AI Threat Report: How Artificial Intelligence Is Used Across Illicit Communities
It seems to be a Tuesday morning like any other. A finance employee joins a video call with their CFO and several colleagues. The request appears to be routine. The faces match. The voices sound authentic. Minutes later, $25 million is transferred—only to be discovered later that every participant on the call, except one, was AI-generated.
Techniques behind incidents like this—synthetic video, voice cloning, scripted interactions—are now being discussed openly in the same environments where threat actors exchange tools and methods. In June 2026 alone, Flashpoint analysts identified more than 4.7 million posts discussing artificial intelligence in the context of illicit activity.
This volume reflects a larger shift: Artificial Intelligence (AI) is now deeply embedded across cybercrime ecosystems, heavily influencing fraud, impersonation, social engineering, and access operations. It alters how malicious content is generated, how identities are replicated, and how automated workflows are executed and refined over time.
To track this evolution, our monthly AI Threat Report analyzes primary source communities across forums, marketplaces, and chat services. By isolating the tactics, tools, and operational patterns shaping malicious AI use, our latest data reveals an aggressive focus on prompt-sharing, jailbreak methods, and alternative models that lack standard moderation controls.
AI Activity Volume and What It Represents
Flashpoint analysts identified 4,718,651 posts discussing AI and criminal activities in June 2026. In May, Flashpoint observed 2,910,012 posts, marking a sharp 62% month-over-month increase.
The underlying activity was concentrated around a familiar set of use cases:
- Identity verification bypass
- Fraud enablement and scripting
- Impersonation through synthetic media
- Prompt-sharing and jailbreak workflows
Where AI Activity Is Concentrated
While AI-related chatter remained concentrated on a small handful of platforms, with Telegram accounted for the absolute majority of observed activity. Reddit, GitHub Gist, Pastebin, 4chan, Discord, and Mastodon followed, seeing significantly lower volumes.
The massive Telegram volume highlights its role as a heavily saturated distribution layer. Threat actors frequently spam messages across channels for maximum exposure, making it a primary marketplace for prompts, jailbreak methods, fraud tooling, and service advertisements.
Throughout the month, the same offers and workflows appeared repeatedly across different channels, often tweaked based on user feedback or platform updates. Meanwhile, alternative platforms served more targeted roles:
- GitHub Gist and paste sites hosted scripts and technical supporting material.
- Underground forums supported reputation building and long-form technical discussions.
- Discord and Reddit communities centered around specific models, prompt collections, or jailbreak workflows.
Because these environments remain interconnected, techniques introduced in one community frequently reappear elsewhere the moment they prove to produce reliable outputs or successfully evade moderation controls continue to gain traction and which techniques are becoming more broadly operationalized.
AI-Enabled Fraud and Identity Verification Bypass
Flashpoint analysts observed a massive surge in identity evasion activity in June, recording 3,533,769 posts advertising or discussing Know Your Customer (KYC) bypass methods—which include deepfake-enabled verification workflows. This was a staggering 98% month-over-month increase.
This activity was highly concentrated across Telegram channels dedicated to identity fraud, with posts consistently advertising:
- Synthetic video generation designed to mimic live verification behavior.
- Voice cloning and scripted interaction prompts.
- Bundled “KYC bypass kits” tailored to specific onboarding systems.
Some offerings included step-by-step guidance on adapting responses for specific financial platforms. Others promoted end-to-end combinations of synthetic video, matching fraudulent documentation, and AI-generated scripts to fully automate impersonation attempts.
This activity connects directly to the broader access ecosystem. Stolen credentials, session tokens, and phishing infrastructure are increasingly combined with AI-enabled impersonation within the same operational workflows. For security teams, this means verification systems, onboarding processes, and account recovery layers are being actively tested and systematically targeted.the same environments where these methods are exchanged and improved.
Malicious LLM Usage and Prompt-Based Workflows
Discussions tied to malicious or unrestricted LLM usage focused heavily on jailbreak methods, prompt-sharing, and access to alternative models perceived as less restricted than mainstream platforms. Threat actors continue to rely on unrestricted models to generate phishing links, build harmful code, or craft offensive media.
The underground market centers on usability and output reliability, with frequent references to:
- Jailbreak prompts designed to bypass safety guardrails.
- Phishing and fraud-oriented prompt collections.
- Step-by-step instructions for generating specific malicious outputs.
- Requests for prompts tailored to social engineering campaigns.
Many of these prompts are shared in active, living collections that include updates and troubleshooting channels. When a prompt stops working or a platform introduces new restrictions, users exchange feedback and roll out updated versions within hours.
This behavior reinforces how prompt engineering has developed into its own service layer across illicit communities. The emphasis remains on accessibility, portability, and ease of use rather than custom, ground-up model development.
What Security Teams Should Take Away
The underground activity tracked this month shows how artificial intelligence is being operationalized in environments where techniques are developed, tested, and shared long before they surface in the wild.
Because these methods are structured for easy deployment, they require very little modification to move from a forum discussion into an active attack vector. For security teams, the priority must be maintaining direct visibility into how these methods are evolving. Understanding which techniques are actively in circulation is the only way to build earlier detection and more focused defenses at the control layer.
If you want to see how this activity maps to your environment, request a demo.
Frequently Asked Questions (FAQ)
What is the Flashpoint AI Threat Report?
The Flashpoint AI Threat Report is a monthly intelligence analysis tracking how threat actors operationalize artificial intelligence across illicit communities. Built on Flashpoint’s primary source collection, this report provides proprietary visibility into underground forums and dark web marketplaces. The report isolates emerging cybercrime trends, jailbreak workflows, synthetic media fraud, and malicious language model usage.
How are threat actors currently using AI in cybercrime?
Threat actors primarily use AI to automate and refine existing attack vectors. Key operational use cases include:
- Identity Verification Bypass: Creating deepfake video and voice clones to circumvent Know Your Customer (KYC) checks.
- Social Engineering: Generating natural, multi-language phishing scripts and executive impersonations.
- Prompt Engineering & Jailbreaks: Exchanging prompts to bypass guardrails on mainstream LLMs.
How rapidly is illicit AI activity growing in cybercrime communities?
Illicit AI activity is growing exponentially. Flashpoint analysts identified 4,718,651 posts discussing AI and criminal activities in June 2026—a 62% month-over-month increase from the 2,910,012 posts recorded in May 2026. This surge highlights how AI tools have become deeply embedded in the daily operations of underground threat ecosystems.
Which messaging platforms and forums host the most illicit AI chatter?
- Telegram: Hosts the vast majority of illicit AI activity, functioning as a heavily saturated marketplace for trading prompts, jailbreak scripts, and KYC bypass kits.
- GitHub Gist & Pastebin: Host supporting scripts and technical code snippets.
- Discord & Reddit: Host community discussions around prompt collections and specific LLM models.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.