Press play to start listening
Cybercriminals are moving AI operations onto private infrastructure while using automation to speed up phishing, malware development and vulnerability exploitation, according to Flashpoint’s 2026 Global Threat Intelligence Report: Midyear Edition.
Published on August 13, the report covers activity recorded from January 1 through June 30, 2026. Its findings are based on Flashpoint’s Primary Source Collection, which contains more than 3.9 petabytes of monitored data from illicit forums, private communication channels, and other criminal sources.
Flashpoint counted more than 22 million threat actor posts that discussed, shared, or advertised AI toolkits for criminal use over the six-month period.
Attackers are also deploying customized AI models without safety restrictions on private infrastructure. According to the report, these locally operated systems can assist with phishing content, malware development, code obfuscation, target profiling, and exploit generation without depending on public underground communities for development.
Infostealers Compromise 7.4 Million Hosts
According to researchers, credential theft remained one of the main routes into personal and business accounts. Flashpoint recorded more than 7.4 million unique hosts compromised by infostealer malware, about 27% more than during the previous six months.
Among the malware families tracked, Vidar, StealC, and Lumma were the three most active during the reporting period.
Together, infostealers collected about 1.7 billion credentials and other identity data points. Such information can include passwords, browser cookies, authentication tokens, and stored account details, allowing attackers to enter accounts using valid login information.
Exploit Code Accompanies One in Five Vulnerabilities
The research further revealed that software vulnerabilities continued to provide another route into organizations. Flashpoint tracked 21,667 vulnerability disclosures during the first half of 2026, about 8% more than during the previous six months.
Of those disclosures, 4,015, or 19%, already had public or functional exploit code available. This reduces the time organizations have to assess and correct newly disclosed vulnerabilities before attackers begin testing them.
Flashpoint’s report also identified 239 vulnerabilities exploited in the wild during the period, which is 191% more than the 82 vulnerabilities documented in CISA’s Known Exploited Vulnerabilities catalog during the same six months.
Another 6,808 vulnerability records were available through Flashpoint before the corresponding National Vulnerability Database enrichment was published. Delays in public vulnerability data can leave organizations without enough technical information to decide which updates require immediate attention.
Ransomware Victim Count Reaches 6,256
Flashpoint documented 6,256 verified ransomware victims during the first half of 2026, a 45% increase over the same period in 2025.
Flashpoint connected the increase to automated criminal operations, lower-cost initial access and mature ransomware-as-a-service (RaaS) businesses. These services give affiliates access to ransomware software, payment systems, leak sites and negotiation support without requiring them to build the operation themselves.
The report also found that the proportion of victims paying ransom demands fell to 28%, its lowest recorded level. Despite fewer payments, operators continued targeting more organizations to maintain revenue.
Military Conflict Influences Cyber Activity
Military conflict in the Middle East also coincided with cyber campaigns targeting supply chains, financial institutions, industrial systems and critical infrastructure, Flashpoint reported. Such activity created operational risks for organizations located outside the immediate conflict zones.
Separately, Hackread.com recently reported an AI-assisted campaign targeting Taiwanese government agencies, which compromised 85 accounts and extracted more than 2,500 personnel records. That operation was not part of Flashpoint’s Middle East findings.
Flashpoint’s data indicates that AI is accelerating familiar cybercrime methods by reducing the time and technical expertise required to conduct them.
