News
AI Is No Longer Just Helping Hackers. It's Running Parts of the Attack
Artificial intelligence is changing the economics of cybercrime. For years, security researchers warned that attackers would use AI to improve existing techniques. But according to Check Point Research’s “AI Security Report 2026,” published in July, the threat landscape has entered a new phase: AI is no longer just helping attackers; it is beginning to operate inside real-world attacks.
The report describes a shift from AI as a force multiplier to AI as an active component of cyber operations. It documents intrusions in which AI autonomously ran exploitation workflows, generating thousands of commands across dozens of sessions with minimal human direction.
The change matters because it lowers the expertise barrier that traditionally separated advanced attackers from less-skilled criminals. “AI has crossed into the live attack chain,” the report states.
The researchers found that AI is now appearing across multiple stages of cyberattacks, including social engineering, malware development, vulnerability research, attacker tool creation, and live intrusion support. The techniques themselves are often familiar. What has changed is the speed and scale at which attackers can execute them.
AI Is Compressing the Cyber Skills Gap
One of the report’s most significant findings is that AI is putting sophisticated cyber capabilities within reach of a much wider range of attackers. The researchers said the attackers creating the greatest risks are not necessarily those with the most advanced tools. Instead, the greatest threat comes from groups that can successfully orchestrate AI across multiple stages of an attack.
The report cited a ransomware-as-a-service group known as “The Gentlemen” as an example of how cybercriminals are experimenting with AI. Researchers found that the group used AI to help build its “Glocker” management tool in just three days.
The report also noted an important limitation: AI can accelerate attackers, but human understanding still plays a role. One member of the group warned others that “you still need to understand what you are doing,” showing that AI improves attackers’ capabilities but does not eliminate the need for expertise.
How Attackers Are Accessing AI Capabilities
Check Point identified three main ways attackers are gaining access to AI capabilities. The most common approach is abusing commercial AI models. Attackers are using widely available tools and attempting to bypass safety controls by breaking malicious requests into smaller, less obvious steps.
The report said attackers are increasingly choosing mainstream AI platforms because they are more capable and accessible than underground alternatives.
Another growing risk is the theft of AI credentials. Check Point highlighted the rise of “LLMjacking,” in which criminals use stolen account credentials to access commercial AI services. The report said one campaign, known as Bissa Scanner, stole AI login details from more than 30,000 exposed configuration files.
The third approach involves self-hosted open-source models. While these models allow attackers to avoid provider safety controls and logging, the cybersecurity company said many attackers have found them less capable and more difficult to operate than commercial AI tools.
AI Creates a New Security Challenge for Enterprises
The report also highlights a challenge for organizations adopting AI internally. As businesses deploy more AI applications, they are creating new potential attack surfaces.
Check Point identified risks involving AI models, infrastructure, and applications, while warning that security practices have not always kept pace with adoption. The same AI capabilities that help businesses automate tasks and improve productivity can also introduce new risks if they are poorly secured.
For security teams, the challenge is becoming two-sided. They must defend against attackers using AI while also securing the AI systems their own organizations rely on.
The Next AI Cybersecurity Battle
The rise of AI-powered attacks signals a broader shift in cybersecurity. The question is no longer whether attackers will use AI. According to the report, that transition has already happened.
As Check Point concludes in its report, the incidents observed over the past year represent “a record of what already happened, setting the stage of what’s expected to come.” The next challenge will be whether defenders can adapt quickly enough as AI becomes more deeply embedded in cyber operations.