
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
CrowdStrike's 2026 Global Threat Report reveals an 89% surge in AI-enabled cyberattacks, with criminals using generative AI tools to automate and accelerate breaches. Average breakout time dropped to 29 minutes in 2025, with some attacks taking just seconds, leading to rapid data theft and compromised enterprise systems.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event involves AI systems both as tools used maliciously by adversaries (e.g., injecting malicious prompts into generative AI tools) and as targets of exploitation, leading to significant harms including financial theft, data breaches, and disruption of enterprise security. These harms fall under violations of property and harm to organizations, and the AI system's role is pivotal in enabling and accelerating these attacks. Therefore, this qualifies as an AI Incident.[AI generated]