
New research reveals how AI is rewiring cybercrime today, and how you can prepare for what’s coming tomorrow.
In early 2026, an attacker with no background in industrial control systems set their sights on a municipal water utility’s control systems in Monterrey, Mexico. They didn’t find the target themself. While they directed Claude through a broader reconnaissance operation, it identified the utility’s control interface without being asked, correctly flagged it as critical infrastructure, and recommended a targeted attack against it.
The attack ultimately failed, but it shouldn’t have gotten that far. It’s one thread in a much larger report we’re publishing today: Cybercrime in the age of AI.

Last year, we said this was coming—this year, it’s arrived. Three findings that prove it:
1. Criminals use the same frontier models as you. Some of the most active malicious AI tools now operate like ordinary software companies: pricing pages, login buttons, and checkout flows, all indexed by Google and available on the clearnet. When our researchers traced the infrastructure underneath them, a pattern emerged: these tools don’t build their own intelligence. They rent it, from providers already sitting on your own vendor list.


2. Malicious AI is moving offline. In July 2026, our researchers found over 6,000 models published openly on Hugging Face under self-declared guardrail-free labels: “abliterated,” “uncensored,” “heretic,” “decensored,” and “unfiltered,” implying they no longer refuse unsafe or harmful requests. These models were downloaded more than 22 million times in a single 30-day window, and run locally, they leave nothing to monitor, log, intercept, or restrict.

3. In April, a frontier AI model proved so good at finding vulnerabilities that its maker held it back rather than releasing it broadly. It’s exactly the kind of capability our report tracks moving toward criminal marketplaces next.
That’s what AI-powered cybercrime looks like today. What comes next is where it gets uncertain: the gap between organizations that are ready and organizations that aren’t is widening. There’s six months left to close it, and the clock favors the ones who move.
The full findings are live now. Read the report, then ask yourself the question we asked ourselves:
Which side of that six-month gap is your organization actually on?



























