AI is reshaping the economics of cybercrime by making attacks faster and cheaper to launch, according to Flashpoint, which found ransomware victims rose 45% in the first half of 2026 as the average underground price of initial access fell 69%, from $1,427 to $439.
The findings, detailed in Flashpoint’s 2026 Global Threat Intelligence Report: Midyear Edition, suggest AI is not necessarily making individual attacks more successful. Instead, it is lowering the time, expertise, and cost required to carry them out, allowing threat actors to target more organizations at greater speed and scale.
For MSPs and MSSPs, that shift raises the stakes around threat intelligence, credential monitoring, vulnerability prioritization, and response as customers face a higher volume of lower-cost attacks.
AI lowers cybercrime costs without guaranteeing success
Flashpoint tracked more than 22 million illicit AI-related discussions, 7.4 million infostealer-infected hosts, and 21,667 vulnerability disclosures over the six-month period.
Speaking with Channel Insider, Flashpoint analysts said the findings show that threat actors have moved beyond experimentation and now use malicious or jailbroken LLMs in their everyday operations.
“The clearest effect we’re seeing today is scale and speed,” Flashpoint analysts said. “AI is lowering the amount of time, expertise, and money required to perform activities that previously demanded considerably more manual effort.”
Flashpoint also said more threat actors are moving these tools onto locally hosted private infrastructure rather than relying on public underground services. This makes malicious AI activity harder for defenders to observe and detect.
Their research found that these tools are being used to generate phishing content, create malware components and evasion scripts, analyze vulnerabilities, automate target profiling, and support initial access efforts.
Ransomware growth and cheaper access shift attacker economics
Ransomware is one cyberthreat that has been significantly affected by AI’s growing role as an enabler of cybercrime. Flashpoint documented 6,256 verified ransomware victims during the first half of 2026, up 45% from the same period in 2025.
At the same time, the cost of purchasing initial access has dropped significantly.
“Flashpoint observed a 45% increase in ransomware victims in the first half of 2026, while agentic systems are increasingly being used to automate initial access. This enablement via AI has driven the average underground price of sold initial access down by 69%, from $1,427 to $439.”
Lower costs can allow threat actors to launch more campaigns against more targets, even if AI does not substantially increase the success rate of each individual attempt.
Flashpoint analysts said attackers leverage automated tools to continuously identify targets, tailor messages to specific environments, and test stolen credentials across large numbers of VPNs, SaaS applications, and cloud endpoints.
“That doesn’t mean AI, or these AI tools, guarantee attack success,” Flashpoint analysts said. “However, this lower cost does mean attackers now have resources to spare, which enables more attacks, against more targets, while being much faster.”
Stolen credentials and exploit-ready flaws raise pressure
In addition, Flashpoint recorded 7.4 million infostealer-infected hosts during the first half of the year, yielding approximately 1.7 billion stolen credentials and identity artifacts.
The scale of credential exposure provides threat actors with another path into organizations, enabling them to use legitimate credentials to carry out attacks rather than directly breaching network defenses.
“Attackers increasingly don’t need to break through the perimeter when they can acquire legitimate credentials or session data and simply log in,” Flashpoint analysts said.
Flashpoint also tracked 21,667 vulnerability disclosures during the first half of 2026, including 4,015 with publicly available or functional exploit code.
With nearly one in five disclosed vulnerabilities already accompanied by exploit code, Flashpoint said organizations have less room to rely solely on traditional severity scoring or manual patch prioritization.
The challenge could grow as AI accelerates both vulnerability discovery and exploitation.
“As both vulnerability discovery and exploitation become more automated, organizations will have even less time to rely on traditional manual triage and severity-based patching,” the analysts said.
Security automation still requires human expertise
As AI-enabled threats continue to be leveraged by malicious actors, Flashpoint emphasized that the same technology can also help security providers manage the growing volume of threat data.
Flashpoint analysts said AI can be particularly valuable to MSPs and MSSPs managing multiple customer environments by processing large volumes of intelligence, prioritizing alerts, and automating well-defined response actions.
Despite this, they cautioned against assuming that automation alone will produce better security decisions.
“AI is only as useful as the data, context, and workflows around it. Automating analysis of incomplete or poorly prioritized intelligence can simply allow teams to reach the wrong conclusion faster,” the analysts said.
Providers can automate repetitive, high-volume work while keeping analysts involved in decisions that require context, attribution, judgment, or knowledge of a customer’s specific risk environment.
“More information does not inherently mean better intelligence,” Flashpoint analysts said. “AI can help analysts get to the relevant information faster, but experienced analysts are still essential for turning that information into defensible judgments and action.”
MSPs can turn threat intelligence into customer action
Against this backdrop, Flashpoint said that the increased speed and volume of threats creates a significant opportunity for MSPs to help customers determine which risks actually matter to their environments.
“MSPs and MSSPs have an important opportunity to become the operational bridge between threat intelligence and customer action,” Flashpoint analysts said.
For example, MSPs and MSSPs can help customers identify which vulnerabilities are actively being exploited, rather than treating every high-severity disclosure as equally urgent. They can also monitor exposed credentials and compromised identities before that access is used in a broader attack.
“For security providers, the common thread across these trends is the need to move upstream,” Flashpoint analysts said.
In practice, that means identifying exploitable vulnerabilities, exposed credentials, and other signs of risk early enough for customers to act before attackers can turn them into a broader compromise.
“The organizations best prepared for 2027 will be those that can turn intelligence into action quickly without sacrificing the human judgment needed to determine what matters most,” Flashpoint analysts said.





