Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

CrowdStrike reports 43% rise in finance hacks

CrowdStrike, a US cybersecurity firm based in Austin, Texas, said in a report released on May 14 that intrusions against financial institutions rose 43% globally over two years.

North Korea-linked hackers stole US$2.02 billion in digital assets in 2025, partly using AI-based deception.

The report said 423 financial services firms appeared on ransomware leak sites in 2025, up 27% from a year earlier.

It also said a North Korea-linked group stole US$1.46 billion in cryptocurrency through trojanized software distributed in a supply chain compromise.

CrowdStrike said China-linked groups were a key intelligence threat in Southeast Asia.

The company said activity in Indonesia and the Philippines focused on economic data, personal information, and other information that could support future espionage operations.

🔗 Source: CrowdStrike

🧠 Food for thought

Implications, context, and why it matters.

Financial firms are adopting AI tools that can also expose them

  • U.S. financial regulators want banks to use tools such as AI if they can manage the risks 1.
  • The U.S. Treasury released an AI Lexicon and the Financial Services AI Risk Management Framework to guide AI use and reduce uncertainty. Treasury said the resources could help speed broader use across finance 2.
  • The Office of the Comptroller of the Currency is the U.S. bank regulator 3. The National Credit Union Administration oversees credit unions 4. Both have set up technology-focused teams to work on new tools 3, 4.
  • That support can add more links between systems, which gives cybercriminals and nation-states more places to strike 5.

Relying on a few cybersecurity providers is becoming a larger danger

  • Rising threats may lead banks and other financial institutions to lean on a small group of cybersecurity vendors, which raises concentration risk 6.
  • That danger came into view in July 2024 when a CrowdStrike update caused a global IT outage that hit banks and payment systems 7.
  • The event made clear that a tool built to block attackers can still disrupt many systems even without a breach 8.
  • Regulators and financial institutions need to manage the systemwide risk tied to third-party technology and cybersecurity providers, along with the hackers those firms try to stop 6.

Recent CrowdStrike developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.