IT Brief US - Technology news for CIOs & IT decision-makers
United States
AI-driven cybercrime surges at scale, Flashpoint warns

AI-driven cybercrime surges at scale, Flashpoint warns

Thu, 13th Aug 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Flashpoint has released its 2026 Global Threat Intelligence Report: Midyear Edition, which says AI-driven cybercrime is now operating at scale.

The findings point to a sharp rise in the use of artificial intelligence by criminal groups for phishing, malware development, exploit creation, and social engineering. Flashpoint tracked more than 22 million illicit discussions involving criminal AI toolkits during the first half of the year, alongside 7.4 million infected hosts that yielded about 1.7 billion stolen credentials.

The report depicts a cybercrime landscape that is becoming more automated and more specialised. It argues that attackers are relying less on conventional network intrusion and more on stolen identities, while ransomware groups continue to expand through affiliate models and lower-cost access to victims.

AI activity

According to the report, threat actors are moving beyond experiments with public tools and increasingly using locally hosted AI models without safeguards. These models are being used to generate phishing emails, malware code, exploit material, and other content intended to support attacks.

This shift reduces dependence on mainstream platforms that may impose restrictions or monitoring. It also allows criminal groups to adapt tools more quickly to specific operations, including attacks targeting cloud services, identity and access management systems, and misconfigured environments.

Josh Lefkowitz, Co-Founder and Chief Executive Officer of Flashpoint, described the pace of change in stark terms. "AI is compressing the time between opportunity and exploitation. Capabilities that once took significant expertise, coordination, and time to develop are becoming faster to build, easier to scale, and harder to detect. Security teams are facing an adversary ecosystem that can use AI to iterate at unprecedented speed - the only way to keep pace is with primary-source intelligence that surfaces adversary behavior before attacks unfold," Lefkowitz said.

Identity focus

One of the report's central themes is the growing value of stolen credentials. Infostealers infected more than 7.4 million hosts globally in the six-month period, harvesting credentials and other identity-related data at scale.

The report argues that these credentials let attackers sign in as legitimate users rather than break into systems through software flaws alone. That approach can help them evade some traditional security measures by blending malicious activity into normal authentication traffic.

For cloud-first organisations, the emphasis on identity over perimeter breaches has particular significance. Businesses that rely on multiple cloud providers and large numbers of user accounts may find that weak credential hygiene, poor access controls, and exposed identity artefacts pose a more immediate risk than some traditional forms of intrusion.

Vulnerabilities

Flashpoint tracked 21,667 disclosed vulnerabilities between January and June, with nearly one in five already linked to public or functional exploit code. The report says this is increasing pressure on security teams that already struggle to prioritise patching and remediation across large software estates.

It concludes that vulnerability management is becoming less about headline severity scores and more about whether flaws can be exploited in practice. That distinction has become more important as AI tools make it easier to refine exploit code and speed testing against likely targets.

The report also notes delays in public vulnerability enrichment and a growing list of known exploited flaws. Together, those factors leave defenders racing to identify which issues pose immediate risk and which can wait.

Ransomware growth

Ransomware remained a major source of disruption in the first half of the year. Flashpoint documented 6,256 verified ransomware victims, a 45% increase from the same period a year earlier.

While fewer organisations are said to be paying ransom demands, the report suggests operators are compensating by increasing the volume of attacks. It links that expansion to mature ransomware-as-a-service structures, in which different actors handle development, access, deployment, and extortion as separate tasks.

Ian Gray, Vice President of Intelligence at Flashpoint, said the figures show how cybercrime has evolved into a service-based market. "The data from the first half of 2026 suggests that cybercrime continues to operate as a service economy, with specialization at every stage. AI developers, infostealer operators, initial access brokers, ransomware affiliates, and fraud actors each contribute capabilities that lower cost, reduce friction, and accelerate downstream operations. Disrupting individual campaigns remains important, but understanding the relationships between these actor ecosystems provides a much stronger indicator of where threats are heading next," Gray said.

Geopolitical risk

Beyond cybercrime, the report highlights the overlap between geopolitical instability and digital attacks. It cites military conflict in the Middle East during the first half of the year as coinciding with coordinated campaigns targeting supply chains, financial institutions, industrial systems, and critical infrastructure.

That overlap reflects a broader challenge for companies whose exposure extends beyond their own networks. Cyber risk can now be shaped by regional conflict, disruption to third-party suppliers, and attacks aimed at strategically important sectors.

Flashpoint's midyear findings suggest organisations face a threat environment in which AI, stolen identities, software flaws, and criminal outsourcing models reinforce one another. The data shows defenders are no longer dealing with isolated trends, but with an interconnected system that is making attacks faster to organise and easier to scale.