A new report from CrowdStrike, covering the year ending March 31, 2026, concludes that more than 58% of Chinese state-linked cyber operations targeted technology companies, with attackers seeking artificial intelligence development assets and intellectual property.
Why the uptick in espionage?
CrowdStrike’s analysis attributes the increased espionage to Beijing’s inability to quickly develop advanced AI capabilities and related intellectual property domestically. The report highlights that United States export controls on chips used to train AI models have significantly slowed China’s technological progress. At the same time, the report notes that domestically developed Chinese models are attempting to match Western systems’ performance at much lower operating cost.
Who was targeted?
The investigation found that Chinese-affiliated actors exploited software vulnerabilities to establish persistent access to networks of North American technology organizations. The report also states that government communications systems in Southeast Asia were targeted by these actors.
Context and legal gray areas
CrowdStrike’s findings align with earlier warnings: earlier this year Anthropic and OpenAI reported attempts by Chinese companies to obtain commercially sensitive information from U.S. AI developers. Analysts have cautioned that the line between unlawful activity and aggressive commercial intelligence-gathering is often blurred in this domain.
North Korea-related activity
The report also flags worrying activity connected to North Korea. It says actors linked to the Pyongyang regime have sought to embed themselves as IT professionals within North American, European and Asian companies, primarily to generate foreign currency revenue for the regime.
The Chinese Cyberspace Administration did not respond to inquiries about the report.
Why this matters
The report underscores that geopolitical competition increasingly plays out in cyberspace, with states focusing on acquiring technology and AI capabilities. The scale and focus of these operations suggest some governments are using cyber means to try to make up shortfalls in advanced technologies in the near term.



