Executive Overview
For the better part of a decade, the global cybersecurity community lived in the shadow of a hypothetical threat. Security researchers, intelligence analysts, and defense contractors routinely warned that the proliferation of generative artificial intelligence and large language models (LLMs) would eventually give rise to a new breed of automated cybercrime. The standard industry narrative framed AI as an impending storm—a force multiplier that would eventually allow threat actors to scale phishing campaigns, optimize exploit payloads, and synthesize malicious code with unprecedented velocity.
That hypothetical future has officially arrived, and it has materialized faster and more aggressively than many anticipated.
According to Check Point Research’s landmark "AI Security Report 2026," the threat landscape has crossed a critical and irreversible threshold: artificial intelligence is no longer merely a preparatory tool used in the background; it is now actively operating inside real-world attack chains. The report documents a fundamental shift in how threat actors leverage technology, moving away from AI as a passive brainstorming assistant and toward AI as an autonomous, operational component of active cyber intrusions.
In documented cases analyzed by Check Point, artificial intelligence models have autonomously managed end-to-end exploitation workflows, generating thousands of hyper-specific terminal commands across dozens of concurrent sessions with minimal human intervention. This evolution fundamentally alters the economics of cybercrime. By bridging technical capability gaps, AI has radically compressed the cyber skills gap, allowing lower-skilled threat actors and emerging syndicates to execute operations that were previously the exclusive domain of sophisticated Advanced Persistent Threat (APT) groups.
For enterprise security teams, this shift inaugurates a complex, multi-front war. Defenders are no longer simply tasked with patching known vulnerabilities or thwarting conventional phishing attempts; they must now outpace an adversary capable of iterative, machine-speed problem-solving. Compounding this challenge, as organizations race to integrate AI into their own operational infrastructure, they are inadvertently expanding their attack surfaces, creating a dual-front dilemma where security teams must simultaneously defend against AI-powered threats while securing the very AI models their enterprises rely upon.
Detailed Chronology: The Evolution to Autonomous Operations
To understand the gravity of the 2026 findings, it is necessary to examine the evolutionary trajectory of AI in the underground economy. The transition from theory to operational reality did not happen overnight; it represents a methodical, step-by-step adoption curve by cybercriminal ecosystems.
Phase 1: The Administrative Assistant Era (2023–2024)
In the immediate aftermath of the widespread commercial availability of generative AI, threat actors primarily used foundational models for administrative and linguistic support. Early iterations of underground cybercrime tooling relied on LLMs to draft convincing spear-phishing emails, translate malicious documentation, and assist with basic script debugging. While this lowered language barriers and increased the volume of social engineering campaigns, the AI remained firmly outside the technical execution phase. Humans retained complete control over the attack chain, utilizing AI merely as a sophisticated dictionary or grammar checker.

Phase 2: The Scripting and Prototyping Wave (2024–2025)
As safety guardrails on commercial platforms faced relentless probing, underground actors began developing specialized, fine-tuned models—often marketed on dark web forums as "WormGPT," "FraudGPT," or unmoderated wrappers—to assist with malware development and vulnerability research. During this phase, AI served as a rapid prototyping engine. Attackers used models to write bespoke ransomware droppers, obfuscate malicious code, and query vulnerabilities in open-source software libraries. However, execution remained largely manual; attackers would generate a script via AI, review it, and manually deploy it into a target environment.
Phase 3: The Live Attack Chain Integration (2025–Present)
The findings detailed in Check Point Research’s 2026 report mark the culmination of this trajectory: the integration of AI directly into the live attack chain. Rather than generating a static piece of code to be deployed manually, threat actors are now embedding AI frameworks directly into their operational command-and-control infrastructure.
The report documents intrusions where autonomous or semi-autonomous AI loops were deployed during active engagements. In these scenarios, the AI model receives real-time feedback from the target environment—such as error messages from a failed exploit or the output of a network enumeration scan—and dynamically adjusts its next move. The model generates, tests, and refines thousands of iterative commands across multiple concurrent sessions in real time. This closed-loop interaction between the attacker’s AI and the victim’s infrastructure reduces human latency to near-zero, enabling attacks to unfold at machine speed.
