AI Is Making Cyberattacks Cheaper and Faster to Retry, Researchers Warn
Security researchers say the real shift caused by AI in cybercrime isn't a brand new type of attack, but how cheap and fast it now is to recover from failure. When an attacker's first attempt at breaking into a system fails, tasks that once took hours of manual research and script debugging can now be fixed and retried within minutes with the help of an AI model.
Google's Threat Intelligence Group has tracked this shift over time. In early 2025, it found state-backed hacking groups using generative AI mainly for translation, scripting help, and research. By late 2025, it was seeing malware that contacted an AI model while running, alongside a growing underground market for illicit AI tools. Anthropic separately disclosed shutting down an extortion operation that used AI at nearly every stage, from reconnaissance and credential theft to setting ransom demands. In May 2026, GTIG reported that criminals found a two-factor authentication bypass in an open-source admin tool and built working exploits for it, assessing with high confidence that an AI model helped with both discovery and exploit development. The vendor was notified and the activity disrupted before GTIG believes the exploit was used.
Researchers caution that assessed AI assistance is not the same as confirmed widespread use, and attribution remains difficult. Even so, the overall trend points to AI becoming embedded in attacker workflows, reducing the time, cost, and skill barrier that once slowed down intrusions.