← All news

general

AI Hasn't Reinvented Hacking, Just Made It Cheaper

2026-06-25

ReliaQuest has spent two years watching the cybercrime underground experiment with AI, and its latest report lands on a conclusion that cuts against most of the noise on the topic: AI hasn't rewritten the attacker playbook. It's just letting attackers run the same plays faster, cheaper, and with less effort.

The progression they describe is straightforward. In 2024, criminals were mostly using AI for housekeeping: tidying up phishing emails, knocking out basic scripts, hawking novelty tools like FraudGPT to anyone who'd buy them. By the middle of 2025, deepfake services and a proper underground market for AI-enabled kit had taken hold. Now, the technology sits much closer to the centre of the offensive workflow.

Two roles, one tempo

In the incidents ReliaQuest reviewed, AI showed up in two distinct roles.

  • Embedded in the attack itself. Generating phishing pages, building web shells and credential harvesters, padding code to slip past static analysis, and smoothing out the language in social-engineering messages so they read like a colleague instead of a stranger.
  • As the bait. Attackers are leaning on the demand for AI tools, and on trust in AI brands, to convince people to install dodgy browser extensions or follow fake setup instructions that look harmless enough at a glance.

The user base is broad and unsurprising. ShinyHunters. North Korean operators. Fraud crews. Extortion gangs. Espionage actors. The common thread, per the report, is that AI consistently lets them achieve more with less. It's being treated as operational infrastructure, bought and tuned and slotted into existing workflows like any other tool.

The shape of the threat hasn't changed

This is the part worth sitting with. Phishing is still phishing. Credential theft is still credential theft. Social engineering still works because a real person believes a real-looking message and clicks a real-looking link. None of that is new.

What's changed is the cost curve. A phishing page that took an attacker an hour to put together in 2022 takes minutes now. A social-engineering pretext that used to require half-decent English from a non-native speaker now reads cleanly in any language the attacker wants. The labour bottleneck that used to slow lower-tier criminals down has been quietly removed.

That means more attempts, hitting more inboxes, sounding more plausible, more often. The hit rate per attempt might not have moved much. The number of attempts very much has.

What actually helps

ReliaQuest's own framing is honest, and worth repeating. Security teams don't need a brand new AI strategy bolted onto everything they already do. They need the fundamentals working: defence in depth, sensible identity controls, patched systems, staff who can spot a dodgy message even when it reads beautifully, and enough automation to keep pace with the new tempo.

The threat hasn't changed shape. It's just moving quicker. The teams that already had their basics in order are in a much better position than the ones who were hoping the basics would never get properly stress-tested.

AI Hasn't Reinvented Hacking, Just Made It Cheaper | RiskSense