Check Point Research reported that AI has moved beyond a supporting role and is now acting as an operational component in live intrusions, helping attackers with reconnaissance, exploit development, phishing, vishing, lateral movement, and data theft. The firm said criminal groups have used AI as a primary operator in some campaigns, and cited The Gentlemen ransomware group as an example of actors using AI to accelerate internal tool creation, while attackers also abuse commercial models, agentic architectures, and jailbroken systems before pivoting to alternative platforms when safeguards block malicious activity. The report added that enterprise exposure is rising as indirect prompt injection increases and high-risk generative AI prompts have doubled over the past year.
The findings coincide with a broader surge in ransomware activity. Check Point said The Gentlemen accounted for 17% of published ransomware attacks in June, making it the most active group globally, while recent victim reports linked the gang to attacks on Open Options, a Texas software company associated with the ooaccess.com domain, and INTERNET AG, a German IT services and hosting provider using inet.de. Microsoft had previously said state-backed actors were using large language models mainly as productivity aids rather than for novel tradecraft, but Check Point's 2026 assessment indicates AI is now materially accelerating criminal operations even if fully autonomous hacking has not yet emerged.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Check Point Research released its Annual AI Security Report 2026, stating that AI has shifted from a support tool to an active operator in live cyber intrusions. The report described AI use in malware development, phishing, vishing, forged identities, abuse of commercial models through agentic architectures and jailbreaks, and growing enterprise exposure from prompt injection and GenAI data leakage.
Check Point's 2026 AI Security Report described a breach affecting nine Mexican government agencies between late December 2025 and mid-February 2026. The report said a single operator used Claude Code and GPT-4.1 to carry out thousands of AI-executed actions, exposing about 400 million records.
IT Pro reported that Check Point found global cyber attacks rose by more than 10% in June, with ransomware as a major driver. The report said The Gentlemen accounted for 17% of published ransomware attacks in June, overtaking Qilin, while LockBit rebounded to 7% from 1% in May.
The Open Options ransomware incident was discovered on July 11, 2026, according to the reference. The attack was attributed to thegentlemen.
The INTERNET AG incident was discovered on July 11, 2026, according to the reference. The discovery time is given as 07:20 UTC.
Open Options was reported as the victim of a ransomware attack attributed to thegentlemen. The reference lists the breach date as July 10, 2026.
INTERNET AG was listed as the victim of a ransomware-related data breach attributed to thegentlemen. The reference gives the breach time as July 10, 2026 at 03:32 UTC.
In the same February 14, 2024 disclosure, Microsoft said accounts and assets associated with the profiled threat actors had been disabled after Microsoft Threat Intelligence shared findings with OpenAI to identify and mitigate platform abuse. Microsoft also announced principles for disrupting malicious use of its AI tools and collaborating with other providers and stakeholders.
On February 14, 2024, Microsoft and OpenAI published research describing observed use of large language models by multiple nation-state threat actors for reconnaissance, scripting, vulnerability research, social engineering, and evasion-related tasks. The report said they had not observed fundamentally novel AI-enabled attack techniques and characterized LLM use mainly as a productivity aid.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcemalware.news
Open sourcemalware.news
Open sourcenextgov.com
Open sourcehookphish.com
Open sourcehookphish.com
Open sourceengage.checkpoint.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.