AI Is Moving Deeper Into Cybercrime As Attackers Adopt More Capable Tools
The digital battlefield has shifted. For years, cybersecurity experts warned that artificial intelligence could one day empower cybercriminals. That day has arrived. According to CrowdStrike's 2026 Threat Hunting Report, AI is now embedded across modern adversary operations—functioning simultaneously as a weapon, a target, and a force multiplier for threat actors worldwide.
The numbers are staggering: AI-enabled malicious activity has surged by 89 percent over the past year, with attackers leveraging large language models to generate payloads, craft convincing phishing campaigns, and compress attack timelines from weeks to mere hours.
What makes this shift particularly alarming is how AI is lowering the barrier to entry for cybercrime. Cisco Talos researchers documented real-world examples of threat actors abusing AI systems to build bulk-mail validation services processing tens of millions of email records, adapt critical vulnerabilities into credential-harvesting pipelines, and even develop DDoS infrastructure targeting Android TVs.
Perhaps most concerning, attackers are increasingly bypassing AI guardrails with simple social engineering tactics—claiming "this is authorised testing" or "I'm asking this as part of a capture the flag exercise"—tricks that convince most commercial models to comply.
When censored models refuse, criminals simply switch to uncensored open-weight alternatives like Qwen, Dolphin, and Mistral.
The business impact is already measurable. INTERPOL's African Cyberthreat Assessment Report 2026 found that AI is now linked to 55 percent of reported cybercrimes across the continent, with cybercrime-related losses more than doubling from USD 192 million to USD 484 million since 2024.
East Africa has emerged as a hub for mobile money fraud, while Southern Africa's high connectivity makes it a magnet for global threat actors. The report also revealed that criminals have moved beyond stealing existing credentials to creating entirely synthetic identities using AI—digital personas that can bypass even advanced biometric verification systems.
Perhaps the most sobering development is the emergence of fully autonomous AI agents conducting end-to-end cyber intrusions. In early July 2026, Sysdig's Threat Research Team documented JADEPUFFER, the first ransomware campaign where every phase—from reconnaissance to extortion—was carried out by an LLM-driven agent operating without step-by-step human direction.
The agent moved laterally, encrypted more than 1,300 database records, and demanded a ransom, demonstrating how AI could accelerate ransomware operations at unprecedented scale.
CrowdStrike's OverWatch team also observed that AI agent-triggered detection leads grew at 2.5 times the rate of human-triggered leads, highlighting how automation is overwhelming security teams with volume and velocity.
The implications for businesses and governments are profound. Attackers are now exploiting AI infrastructure, compromising software supply chains, and abusing enterprise LLMs—including one campaign that sent nearly 200,000 AI model requests in just two minutes.
North Korean cybercriminals have poisoned 131 trusted AI framework packages, while Chinese-aligned actors are exploiting critical vulnerabilities within 24 hours of public disclosure.
As CrowdStrike's Adam Meyers put it, "AI is both the weapon and the target". For defenders, the message is clear: the window to respond has collapsed, and organizations must move toward automated remediation, continuous monitoring, and zero-trust architectures to survive this new era of AI-driven cybercrime.

