Home
News
Tech Grid
Interviews
Anecdotes
Think Stack
Press Releases
Articles
  • Identity & Access ManagementThreat Detection & Incident Response

ThreatDown Report Warns AI Is Accelerating Modern Cybercrime


ThreatDown Report Warns AI Is Accelerating Modern Cybercrime
  • by: Business Wire
  • |
  • July 22, 2026

ThreatDown has released its 2026 Cybercrime in the Age of AI report, highlighting how artificial intelligence is already reshaping cybercrime through openly available AI models, commercial cloud infrastructure, and rapidly expanding shadow AI environments. The research concludes that AI has significantly lowered the barrier to sophisticated cyberattacks, making cybercriminal operations more accessible while creating new challenges for enterprise security teams.

Quick Intel

  • ThreatDown's 2026 report finds AI-powered cybercrime is already mainstream rather than a future threat.
  • Researchers identified 6,644 openly available guardrail-free AI models downloaded over 22 million times in 30 days.
  • Criminal AI services increasingly rely on legitimate cloud providers instead of building their own infrastructure.
  • Nearly half of employees using generative AI at work reportedly use unmanaged personal accounts, increasing shadow AI risks.
  • AI-assisted vulnerability discovery is expected to reach criminal marketplaces within approximately six months.
  • ThreatDown recommends prioritizing patch management, continuous monitoring, and shadow AI governance.

ThreatDown Highlights the Rise of AI-Enabled Cybercrime

ThreatDown's latest cybersecurity report examines how artificial intelligence is transforming the modern threat landscape through publicly accessible AI models, commercial infrastructure, and emerging attack techniques. Rather than focusing on future scenarios, the report argues that AI-powered cybercrime is already operating at scale, requiring organizations to strengthen security strategies immediately.

The research combines ThreatDown's threat intelligence with analysis of publicly available AI models, criminal AI marketplaces, and evolving cyberattack methods to help organizations better understand the growing risks associated with AI-assisted software, identity attacks, and social engineering.

Open AI Models Are Expanding the Cybercrime Landscape

One of the report's primary findings is that many guardrail-free AI models are now openly available through mainstream AI model repositories instead of hidden within dark web communities.

ThreatDown researchers identified 6,644 publicly available AI models labeled with terms such as "uncensored," "abliterated," "decensored," "heretic," and "unfiltered." According to the report, these models accumulated more than 22 million downloads within a single 30-day period.

Unlike cloud-hosted AI services, these downloadable models can operate locally without relying on external providers, limiting opportunities for AI vendors to monitor prompts, suspend accounts, or detect malicious usage. The report suggests this shift significantly reduces defenders' visibility into AI-enabled attacks.

Criminal AI Services Depend on Legitimate Infrastructure

The research also challenges the perception that cybercriminals develop entirely independent AI platforms.

Instead, ThreatDown found that many criminal AI services package or resell capabilities from legitimate frontier AI models while operating on commercial cloud infrastructure. Among the platforms analyzed, services including WormGPT, Kriminal, DadGPT, and Xanthorox were found to rely on infrastructure from established technology providers, illustrating how criminal AI increasingly leverages mainstream cloud ecosystems.

“The criminal AI market doesn’t build its own intelligence. It rents it,” said Kendra Krause, General Manager at ThreatDown. “That changes how defenders need to think about the problem. There isn’t a single criminal supply chain to dismantle or a single platform to shut down. Organizations need visibility into what’s happening inside their own environments, because the infrastructure powering these services increasingly looks like the same infrastructure powering legitimate AI.”

Shadow AI Creates New Enterprise Security Challenges

ThreatDown also warns that organizations are unintentionally expanding their attack surface through widespread adoption of unmanaged AI tools.

The report references research indicating that nearly half of employees using generative AI for work rely on personal accounts outside corporate governance processes, creating shadow AI environments that security teams may be unable to monitor. Researchers also documented malicious AI agent capabilities designed to steal credentials, exfiltrate sensitive information, install malware, and manipulate both AI systems and their users.

As enterprise AI adoption accelerates, attackers are increasingly exploiting employee interest in AI through malicious software, deceptive downloads, and AI-assisted social engineering campaigns.

AI-Driven Vulnerability Discovery Could Accelerate Attacks

Looking ahead, ThreatDown predicts that AI-powered vulnerability discovery capabilities may become available within criminal marketplaces over the next six months.

The report notes recent developments involving AI-assisted vulnerability research and warns that increasingly capable AI models could dramatically increase the speed at which attackers discover and weaponize software vulnerabilities. As a result, organizations may face greater pressure to improve patch management and vulnerability remediation processes.

"The question is no longer whether AI will reshape cybercrime,” said Shawn Dorsey, Sr. Director, Managed Services at ThreatDown. “The transformation is already underway. Organizations that improve visibility into AI use, strengthen identity security and accelerate vulnerability management now will be far better positioned than those waiting for these capabilities to become mainstream.”

ThreatDown Recommends Three Immediate Priorities

To prepare for evolving AI-enabled threats, ThreatDown recommends that organizations focus on three key security priorities over the next six months:

  • Strengthen patch management to keep pace with increasing AI-assisted vulnerability discovery.
  • Maintain continuous 24/7 security monitoring to detect identity attacks and endpoint compromise.
  • Identify and govern shadow AI tools, AI agents, and unmanaged AI connections before they introduce security and compliance risks.

Report Data and Methodology

The report data is taken from samples of threats detected by ThreatDown's Research team, and from ThreatDown threat intelligence research of third-party marketplaces, AI model hubs, repositories, and developer ecosystems. Where the report draws findings from other security researchers, AI developers, or third-party organizations, those sources are cited directly throughout.

The Hugging Face findings come from a complete census of Hugging Face's public model listings, using a script built to be independently reproducible. Researchers queried Hugging Face's public API for models matching one of five terms that unambiguously signal guardrails have been removed: "abliterated," "uncensored," "heretic," "decensored," and "unfiltered," keeping only genuine name matches. A broader set of terms, including general descriptors such as "dolphin" and "nsfw," was tested as a cross-check but excluded from the headline figure because it also captures unrelated general-purpose and adult-content models.

Duplicate uploads of the same model, often re-uploaded under different accounts and file formats, were merged into a single count, reducing 15,865 individual repository uploads to 6,644 distinct models. These labels are self-declared by each model's publisher, reflecting what the models are published as rather than independently tested behavior.

Download figures come directly from Hugging Face's own "downloads last month" metric, a rolling 30-day count captured as of July 4, 2026. The monthly publishing trend referenced elsewhere in the report spans July 2025 through June 2026.

 

About ThreatDown

ThreatDown is a leader in elite Managed Detection and Response (MDR), purpose-built to empower resource-constrained security teams with high-efficacy protection, without the complexity. As attacks grow faster and more automated, ThreatDown pairs proprietary AI and threat research with analyst judgment to deploy in minutes. Recognized by MRG Effitas, AVLab, and G2, ThreatDown scales security operations to intercept sophisticated attacks at the speed of modern threats.

  • CybersecurityAI SecurityThreat IntelligenceIdentity Security
News Disclaimer
  • Share