AI is accelerating an established cybercrime economy
AI can help criminals produce phishing emails, malware code and exploit material faster. Its impact also depends on an established service economy that supplies stolen identities, exploitable software flaws and specialist operators.
Flashpoint’s 2026 Global Threat Intelligence Report: Midyear Edition describes these components developing together. Flashpoint is a threat-intelligence vendor and benefits commercially when organizations value intelligence about these connections. Its findings frame a concrete executive question: how quickly can criminals combine stolen access, exploitable flaws and specialist services into an attack?
Stolen identities turn access into an attack service
An infostealer is malware designed to collect credentials and other data from infected systems. Flashpoint reports that infostealers infected more than 7.4 million hosts globally during the first half of 2026, yielding approximately 1.7 billion stolen credentials and other identity-related data.
Those numbers do not mean every credential led to a successful compromise. They show the size of the identity-data pool potentially available to criminals.
Valid credentials can let attackers attempt access through an organization’s normal authentication systems. That puts exposed credentials, authentication controls and access management within the same risk assessment for security leaders.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Exploitability is a vulnerability-prioritization signal
Software vulnerabilities provide another input. Flashpoint tracked 21,667 disclosed vulnerabilities between January and June 2026. Nearly one in five was already associated with public or functional exploit code.
A security team managing a large software estate has to prioritize remediation. Severity is one signal. Evidence of working exploit code is another because it shows that a disclosed flaw can be put into practice.
Flashpoint says AI tools can help threat actors generate and refine exploit material and speed testing against potential targets. It also points to delays in public vulnerability enrichment and a growing list of known exploited flaws. As a threat-intelligence vendor, Flashpoint has a commercial interest in the value organizations place on timely exploitability intelligence.
The evidence supports a limited causal claim. AI can assist exploit development and testing, but these findings do not establish how much of any observed increase in exploitation was caused by AI.
Specialization turns capabilities into scale
The connection between these developments is economic. Specialists can supply different stages of a criminal operation.
Ian Gray, Vice President of Intelligence at Flashpoint, describes cybercrime as a service economy with “specialization at every stage.” He identifies AI developers, infostealer operators, initial access brokers, ransomware affiliates and fraud actors as contributors whose services can “lower cost, reduce friction, and accelerate downstream operations.” Flashpoint sells intelligence about these criminal ecosystems, so it benefits commercially when organizations value an understanding of those relationships.
An initial access broker is a criminal who obtains access to victim systems and supplies it to other actors. A ransomware affiliate deploys ransomware in a shared criminal business model. Fraud actors can use compromised accounts and identity material. These roles let participants specialize instead of building every capability themselves.
Flashpoint says AI can help generate phishing content, malware code and exploit material. It also reports a shift toward locally hosted AI models without the safeguards or monitoring that mainstream platforms may impose. According to Flashpoint, criminal groups can use these models to refine material for operations involving cloud services, identity and access management systems and misconfigured environments.
Josh Lefkowitz, Co-Founder and Chief Executive Officer of Flashpoint, says, “AI is compressing the time between opportunity and exploitation.” He argues that capabilities requiring substantial expertise, coordination and development time can become faster to build and easier to scale. Lefkowitz leads a company that sells threat intelligence and therefore has a commercial stake in how organizations assess these developments.
Ransomware shows the scale Flashpoint observes in the surrounding service economy. Flashpoint documented 6,256 verified ransomware victims in the first half of 2026, up 45% from the same period a year earlier. Flashpoint says fewer organizations are paying ransom demands and suggests operators are compensating by increasing attack volume through mature ransomware-as-a-service structures. Ransomware-as-a-service is a model in which participants divide functions such as development, access, deployment and extortion.
That increase does not demonstrate that AI caused ransomware growth. The narrower conclusion supported by Flashpoint’s findings is that AI tools are entering an ecosystem where specialized actors already supply capabilities to one another.
Flashpoint also cites military conflict in the Middle East during the first half of the year alongside coordinated campaigns against supply chains, financial institutions, industrial systems and critical infrastructure. These examples broaden the range of external actor activity executives may need to consider when assessing exposure.
Defense has to follow the connections
The management question is whether security priorities reflect the interaction among identities, vulnerabilities and criminal services.
For CISOs and technology leaders, practical questions follow. Can the organization detect suspicious use of credentials? Does vulnerability prioritization include observed exploitability alongside severity? Does threat intelligence about access markets and specialized criminal ecosystems inform decisions about identity, cloud environments and remediation?
These signals can change priorities. Working exploit code shows that a vulnerability can be put into practice. Intelligence that an organization’s credentials are circulating can add context to authentication activity, while intelligence about initial access brokers can indicate that compromised access is being supplied to other criminals.
Gray argues that understanding relationships between actor ecosystems can provide stronger indications of where threats are heading, while disruption of individual campaigns remains important. This is Flashpoint’s assessment of how threat intelligence should be used, and the company benefits commercially from demand for that capability. For executives, the operational decision is whether defenders have enough context to assess access, exploitability and adversary activity together when setting priorities.
Key highlights
- Stolen identities turn access into an attack service: Flashpoint reports 1.7 billion stolen credentials and other identity-related data from infostealer infections in the first half of 2026. Leaders should assess credential exposure, authentication controls and access management as connected risks.
- Exploitability is a vulnerability-prioritization signal: Nearly one in five vulnerabilities tracked by Flashpoint had public or functional exploit code. Security teams should consider evidence of exploitability alongside severity when setting remediation priorities.
- Specialization turns capabilities into scale: AI can speed phishing, malware development and exploit testing within an existing market of access brokers, ransomware affiliates and other specialists. Leaders should assess AI-enabled threats in the context of the broader criminal service economy rather than as a standalone risk.
- Defense has to follow the connections: Identity exposure, exploitable vulnerabilities and criminal services can combine into the same attack chain. CISOs should connect intelligence across credentials, vulnerabilities and adversary activity when setting defensive priorities.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


