CrowdStrike Holdings shares jumped 20.5% after the cybersecurity company posted record fiscal second-quarter results and raised its full-year outlook. CEO George Kurtz linked stronger demand directly to rising AI-driven cyber threats.
Revenue and adjusted earnings also beat Wall Street estimates, while new subscription commitments reached a quarterly record. The gains came as businesses faced growing concern about AI-enabled attacks and wider cyber risks.
CrowdStrike reported $1.47 billion in quarterly revenue, up 26% from a year earlier. Analysts had expected revenue of $1.44 billion. Meanwhile, adjusted earnings reached $0.31 per share, above the $0.29 consensus estimate. Net new annual recurring revenue hit a record $332.8 million.
That measure increased 51% from a year earlier. Total annual recurring revenue also climbed 25% to $5.84 billion. CrowdStrike then raised its full-year revenue forecast to between $5.99 billion and $6.01 billion. It also lifted its net new ARR growth forecast by 630 basis points.
Kurtz described the demand shift as a “Mythos moment,” referring to Anthropic's Mythos model launch. Reports said the model can exploit previously unknown software flaws.
As a result, Kurtz said AI security had moved higher on enterprise priority lists. He described an “arms race” as AI increases both attack capabilities and security spending.
CrowdStrike's own earlier research had also flagged threats linked to artificial intelligence. The latest results followed Jim Cramer's stock picks naming cybersecurity among key themes for 2026. How much further could cybersecurity spending rise as AI threats grow and state-linked attacks reach critical infrastructure?
Read More: DeepSeek AI Joins the Hacker Toolkit, Making Cyberattacks Faster
The broader security backdrop has also intensified as the conflict involving the United States, Israel and Iran reaches six months. The fighting has disrupted regional infrastructure and energy markets.
At the same time, recent reports linked Iran to July cyberattacks against infrastructure in Britain and the United States. One incident forced a UK power facility offline.
Separate attacks targeted around 30 U.S. water systems, while U.S. officials examined possible Iranian involvement. The incidents increased concern about attacks against infrastructure far from conventional battlefields.Former Department of Homeland Security official Frank Cilluffo described cyber operations as suited to Iran's asymmetric strategy. Such operations can target economic systems and critical infrastructure without matching U.S. conventional military strength.
CrowdStrike's record $332.8 million in net new ARR and higher guidance came as AI-driven cyber risks lifted security demand. Meanwhile, Iran-linked infrastructure attacks added another source of concern, connecting stronger cybersecurity spending with both rapidly developing AI threats and geopolitical risks.