CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 378

As cited

Copy frozen at (site build).

vulnerabilities

Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime

Underground markets have shifted from standalone malicious AI tools toward integrating AI as a productivity layer within existing cybercrime operations. Rather than replacing attackers, AI accelerates routine tasks like phishing, code debugging, document forgery, and data processing at scale. Criminal AI-as-a-Service offerings are being commercialized through subscriptions, Telegram bots, and jailbreaks around legitimate models, though the market remains volatile and uneven.

Why it matters: Security teams need to understand that AI is lowering skill barriers and accelerating the velocity of social engineering, fraud, and post-breach exploitation across their threat surface. Defenders should expect increased volume and sophistication of phishing, credential attacks, and data exfiltration campaigns powered by these accessible criminal AI services.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Criminal AI-as-a-Service in 2026: How the Underground Market Is Operationalizing Cybercrime

Underground markets are increasingly commercializing artificial intelligence (AI) as a service for cybercriminals, using familiar business models like subscriptions and Telegram-based delivery. Rather than deploying fully autonomous AI hacking systems, threat actors are embedding AI into routine tasks such as phishing generation, malware modification, data processing, and document forgery to accelerate operations and lower skill barriers. The ecosystem relies primarily on jailbroken wrappers around commercial models, open-weight deployments, and stolen credentials rather than proprietary foundational models.

Why it matters: Security teams must recognize that AI-as-a-Service reduces the operational friction for attackers at scale: lower-skilled threat actors can now conduct sophisticated social engineering, data exploitation, and identity abuse at speeds and volumes previously unattainable, requiring defenders to adjust detection baselines and assume broader adversary capabilities.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary