AI-Powered Attackers Are Running Past Traditional Defences, CrowdStrike Data Suggests
With roughly four in five intrusions now leaving no malware behind, security teams are being forced to rethink what a break-in even looks like.

Key points
- CrowdStrike's Global Threat Report estimates about 79% of attacks in the last year involved no malware at all.
- Attackers are increasingly using stolen logins and legitimate tools instead of viruses, making them harder to spot.
- Security operations centres, the teams that watch company networks around the clock, are being pushed to add new layers of detection.
- AI is now on both sides of the fight, helping criminals move faster and helping defenders sift through alerts.
For two decades, the pattern in cybersecurity was almost boring. Defenders built walls. Attackers found ladders. Defenders built taller walls.
That rhythm is breaking.
According to reporting from The Hacker News, attackers armed with artificial intelligence are now outpacing the tools most companies rely on to catch them. The clearest evidence sits in a single number from CrowdStrike, a large security vendor: about 79% of attacks the company tracked involved no malware at all.
That matters because most business defences are still built to spot malware, meaning malicious software that infects a computer. Antivirus programs, and their modern cousins known as endpoint detection tools, are trained to notice files behaving badly.
But if there is no bad file, there is nothing for them to notice.
So how are the criminals getting in without malware?
They are logging in. Increasingly, attackers buy or steal a valid username and password, often from a worker who was tricked by a phishing email, which is a fake message designed to harvest login details. Once inside, they use the same everyday software a real employee would use: remote access tools, cloud dashboards, file-sharing apps.
To a monitoring system, it looks like Karen from accounts doing her job. It is not Karen.
This technique has a name in the industry: "living off the land". The attacker brings almost nothing with them. They borrow what is already there.
AI has made this style of attack far cheaper to run at scale. Criminals now use large language models to write more convincing phishing emails in fluent English, to generate fake voice messages for phone-based scams, and to sift through stolen data faster than a human ever could.
The old defensive stack was not built for this. It was built to catch a virus attached to an email in 2011.
What defenders are actually doing about it
The response, at least among better-resourced companies, is to stop relying on any single layer of detection. Instead of watching only the laptop or only the email server, security teams are trying to stitch together signals from across the business: identity systems that track logins, cloud platforms that record file access, network tools that watch traffic patterns.
The idea is simple. One weird event is noise. Five weird events in the same hour, involving the same account, is a story.
This is where the phrase "multi-layered detection" comes from. It is not marketing. It is an admission that no single sensor is enough any more.
AI is helping on this side of the fence too. Security operations centres, the round-the-clock teams that triage alerts, are drowning in warnings. Machine learning is being used to group related alerts, rank the urgent ones, and quietly close the false alarms.
That frees analysts to chase the intrusions that actually matter.
What ordinary people can take from this
If 79% of attacks now start with a stolen login, the single most useful thing most people can do is protect their own credentials. Turn on multi-factor authentication, which is the extra code sent to your phone, on every account that offers it. Treat unexpected password reset emails with suspicion.
And if a message at work asks you to click quickly, quiet urgency is usually the tell. Real IT departments almost never rush you.
The walls-and-ladders game is not coming back. What replaces it is messier, faster and far more dependent on the humans in the middle.



