How AI is changing the economics of cybercrime
Cybercriminals are increasingly using AI across a range of activities, from reconnaissance and phishing to code generation, credential theft, and identity fraud. The concern for now, however, is not that AI is creating entirely new forms of cybercrime, but that it’s making existing attacks faster, cheaper, and accessible to a much wider group of bad actors.
The companies building today’s most advanced AI systems are increasingly warning about their misuse in cybercrime. Reports from Anthropic, Google, and Microsoft published in September describe AI being used to personalize phishing campaigns, create convincing fake websites, automate social-engineering attacks, identify vulnerable systems, and accelerate fraud and identity theft.
More concerningly, some attacks are beginning to resemble coordinated campaigns rather than isolated acts. Multi-agent frameworks can distribute different stages of an attack across specialized AI agents, allowing reconnaissance, exploitation, and data exfiltration to occur simultaneously rather than sequentially.
To what extent is AI amplifying the cyber threat landscape, and what can organizations and cybersecurity experts do in response?
Core Insights
- AI lowers the cost of cybercrime, reducing the time and specialist effort needed to develop and execute familiar attacks.
- Automation increases attack scale, allowing smaller groups to coordinate tasks and target more victims.
- Cybersecurity fundamentals remain essential, with AI supporting faster monitoring, investigation, and incident response.
- AI agents can execute parts of an attack with limited human input, even when people still set objectives and review outcomes.
In this article
This article is also available in podcast/video form. Watch the video below from our YouTube channel, or follow The Intuition Finance Digest on Spotify, Apple Podcasts, or Amazon Music.
What AI is changing: the economics of cybercrime
If AI were discovering entirely new forms of cybercrime or previously unknown weaknesses, we’d be facing a much bigger problem.
Fortunately, that’s not what most threat-intelligence research suggests. The activities attracting attention today, from phishing and credential theft to network intrusion, are familiar. So too are the vulnerabilities they exploit, such as weak passwords, exposed systems, and unpatched software.
What AI is changing is the economics of cybercrime. Tasks that once required significant time and specialist expertise, such as reconnaissance, identifying targets, and crafting phishing campaigns, can increasingly be automated or delegated to AI systems.
For example, Google’s Threat Intelligence Group documented a case in which attackers compromised a cloud resource and launched an agent-enabled credential-harvesting campaign in under six hours. Microsoft has similarly reported AI-orchestrated cloud attacks involving more than 150 credential-related or destructive actions within just 35 minutes.
Such operations would previously have required hours, or even days, of manual work. Increasingly, AI systems can automate many of these stages, dramatically reducing the time, cost, and expertise required to execute sophisticated attacks.
In short, AI is lowering the barriers to entry for cybercrime while increasing the number of targets that can be attacked simultaneously. In other words, cybercrime is becoming more scalable even as the expertise required to conduct it declines.
What can be done?
If AI is not changing the underlying fundamentals of cybercrime, the fundamentals of cybersecurity also remain largely unchanged. Here too it’s the economics that are changing.
Security teams are using AI-powered tools to enhance cyber hygiene by identifying vulnerabilities, monitoring networks, detecting suspicious activity, and responding to incidents more quickly than would be possible through manual processes alone.
The sheer number and range of AI-enabled attacks described in recent threat-intelligence reports is illustrative. While it might appear daunting at first glance, it’s also testament to the improved capabilities of modern AI-enhanced detection systems.
The potentially greater risk worth monitoring
Up to now, AI has largely been accelerating known forms of cybercrime.
Today’s AI-enabled attacks still require human operators to define objectives, select targets and make key decisions throughout the attack lifecycle. In that sense, AI remains more of an accelerator than an independent actor.
But that could change. As AI systems become more capable and autonomous, the possibility of them independently identifying vulnerabilities, adapting attack strategies or discovering entirely new avenues of exploitation is a daunting prospect.
Such scenarios remain largely theoretical for now. But as AI systems become increasingly capable and autonomous, the risk of cyberattacks evolving from AI-assisted to AI-directed is one that governments, regulators, and technology providers are taking increasingly seriously.
Conclusion
So far, AI has not reinvented cybercrime. Instead, it has made familiar angles of attack faster, cheaper, and easier to execute, allowing less sophisticated attackers to operate at unprecedented speed and scale. While this presents a significant challenge, defensive capabilities are proving largely equal to the task, with AI itself increasingly being deployed to strengthen monitoring, threat detection, and incident response.
The bigger questions may lie ahead. If today’s AI acts primarily as an accelerator, tomorrow’s systems could take on a more independent role in identifying vulnerabilities, adapting tactics and conducting attacks. And if cybercrime becomes increasingly autonomous, will we become increasingly reliant on autonomous defense too?
Intuition Know-How has a number of tutorials relevant to the content of this article:
- AI Applications – Fraud Detection & Prevention
- AI Ethics – An Introduction
- AI Applications – Regulatory Compliance
- AI Ethics – Generative AI
- AI Applications – Trading
- AI Applications – Corporate Credit Risk
- AI Ethics – Data Privacy & Security
- Digital Banking – An Introduction
- AI Applications – Retail Credit Risk
- AI & GenAI – An Introduction
Frequently Asked Questions
How is AI changing the economics of cybercrime?
AI can reduce the time, cost, and specialist effort required for reconnaissance, phishing, code generation, and credential theft. By automating parts of these workflows, it enables attackers to run familiar operations faster and target more victims with fewer resources.
Is AI creating entirely new forms of cybercrime?
Many reported AI-enabled attacks use familiar methods such as phishing, credential theft, and network intrusion. The change is often in the speed, scale, and coordination of those attacks. Existing weaknesses, including exposed credentials and unpatched software, remain important targets.
How do AI agents make cyberattacks more scalable?
AI agents can divide tasks such as reconnaissance, tool development, and analysis across specialized workflows. Multi-agent systems can coordinate work and run some tasks in parallel, reducing manual effort. Human involvement varies, including setting objectives, selecting targets, and reviewing results.
How can organizations respond to AI-enabled cybercrime?
Organizations should maintain strong cyber hygiene, protect credentials, patch vulnerabilities, and monitor systems for suspicious activity. AI tools can help security teams prioritize alerts, investigate threats, and respond faster. Their use should complement clear incident-response processes and human oversight.
Can AI carry out cyberattacks autonomously?
Some attack stages can already be executed by AI agents with limited human input, including reconnaissance, exploitation, and data theft. Human operators often still select targets, set objectives, and review outcomes. Autonomy varies across operations; it does not necessarily mean an attack is independent of human direction.





