Report | AI Security, 2026 | Check Point Software
Report | AI Security, 2026
Check Point Research AI Security Report 2026 Check Point AI Report • 2nd Annual Edition
Table of Contents
01 Introduction
02 AI-Powered Cyber Attacks
03 Attacks against AI: AI as an attack surface
04 Digital Identity Under Siege
05 Data Leakage & Enterprise AI Exposure
06 Security for AI. Security by AI. Security with AI
07 2026 CISO Recommendations
Introduction
Introduction
When AI Stopped Assisting and Started Operating A year ago, we described AI as a force multiplier for cyberattackers: something that made existing techniques faster, cheaper, and more accessible. Over the past twelve months, the evidence we collected tells a more significant story. AI has crossed into the live attack chain. We documented intrusions where AI ran exploitation workflows autonomously, generating thousands of commands across dozens of sessions with minimal human direction. We analyzed malware that a single developer produced in under a week at a quality level our researchers initially attributed to a multi-person team working for months. We watched criminal groups breach government agencies at scale, using AI as the primary operator rather than a background assistant. And in most of those cases, what gave away the AI's role in the attack was the attacker's own operational mistakes or monitoring by the AI provider, not anything the victim organization had detected or put in place to catch it.
The shift matters because it changes what defenders need to account for. The expertise barrier that once separated capable attackers from the rest has been compressing steadily, and the artifacts now coming out of AI-assisted operations are the clearest evidence of how far that compression has gone.
The other half of this report looks inward. Organizations adopting AI are generating an exposure surface that most security teams are still working to understand. High-risk GenAI prompts doubled over the past year. The average organization now runs ten AI applications a month, many operating outside any formal approval process. The models and infrastructure being adopted carry attack surfaces of their own, and the security practices around them have not kept pace with the rate of adoption.
Four chapters follow, grounded in Check Point Research incidents, telemetry, and original case studies from the past twelve months. What you will read is a record of what already happened, setting the stage for what’s expected to come.
Lotem Finkelstein
Vice President, Check Point Research
AI-Powered Cyber Attacks
AI-Powered Cyber Attacks Over the past twelve months, public reporting and real incidents show AI playing a role in nearly every stage of a cyber attack chain: social engineering, malware development, live intrusion support, building attacker tools, and vulnerability research. The attack techniques themselves are mostly familiar. What has changed is that AI now does in minutes what used to take a skilled attacker hours or days, and at a fraction of the cost and expertise required before.
Anthropic's analysis on misuse supports this pattern: attackers are using AI less for initial access, but rather to do the work itself once inside, increasing in post-compromise activity. The attackers posing the highest risk aren't the ones with the fanciest tools; they're the ones who've figured out how to orchestrate AI to chain multiple stack stages without needing to step in themselves.
How attackers access AI capability
Attackers obtain AI capabilities through three routes, and all three matured over the year, though not equally:
- Abusing commercial models, accessed legitimately or through stolen credentials, remains the most common route in practice.
- Deploying self-hosted open-source models avoids moderation and provider logging, but stays more aspirational than practical.
- Buying access to purpose-built malicious services peaked and then declined as the underground grew skeptical of their quality.
Abusing commercial models
The simplest route is also the most popular: use an everyday tool like ChatGPT, Gemini, or Claude and work around its safety rules. Attackers break a malicious request into smaller, innocent-looking steps, first asking the AI to explain a technique in general, then asking for the actual code, and they gravitate toward whichever mainstream tool has the weakest safety rules. Much of what we know comes from the AI companies themselves: Google’s Threat Intelligence Group has documented state-sponsored and criminal abuse of Gemini to conduct reconnaissance, lure development, and tooling, and Anthropic and OpenAI have reported similar abuse of their own AI.
Access can also simply be stolen. Login credentials for AI tools are now a deliberate target for theft, often pulled in bulk from developer configuration .env files that were accidentally left exposed online. One campaign, called Bissa Scanner, stole AI login details for Anthropic, OpenAI, Google, and several other providers from more than 30,000 of these exposed files, with AI accounts the single most common type of credential stolen.
Self-hosted open-source models
The second route is to self-host a freely available AI open-source model (Qwen, Kimi, and others) and run it on the attacker's own infrastructure, rather than routing requests through a commercial provider. This avoids any safety checks, account bans, or activity logs the AI company might otherwise apply. Discussion of this approach has grown steadily in criminal forums. In practice, the reality has not matched the discussion. Attackers who've tried it report that these self-run models perform worse, make more mistakes, and need expensive computer hardware and fine-tuning to reach a usable standard.
The rise and fall of malicious "DarkGPT" services
The third route is to buy access to an AI tool built specifically for crime, with no restrictions at all, like WormGPT and its many imitators. This market rose and then fell over the past year: underground users’ reports found these “dark LLM” criminal-only tools are technically weak and mostly used by low-skill criminals rather than serious operators. The reputation hit bottom when WormGPT itself was breached, exposing the payment details of more than 19,000 of its own paying customers. New, cheap versions still pop up, such as the Tor-hosted DIG AI, but most serious activity has shifted back to the first two routes.
Case study: "The Gentlemen" - one group, the whole access question
The Gentlemen is a financially-motivated ransomware-as-a-service operation with over 330 published victims by May 2026. Check Point Research's analysis of the group's communications demonstrates, in the group's own words, how attackers approach AI:
- Which AI tool to use: they prefer less-restricted Chinese commercial AI tools (DeepSeek, Kimi, Emi, Qwen). One member recommended a setup running on “Qwen 3.5 with all barriers removed... Zero refusals. Absolutely no restrictions.”
- Self-hosting their own AI stayed theoretical: The group discussed running a local model on stolen data but admitted they didn’t know how.
- AI builds tools, but skill steers it: the group's administrator built its “Glocker” management tool for their operation in three days with AI's help, while cautioning fellow members, “you still need to understand what you are doing.”
What makes this case useful is exactly how unremarkable it is: an ordinary, mid-tier criminal group, using the same mainstream AI tools anyone can access, getting real results despite having no local alternative available.