Compressing the Cyber Skills Gap: Case Studies in AI-Driven Crime
One of the most profound conclusions of the Check Point Research report is that the democratization of advanced cyber capabilities has fundamentally shifted the profile of high-risk threat actors. Historically, the greatest enterprise risk emanated from elite, state-sponsored APT groups possessing deep technical resources, specialized tool development teams, and years of collective expertise.
Today, the democratization of AI means that operational sophistication is no longer gated by deep technical knowledge. The most acute threats are increasingly originating from agile, non-traditional cybercriminal syndicates that know how to orchestrate AI models across multiple distinct phases of the attack lifecycle—from initial reconnaissance and social engineering to malware compilation, lateral movement, and final extortion.
The Rise of "The Gentlemen" and the Glocker Tool
To illustrate this paradigm shift, Check Point highlighted the operations of an emerging ransomware-as-a-service (RaaS) collective known in intelligence circles as "The Gentlemen." This group serves as a prime case study in the rapid, experimental deployment of AI-generated enterprise tooling within the underground economy.
According to the research, The Gentlemen successfully leveraged artificial intelligence to architect, write, and refine their proprietary ransomware management platform, ominously dubbed "Glocker," in a staggering three days. For traditional software development teams, conceptualizing, building, testing, and deploying a functional, multi-threaded management dashboard and encryption utility would typically require weeks or months of concerted engineering effort. By utilizing commercial AI capabilities as an interactive development partner, the RaaS group compressed this software development lifecycle into a single long weekend.

The Human Element: Limitations and Caveats
Despite the alarming speed at which AI can accelerate malicious development, Check Point’s findings offer a vital nuance: artificial intelligence remains an accelerator, not a total replacement for human comprehension.
In intercepted communications analyzed by the researchers, a member of The Gentlemen issued a cautionary note to fellow syndicate members regarding the uncritical reliance on automated outputs. The criminal explicitly warned that "you still need to understand what you are doing," underscoring the reality that while AI can rapidly generate code and suggest attack vectors, diagnosing complex enterprise network architectures, bypassing sophisticated endpoint detection and response (EDR) solutions, and orchestrating a successful extortion campaign still requires underlying human strategic oversight. AI expands an attacker’s capabilities and lowers the barrier to entry, but it does not completely eliminate the requirement for tactical competence.
How Attackers Access AI Capabilities: The Three Vectors
As cybersecurity defenses harden around specialized underground models, threat actors have increasingly pivoted toward mainstream commercial platforms and illicit access methods to fuel their operations. Check Point Research identified three primary vectors through which cybercriminals currently source their artificial intelligence capabilities.
1. The Abuse of Commercial AI Models
Counterintuitively, the most prevalent approach utilized by cybercriminals does not involve dark web forums or unmoderated underground LLMs. Instead, attackers are heavily relying on widely available, mainstream commercial AI platforms.
Mainstream models boast superior processing capabilities, greater context windows, and higher coding proficiency than their underground alternatives. To exploit these commercial tools without triggering built-in safety filters and automated content moderators, attackers employ sophisticated evasion techniques. They systematically break down malicious requests—such as requests to write a keylogger or design an obfuscation routine—into granular, seemingly benign steps. By cloaking malicious intent across a series of abstracted prompts, attackers successfully coax commercial models into providing actionable exploitation material.
2. The Rise of "LLMjacking" and Credential Theft
As commercial AI APIs and premium enterprise accounts become central to cybercriminal workflows, a lucrative secondary market has emerged around the theft of AI access credentials—a phenomenon dubbed "LLMjacking."
