For years, cybersecurity professionals warned that malicious actors would eventually leverage artificial intelligence to refine existing cybercrime methodologies, automate tedious reconnaissance tasks, and scale phishing operations. However, the publication of the Check Point Research "AI Security Report 2026" indicates that this hypothetical future has fully arrived. The global threat landscape has entered a critical new phase where artificial intelligence is no longer merely an assistive utility operating on the periphery of cybercrime; it is actively embedded inside live, real-world attack chains.
This monumental shift transforms artificial intelligence from a passive force multiplier into an autonomous component of cyber operations. Documented intrusions reveal instances where AI systems independently orchestrated complex exploitation workflows, generating thousands of malicious commands across dozens of distinct operational sessions with only minimal oversight or direction from human handlers. This evolution fundamentally alters the economics of cybercrime. By democratizing sophisticated capabilities, AI drastically lowers the technical barrier that has historically separated elite, state-sponsored Advanced Persistent Threat (APT) groups from low-skill, opportunistic cybercriminals. As the research explicitly concludes, artificial intelligence has definitively crossed into the live attack chain.
The Evolution from Force Multiplier to Active Operator
To understand the gravity of this shift, one must examine how threat actors have historically integrated technology into their operations. In the early stages of generative AI adoption, cybercriminals primarily used large language models (LLMs) as advanced search engines or translation services to draft convincing spear-phishing emails devoid of grammatical errors. Over time, criminal proficiency grew, leading to the rapid generation of basic scripts and malware scaffolding.

The 2026 report marks a stark departure from these historical trends. Check Point researchers observed AI models participating directly in multiple phases of the cyberattack lifecycle, encompassing advanced social engineering, customized malware development, zero-day vulnerability research, proprietary attacker tool creation, and real-time intrusion support. While the fundamental attack techniques—such as credential dumping, lateral movement, and privilege escalation—remain familiar to seasoned blue teams, the velocity, scale, and precision with which modern attackers execute these strategies have scaled exponentially.
This compression of the cyber skills gap poses unprecedented challenges for enterprise security teams. The most dangerous threat actors are no longer exclusively those possessing hyper-specialized programming expertise, but rather agile criminal syndicates that successfully orchestrate AI tools across a multi-stage attack lifecycle, maximizing efficiency while minimizing operational exposure.
Case Studies in AI-Driven Cybercrime
Concrete evidence of this operational shift is visible in recent criminal experiments. The Check Point report highlights a prominent ransomware-as-a-service (RaaS) collective known within the threat intelligence community as "The Gentlemen." This group demonstrated the terrifying speed of AI-assisted development by leveraging artificial intelligence to architect and deploy their proprietary "Glocker" management tool in a staggering three-day window—a feat that traditionally would have required weeks or months of collaborative software engineering by a dedicated team.
Despite these alarming advancements, the research also uncovers critical limitations inherent in current artificial intelligence technologies. AI accelerates the operational tempo of cyberattacks, but it does not completely eradicate the necessity of human oversight and fundamental technical comprehension. During monitoring of "The Gentlemen," researchers intercepted internal communications where a group member explicitly cautioned associates that "you still need to understand what you are doing." This caveat underscores a vital reality: while artificial intelligence supercharges a criminal’s capabilities and bridges knowledge gaps, human judgment remains necessary to navigate complex, unpredictable corporate defense systems and troubleshoot unforeseen technical failures in real time.

How Threat Actors Access AI Capabilities
As the reliance on artificial intelligence deepens, threat actors are deploying diverse strategies to secure access to advanced computing power and proprietary models. Check Point’s intelligence outlines three primary avenues through which cybercriminals obtain these capabilities.
The most prevalent methodology involves the systematic abuse of commercial AI models. Rather than relying on specialized underground models, mainstream threat groups increasingly prefer established, commercially available platforms due to their superior analytical capacity, processing speed, and user-friendly interfaces. To bypass the robust safety guardrails embedded by commercial providers, malicious actors employ sophisticated prompt-engineering techniques, such as chain-of-thought splitting, where complex, inherently malicious requests are fragmented into benign, incremental steps that elude automated security filters.
Simultaneously, the cybersecurity community has recorded a dangerous surge in credential theft targeting AI services, a phenomenon security analysts have dubbed "LLMjacking." In one notable campaign cataloged as the Bissa Scanner, threat actors systematically harvested AI platform login credentials from more than 30,000 publicly exposed and misconfigured configuration files. This unauthorized access allows criminals to piggyback on legitimate corporate accounts, utilizing enterprise-grade AI infrastructure to execute malicious computational tasks at scale while hiding behind legitimate billing profiles.
Finally, a subset of cybercriminals continues to utilize self-hosted, open-source models. While these decentralized models offer the distinct advantage of evading centralized provider safety guardrails, logging, and monitoring, they present significant operational hurdles. Many threat actors find open-source alternatives comparatively cumbersome, less capable, and far more resource-intensive to operate than their commercial counterparts, prompting most sophisticated groups to favor commercial exploitation or credential theft.

The Emerging Enterprise Security Dilemma
The proliferation of artificial intelligence within the threat landscape introduces a complex, dual-sided challenge for modern enterprises. Organizations are rapidly integrating AI applications into their internal operations to automate workflows, accelerate software development, and drive business intelligence. However, this aggressive adoption frequently outpaces corporate security governance, inadvertently expanding the organizational attack surface.
Check Point’s findings highlight vulnerabilities spanning AI models, underlying cloud infrastructure, and user-facing applications. When enterprises deploy poorly secured AI models, they risk exposing proprietary data, enabling indirect prompt injection attacks, or creating pathways for lateral movement within corporate networks. Consequently, modern security teams face a daunting mandate: they must simultaneously defend their perimeter against sophisticated, AI-enhanced adversaries while rigorously hardening the internal AI systems their own enterprises rely upon for daily operations.
Implications for the Future of Cybersecurity
The transition of artificial intelligence from a theoretical research concern to an active component of the live attack chain signals a permanent structural transformation in the cybersecurity domain. The foundational question of whether threat actors would adopt artificial intelligence is now entirely moot; that transition has already occurred and is actively reshaping global incident response metrics.
As Check Point Research observes in its concluding analysis, the sophisticated intrusions documented over the past year serve not as isolated anomalies, but as a historical baseline setting the stage for an increasingly automated threat landscape. The ultimate test for the global cybersecurity industry will be whether defenders—bolstered by automated detection systems, proactive threat intelligence, and AI-driven security orchestration—can adapt swiftly enough to outpace adversaries who are weaponizing the very same technological advancements.




