CrowdStrike says China drives 58% of state-backed cyberattacks on tech firms
CrowdStrike Holdings reported that over 58% of state-sponsored cyberattacks on tech companies originate from China, specifically targeting artificial intelligence assets. The firm noted that adversaries are escalating espionage to steal AI capabilities and intellectual property. North Korean actors were also identified as infiltrating IT workforces to generate income for the regime.

*this image is generated using AI for illustrative purposes only.
Cybersecurity firm CrowdStrike Holdings has reported that over 58% of state-sponsored cyberattacks targeting technology companies originate from China. The firm's analysis indicates that these adversaries are specifically escalating espionage efforts to steal artificial intelligence capabilities and intellectual property that they cannot develop quickly enough on their own.
The report, which covers events until March 31, highlights that U.S. restrictions on China's access to AI training chips have impeded Beijing's technological progress. In response, China is reportedly formulating its own AI models to reduce operating costs and achieve comparable intelligence levels.
CrowdStrike identified several China-linked cyber groups actively targeting the technology sector. SUNRISE PANDA is focusing on East and Southeast Asian tech firms, while MURKY PANDA is launching password-spraying attacks against hundreds of organizations, primarily in the U.S. Additionally, WARP PANDA is repeatedly exploiting vulnerabilities at North American tech companies to maintain long-term access. These activities appear aimed at acquiring technology and information that supports the Chinese Communist Party's intelligence-gathering objectives.
Regional Threat Landscape
The firm also noted efforts by North Korea-linked actors to infiltrate IT workforces across North America, Europe, and Asia. These operations are largely intended to generate income for the regime through illicit means.
| Threat Actor | Target Region | Method |
|---|---|---|
| SUNRISE PANDA | East and Southeast Asia | Targeting tech firms |
| MURKY PANDA | Primarily U.S. | Password-spraying attacks |
| WARP PANDA | North America | Exploiting vulnerabilities |
This surge in cyberactivity coincides with the U.S. Defense Department's recent update to its "1260H list," which added companies suspected of having ties to China's military or defense-industrial sector. The list includes major entities such as Alibaba Group, Baidu Inc., and BYD.
How will the U.S. government likely respond to the escalation of state-sponsored espionage by China?
What impact will these cyber threats have on the global supply chain for AI technologies?
How might the inclusion of major companies like Alibaba and Baidu on the '1260H list' affect their international business operations?

























