Key Takeaways
- AI has shifted from a preparatory aid to an active operator in live cyber‑attacks, conducting hands‑on work inside intrusions.
- Modern attackers use AI to generate ready‑to‑deploy malware and complex offensive frameworks in days rather than weeks or months.
- Commercial language models are the preferred tool; threat actors exploit their agentic architectures via persistent jailbreak configuration files rather than relying on single‑shot prompts.
- A maturing criminal marketplace now offers AI‑enhanced phishing‑as‑a‑service kits and voice‑agent vishing services that operate at scale.
- Synthetic media—voice, face, documents, live video—has become cheap and convincing, eroding virtual identity as a reliable trust anchor in multi‑channel social engineering.
- The AI stack itself expands the attack surface: models can blur data and instruction boundaries, while surrounding software and supply‑chain components introduce traditional vulnerabilities.
- Indirect prompt injection is rising sharply, with longer malicious payloads increasing roughly fivefold between March and May 2026 and nearing 1 % of observed prompts.
- Enterprise data leakage through generative AI continues to grow; high‑risk prompts doubled from 2 % to 4 % over the past year, and many organizations use unapproved AI apps routinely.
- Data‑exposure risk varies by sector; Business Services shows the highest rate of high‑risk GenAI prompts (≈5.9 %), reflecting a combination of heavy AI usage and comparatively lower security maturity.
From AI Assistant to Attack Operator
For years, security analysts viewed artificial intelligence as a force multiplier that accelerated existing attack techniques, making them faster, cheaper, and more accessible. The 2026 AI Security Report from Check Point Research documents a decisive shift: AI is no longer merely a helper in the planning phase; it now functions as an active operator inside live intrusions. Threat actors deploy AI‑driven agents that execute commands, navigate compromised networks, and adapt tactics in real time. This evolution spans sophisticated nation‑state espionage campaigns linked to Chinese actors, large‑scale criminal breaches of Mexican government agencies, and increasingly, opportunistic attacks by ordinary cybercriminals who leverage AI to conduct end‑to‑end operations without extensive human oversight.
AI‑Generated Malware and Attack Suites
One of the most tangible outcomes of AI’s new role is the rapid creation of deployment‑ready malware and comprehensive attack suites. In a highlighted case, a single developer used an AI‑enhanced development environment to produce VoidLink, an 88,000‑line command‑and‑control framework, in under a week—a task that would traditionally require months of manual coding. Importantly, the AI’s contribution often remains invisible in the final binary; the model’s suggestions are woven into the code, making detection through traditional signature‑based methods more difficult. This capability lowers the barrier for actors with limited programming expertise while simultaneously increasing the volume and diversity of malicious tools available on underground markets.
Exploitation of Commercial Models via Agentic Jailbreaks
Attackers show a clear preference for commercially available large language models rather than maintaining self‑hosted instances. The report notes that most threat actors favor jailbroken mainstream models, which they sustain through a durable bypass mechanism: a planted configuration file that the model’s agent loads and trusts across sessions. By exploiting the agentic architecture—where the model can invoke tools, retain state, and chain multiple prompts—actors achieve persistent, stealthy control over the model’s behavior. This approach circumvents many of the safeguards built into single‑prompt interactions and enables prolonged, multi‑step attack campaigns that would be difficult to detect with conventional prompt‑filtering defenses.
Rise of AI‑Powered Criminal Tooling Market
The underground economy has responded to these technical advances by offering AI‑enabled services as ready‑made products. Phishing‑as‑a‑service kits now embed language models with built‑in jailbreaks, allowing purchasers to launch convincing, personalized phishing campaigns with minimal effort. Simultaneously, conversational AI voice‑agent services are being sold for vishing (voice phishing) and one‑time‑passcode theft, operating at scale and capable of mimicking legitimate customer‑support interactions. These services reduce the technical skill required for high‑impact social engineering attacks and contribute to a rapid increase in the volume and sophistication of fraud attempts targeting both individuals and enterprises.
Undermining Virtual Identity as Trust Anchor
Traditional trust anchors—such as voiceprints, facial recognition, and document verification—are losing reliability as generative AI makes synthetic media cheap and convincing. Attackers now routinely forge voices, faces, official documents, and even live video streams to impersonate executives, vendors, or government officials. This capability enables multi‑channel social engineering schemes where, for example, a deep‑fake video call is followed by a spoofed email and a fraudulent invoice, all designed to bypass conventional verification processes. As a result, organizations must reassess their reliance on biometric or document‑based authentication and adopt additional layers of contextual and behavioral checks.
AI Model as New Attack Surface
While AI empowers attackers, it also introduces fresh vulnerabilities into the defender’s environment. Language models cannot always cleanly separate user‑provided data from instructional content, meaning that malicious inputs can subtly influence model outputs or trigger unintended actions. Beyond the model itself, the surrounding software stack—including APIs, plug‑ins, and inference servers—harbors ordinary software bugs and supply‑chain risks that may be exacerbated by the rapid pace of AI innovation. Security practices for these components often lag behind functional advancements, creating an expanding attack surface that defenders must monitor, patch, and harden continuously.
Growth of Indirect Prompt Injection
Indirect prompt injection—where malicious instructions are embedded within data that the model processes rather than delivered directly as a prompt—has become increasingly prevalent. Between March and May 2026, detections of longer malicious payloads rose roughly fivefold, approaching 1 % of all observed prompts by May. Longer payloads are characteristic of content‑borne and agentic attack paths, indicating that attackers are leveraging files, emails, or web pages to smuggle harmful instructions into model interactions. This trend suggests a shift toward more sophisticated, stealthy techniques that evade simple prompt‑filtering defenses and necessitate deeper content inspection and anomaly detection.
Enterprise Data Leakage Through Generative AI
The use of generative AI within enterprises continues to expose sensitive information at an accelerating rate. Over the past year, the proportion of high‑risk prompts—those likely to result in data leakage—doubled from 2 % to 4 %. Organizations reported using an average of ten distinct AI applications each month, many of which operate without formal approval or oversight. This sprawling, unsanctioned AI footprint amplifies the chance that confidential data, intellectual property, or personally identifiable information is inadvertently fed into models that may retain, regurgitate, or leak it through outputs or side‑channel attacks.
Sector‑Specific Variations in Data‑Exposure Risk
Data‑exposure risk is not uniform across industries. Sector‑level analysis reveals a strong correlation between an organization’s AI usage patterns, its security maturity, and the likelihood of high‑risk GenAI prompts. Business Services emerged as the vertical with the highest incidence, recording a high‑risk prompt rate of 5.91 %—meaning nearly one in every seventeen AI interactions carried a significant chance of exposing sensitive data. This finding underscores the need for industry‑tailored governance models, targeted user training, and stricter controls on AI tool deployment, particularly in sectors where AI adoption outpaces the implementation of robust safeguards.

