AI-powered cybercrime tools explode, lowering barriers for low-skill attackers
Artificial intelligence is driving a surge in cheap, easy-to-use cybercrime tools, enabling less-skilled actors to launch phishing, identity fraud and malware attacks at scale.
A US-based study of underground cybercrime channels tracked nearly 4,000 posts between October 2025 and May 2026, revealing a rapid rise in AI-based tools as advertisements grew from fewer than 50 monthly posts to over 1,400 by February 2026. The market now mirrors legitimate software businesses, offering subscriptions, free tiers, automated storefronts and multi-platform distribution. Researchers grouped the offerings into weaponized large-language models, AI-enabled identity fraud, AI-assisted malware infrastructure, and stolen or jailbroken AI services, dramatically lowering the skill barrier for attackers.
Prominent services include an AI-powered call-center capable of 120 concurrent calls in 25 languages and deep-fake voice tools that have led to losses of $499,000 and $25 million in separate incidents. Vendors also sell deep-fake video, synthetic documents and tools to bypass bank verification checks, while stolen ChatGPT accounts trade for as little as $0.10. Although fully autonomous AI attacks are not yet on sale, experts warn such capabilities are likely to appear soon, prompting a shift toward behavior-based verification and out-of-band confirmation for sensitive requests.
Why it matters
AI makes cyber attacks cheaper and easier, raising the threat level for businesses and individuals worldwide.
In this story
