U.S. and China, and China intends to achieve global dominance by 2030.— Adam Meyers, CrowdStrike senior vice president
China opposes hacking activities and fights such activities in accordance with the law, and rejects vilification and smears under the pretext of cybersecurity.— Chinese Embassy spokesperson in Washington