Published Product3 min read
Criminal AI went private, and the counting method went with it
Flashpoint logged criminal AI toolkits in more than 22 million forum posts in the first half of 2026, then watched much of that tooling vanish from public view onto self-hosted models with the guardrails removed.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition found that criminals now use AI in day-to-day operations, well past the experimental stage.
- The report covers the first six months of the year; Flashpoint's analysts worked through 3.9 petabytes of material, most of it from illicit forums, encrypted channels and infrastructure tied to attackers.
- Criminal AI toolkits came up in more than 22 million posts in the material Flashpoint analysed.
- Much of the criminal AI tooling has since disappeared from public view.
- Criminals are running custom language models with the safety guardrails stripped out, on private infrastructure they control.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
Flashpoint's 2026 midyear threat report says criminals are past the experimental stage with AI and are now running custom language models with the safety guardrails stripped out, on private infrastructure they control [1][2][4]. That is a measurement problem before it is a threat problem: the signal defenders were counting, public discussion of criminal AI tooling, is a record of a market that has already moved indoors [3][5].
The scale of the old signal was substantial. Flashpoint's analysts worked through 3.9 petabytes of material, most of it from illicit forums, encrypted channels and attacker infrastructure, and criminal AI toolkits came up in more than 22 million posts [2][3]. Much of that tooling has since disappeared from public view [4]. The reported uses of the self-hosted models are unremarkable and therefore credible: target profiling, malware evasion scripts, phishing content and exploit generation [6]. Flashpoint's position is that this makes the activity far harder to observe from outside, and it calls the result a visibility gap [7]. Josh Lefkowitz, the company's co-founder and chief executive, said AI is "compressing the time between opportunity and exploitation," and that tools which once required real expertise now require much less of it [8].
The operational numbers are where automation shows up without needing to be inferred. Infostealer malware infected 7.4 million hosts over six months and produced 1.7 billion credentials and identity artifacts, roughly 230 per infected host [9][10][1]. Vidar, StealC and Lumma led, sold as subscriptions that harvest active browser session tokens; an attacker holding a live token does not need the password [11][12]. On the vulnerability side, the half produced 21,667 disclosures, with public exploit code for 4,015 of them, about 18.5%, and Flashpoint logged 6,808 before they reached the National Vulnerability Database, roughly 31% [13][14][15][2][3]. More than 34% were rated critical or high, which Flashpoint argues has made a patching queue sorted by severity alone unworkable [16].
The pricing tells the clearest story. Verified ransomware victims rose 45% to 6,256, implying about 4,314 in the first half of 2025, with 2,669 tracked in the U.S. and manufacturing leading sectors at 18% [17][18][4]. Qilin led with 901 victims, and the top five families accounted for 44% of activity [19][20]. Revenue moved the other way: on-chain ransom payments fell about 8% to $820 million on Chainalysis data cited in the report, and the share of victims who paid slid to 28%, which Flashpoint called a possible all-time low [21][22]. Automated access tooling has pushed the average price of initial access on criminal markets down 69%, to $439, from roughly $1,400 [23][5]. More victims, cheaper entry, less money.
Separately, the report ties Middle East conflict to a rise in state-aligned operations against supply chains, financial institutions and industrial control systems, with several wiper families identified and some tooling linked to the Handala Hack group and APT39 [24][25].
What to watch: whether Flashpoint's year-end edition can put any number on private-model activity, or whether the 22 million-post metric simply falls without anything replacing it [3][4]. Watch access prices too. If $439 keeps falling while payment rates sit near 28%, the pressure moves to volume, and session-token theft is the cheapest volume available [22][23][12].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition found that criminals now use AI in day-to-day operations, well past the experimental stage.
- [2]
The report covers the first six months of the year; Flashpoint's analysts worked through 3.9 petabytes of material, most of it from illicit forums, encrypted channels and infrastructure tied to attackers.
- [3]
Criminal AI toolkits came up in more than 22 million posts in the material Flashpoint analysed.
- [4]
Much of the criminal AI tooling has since disappeared from public view.
- [5]
Criminals are running custom language models with the safety guardrails stripped out, on private infrastructure they control.
- [6]
Reported uses of these models include target profiling, malware evasion scripts, phishing content and exploit generation.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- siliconangle.comDuncan RileyAug 13Criminals have moved AI out of testing and into daily use, Flashpoint finds
Additional citations
- Flashpoint
- Josh Lefkowitz, Flashpoint co-founder and CEO
- Chainalysis data cited by Flashpoint



