Flashpoint: AI Makes Cybercrime Faster and Cheaper

Flashpoint says AI is lowering cybercrime costs and accelerating attack volume as ransomware, credential theft, and exploit activity rise in 2026.

Written By
Luis Millares
Luis Millares
Aug 28, 2026
4 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

AI is reshaping the economics of cybercrime by making attacks faster and cheaper to launch, according to Flashpoint, which found ransomware victims rose 45% in the first half of 2026 as the average underground price of initial access fell 69%, from $1,427 to $439.

The findings, detailed in Flashpoint’s 2026 Global Threat Intelligence Report: Midyear Edition, suggest AI is not necessarily making individual attacks more successful. Instead, it is lowering the time, expertise, and cost required to carry them out, allowing threat actors to target more organizations at greater speed and scale.

For MSPs and MSSPs, that shift raises the stakes around threat intelligence, credential monitoring, vulnerability prioritization, and response as customers face a higher volume of lower-cost attacks.

AI lowers cybercrime costs without guaranteeing success

Flashpoint tracked more than 22 million illicit AI-related discussions, 7.4 million infostealer-infected hosts, and 21,667 vulnerability disclosures over the six-month period. 

Speaking with Channel Insider, Flashpoint analysts said the findings show that threat actors have moved beyond experimentation and now use malicious or jailbroken LLMs in their everyday operations.

“The clearest effect we’re seeing today is scale and speed,” Flashpoint analysts said. “AI is lowering the amount of time, expertise, and money required to perform activities that previously demanded considerably more manual effort.”

Flashpoint also said more threat actors are moving these tools onto locally hosted private infrastructure rather than relying on public underground services. This makes malicious AI activity harder for defenders to observe and detect.

Their research found that these tools are being used to generate phishing content, create malware components and evasion scripts, analyze vulnerabilities, automate target profiling, and support initial access efforts.

Advertisement

Ransomware growth and cheaper access shift attacker economics

Ransomware is one cyberthreat that has been significantly affected by AI’s growing role as an enabler of cybercrime. Flashpoint documented 6,256 verified ransomware victims during the first half of 2026, up 45% from the same period in 2025.

At the same time, the cost of purchasing initial access has dropped significantly.

“Flashpoint observed a 45% increase in ransomware victims in the first half of 2026, while agentic systems are increasingly being used to automate initial access. This enablement via AI has driven the average underground price of sold initial access down by 69%, from $1,427 to $439.”

Lower costs can allow threat actors to launch more campaigns against more targets, even if AI does not substantially increase the success rate of each individual attempt.

Flashpoint analysts said attackers leverage automated tools to continuously identify targets, tailor messages to specific environments, and test stolen credentials across large numbers of VPNs, SaaS applications, and cloud endpoints.

“That doesn’t mean AI, or these AI tools, guarantee attack success,” Flashpoint analysts said. “However, this lower cost does mean attackers now have resources to spare, which enables more attacks, against more targets, while being much faster.”

Stolen credentials and exploit-ready flaws raise pressure

In addition, Flashpoint recorded 7.4 million infostealer-infected hosts during the first half of the year, yielding approximately 1.7 billion stolen credentials and identity artifacts.

The scale of credential exposure provides threat actors with another path into organizations, enabling them to use legitimate credentials to carry out attacks rather than directly breaching network defenses.

“Attackers increasingly don’t need to break through the perimeter when they can acquire legitimate credentials or session data and simply log in,” Flashpoint analysts said.

Flashpoint also tracked 21,667 vulnerability disclosures during the first half of 2026, including 4,015 with publicly available or functional exploit code. 

With nearly one in five disclosed vulnerabilities already accompanied by exploit code, Flashpoint said organizations have less room to rely solely on traditional severity scoring or manual patch prioritization.

Advertisement

The challenge could grow as AI accelerates both vulnerability discovery and exploitation.

“As both vulnerability discovery and exploitation become more automated, organizations will have even less time to rely on traditional manual triage and severity-based patching,” the analysts said.

Security automation still requires human expertise

As AI-enabled threats continue to be leveraged by malicious actors, Flashpoint emphasized that the same technology can also help security providers manage the growing volume of threat data.

Flashpoint analysts said AI can be particularly valuable to MSPs and MSSPs managing multiple customer environments by processing large volumes of intelligence, prioritizing alerts, and automating well-defined response actions.

Despite this, they cautioned against assuming that automation alone will produce better security decisions.

“AI is only as useful as the data, context, and workflows around it. Automating analysis of incomplete or poorly prioritized intelligence can simply allow teams to reach the wrong conclusion faster,” the analysts said.

Providers can automate repetitive, high-volume work while keeping analysts involved in decisions that require context, attribution, judgment, or knowledge of a customer’s specific risk environment.

“More information does not inherently mean better intelligence,” Flashpoint analysts said. “AI can help analysts get to the relevant information faster, but experienced analysts are still essential for turning that information into defensible judgments and action.”

MSPs can turn threat intelligence into customer action

Against this backdrop, Flashpoint said that the increased speed and volume of threats creates a significant opportunity for MSPs to help customers determine which risks actually matter to their environments.

“MSPs and MSSPs have an important opportunity to become the operational bridge between threat intelligence and customer action,” Flashpoint analysts said.

For example, MSPs and MSSPs can help customers identify which vulnerabilities are actively being exploited, rather than treating every high-severity disclosure as equally urgent. They can also monitor exposed credentials and compromised identities before that access is used in a broader attack.

Advertisement

“For security providers, the common thread across these trends is the need to move upstream,” Flashpoint analysts said.

In practice, that means identifying exploitable vulnerabilities, exposed credentials, and other signs of risk early enough for customers to act before attackers can turn them into a broader compromise.

“The organizations best prepared for 2027 will be those that can turn intelligence into action quickly without sacrificing the human judgment needed to determine what matters most,” Flashpoint analysts said.

Luis Millares

Luis Millares has extensive experience reviewing virtual private networks (VPNs), password managers, and other security software. He has tested and reviewed numerous forms of tech, covering consumer technology like smartphones and laptops, all the way to enterprise software and cybersecurity products. He has authored over 450 online articles on technology and has worked for the leading tech journalism site in the Philippines, YugaTech.com. He currently contributes to the Daily Tech Insider newsletter, providing well-researched insights and coverage of the latest in technology.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.