Check Point Researchers: AI Has Crossed into the Live Attack Chain

Cybersecurity researchers have long warned that attackers would use AI to improve existing cybercrime techniques. But according to Check Point Research's recent "AI Security Report 2026," the threat landscape has entered a new phase: AI is no longer just helping attackers; it is beginning to operate inside real-world attacks.

The report describes a shift from AI as a force multiplier to AI as an active component of cyber operations. It documents intrusions in which AI autonomously ran exploitation workflows, generating thousands of commands across dozens of sessions with minimal human direction.

The change matters because it lowers the expertise barrier that traditionally separated advanced attackers from less-skilled criminals. "AI has crossed into the live attack chain," the report states.

The researchers found that AI is now appearing across multiple stages of cyberattacks, including social engineering, malware development, vulnerability research, attacker tool creation, and live intrusion support. The techniques themselves are often familiar. What has changed is the speed and scale at which attackers can execute them.

AI Is Compressing the Cyber Skills Gap

One of the report's most significant findings is that AI is putting sophisticated cyber capabilities within reach of a much wider range of attackers. The researchers said the attackers creating the greatest risks are not necessarily those with the most advanced tools. Instead, the greatest threat comes from groups that can successfully orchestrate AI across multiple stages of an attack.

The report cited a ransomware-as-a-service group known as "The Gentlemen" as an example of how cybercriminals are experimenting with AI. Researchers found that the group used AI to help build its "Glocker" management tool in just three days.

The report also noted an important limitation: AI can accelerate attackers, but human understanding still plays a role. One member of the group warned others that "you still need to understand what you are doing," showing that AI improves attackers' capabilities but does not eliminate the need for expertise.

How Attackers Are Accessing AI Capabilities

Check Point identified three main ways attackers are gaining access to AI capabilities. The most common approach is abusing commercial AI models. Attackers are using widely available tools and attempting to bypass safety controls by breaking malicious requests into smaller, less obvious steps.

The report said attackers are increasingly choosing mainstream AI platforms because they are more capable and accessible than underground alternatives.

Another growing risk is the theft of AI credentials. Check Point highlighted the rise of "LLMjacking," in which criminals use stolen account credentials to access commercial AI services. The report said one campaign, known as Bissa Scanner, stole AI login details from more than 30,000 exposed configuration files.

The third approach involves self-hosted open source models. While these models allow attackers to avoid provider safety controls and logging, the cybersecurity company said many attackers have found them less capable and more difficult to operate than commercial AI tools.

AI Creates a New Security Challenge for Enterprises

The report also highlights a challenge for organizations adopting AI internally. As enterprises deploy more AI applications, they are creating new potential attack surfaces.

Check Point identified risks involving AI models, infrastructure, and applications, while warning that security practices have not always kept pace with adoption. The same AI capabilities that help businesses automate tasks and improve productivity can also introduce new risks if they are poorly secured.

For security teams, the challenge is becoming two-sided. They must defend against attackers using AI while also securing the AI systems their own organizations rely on.

The Next AI Cybersecurity Battle

The rise of AI-powered attacks signals a broader shift in cybersecurity. The question is no longer whether attackers will use AI. According to the report, that transition has already happened.

As Check Point concludes in its report, the incidents observed over the past year represent "a record of what already happened, setting the stage of what's expected to come." The next challenge will be whether defenders can adapt quickly enough as AI becomes more deeply embedded in cyber operations.

The full report is available for download here on the Check Point site (registration required).

 

Featured

  • lock symbol with quantum bits in dynamic motion

    Microsoft Accelerates Quantum-Safe Security Timeline

    Microsoft is speeding up its quantum-safe security timeline, noting that advances in quantum computing and new federal requirements have pushed post-quantum cryptography from a future planning issue into an immediate engineering priority.

  • digital data protection and cyber security

    White House Issues New AI Security Framework

    President Donald Trump has launched a new executive order aimed at maintaining United States AI leadership while addressing the security risks posed by increasingly powerful AI systems.

  • Abstract Network of Blue and Orange Lines

    Tech Industry Leaders Launch Alliance for AI Agent Security

    NVIDIA and 36 other industry partners are targeting agent security across multi-vendor clouds by combining open technologies for workload identity, agent controls, vulnerability scanning, and software supply-chain security.

  • Students with backpacks walk down a sunlit school hallway

    SchoolStatus Attend Update Adds Time-Based Attendance Tracking

    K-12 attendance solution provider SchoolStatus has announced an enhancement to its Attend product, adding flexible, time-based attendance tracking that measures missed learning time rather than just full-day absences.