Instead of paying for enterprise subscriptions or struggling with restricted free tiers, criminals are actively hunting for leaked API keys and compromised login credentials that grant direct access to high-end commercial AI services. Check Point’s research drew specific attention to a widespread campaign tracked as "Bissa Scanner," which systematically harvested AI login details and API credentials from more than 30,000 publicly exposed configuration files. Once acquired, these stolen credentials allow threat actors to commandeer legitimate commercial AI infrastructure, leveraging enterprise-grade computational power and advanced model capabilities entirely on someone else’s dime—and under the radar of traditional security monitoring.

3. Self-Hosted Open-Source Models
The third vector involves the deployment of self-hosted open-source models (such as various open weights architectures). Proponents of this approach within the cybercrime underground value the absolute autonomy it provides: by hosting models locally or on rogue bulletproof hosting infrastructure, attackers completely bypass provider safety controls, logging mechanisms, and telemetry collection.
However, Check Point noted a significant trade-off that has limited the widespread adoption of this method. Many self-hosted open-source models remain demonstrably less capable, harder to fine-tune, and significantly more resource-intensive to operate than the polished, state-of-the-art commercial tools maintained by major technology firms. Consequently, while open-source models offer privacy from prying corporate eyes, many threat actors still prefer the high performance of commercial APIs obtained via illicit means.
Enterprise Vulnerabilities: Creating a New Attack Surface
The Check Point AI Security Report 2026 makes it clear that the arrival of AI in the threat landscape is not merely an external challenge for security teams; it is an internal structural vulnerability for organizations worldwide.
As enterprises across every vertical race to deploy generative AI applications, automate internal workflows, and integrate LLMs into core business operations, they are inadvertently manufacturing an entirely new class of attack surfaces. Check Point identified widening security gaps across three critical layers of enterprise AI integration:
- Underlying AI Models: Vulnerabilities stemming from prompt injection, training data poisoning, and model inversion attacks.
- Supporting Infrastructure: Insecure API endpoints, misconfigured cloud environments, and lax identity and access management (IAM) policies governing AI pipelines.
- Application Layer: Poorly secured user-facing chat interfaces and custom agentic workflows capable of executing arbitrary code or querying sensitive internal databases without adequate authorization.
The report warns that corporate security practices have consistently failed to keep pace with the velocity of AI adoption. The exact same transformative capabilities that empower businesses to automate customer service, streamline data analysis, and accelerate software development can be turned inward against the organization if proper guardrails are absent.
For Chief Information Security Officers (CISOs) and security operations center (SOC) teams, the modern threat paradigm is unequivocally two-sided. Organizations can no longer afford to isolate their AI strategy from their security strategy. Security teams must simultaneously mount an active defense against external, AI-powered adversaries while securing the vulnerable, internally deployed AI systems that their own organizations rely upon for competitive advantage.
Future Outlook: The Next AI Cybersecurity Battle
The integration of artificial intelligence into the live cyber attack chain signals an irreversible philosophical shift in the digital security landscape. For years, the core debate centered on whether threat actors would adopt AI at scale. As Check Point Research’s findings demonstrate, that debate is over. The transition has already occurred, and the digital ecosystem is now living with the consequences.

As the report’s concluding assessment notes, the documented intrusions and campaigns observed over the past year do not represent an anomalous spike; rather, they serve as "a record of what already happened, setting the stage of what’s expected to come." The historical record of low-complexity, human-driven cyberattacks is rapidly giving way to an era of automated, high-velocity, machine-speed intrusion workflows.
The defining question for the cybersecurity industry over the next decade will not be technological capacity, but adaptive velocity. Can defenders evolve their architectures, deploy proactive AI-driven countermeasures, and automate their own incident response lifecycles quickly enough to outpace adversaries who are leveraging machine speed to compromise enterprise networks?
If the findings of the AI Security Report 2026 serve as any indication, the window for adaptation is narrowing, and the next phase of the cybersecurity battle has already begun.
The complete "AI Security Report 2026" is available for review on the official Check Point Research engagement portal (institutional registration required).
