AI Threat Report: How Artificial Intelligence Is Used Across Illicit Communities
A monthly analysis of how artificial intelligence is used in illicit communities, based on Flashpoint proprietary intelligence and direct visibility into real threat actor environments.
An unrestricted AI model promises users the ability to generate malware, build phishing kits, develop social engineering scripts, and analyze breached data. For less than $40 a month, users can access its most advanced plan.
That model, MessiahGPT, is one of the malicious large language models Flashpoint analysts observed gaining attention across illicit communities in August. In one Pastebin post identified during the month, an anonymous user appeared to use MessiahGPT to analyze port-scan results and identify potential exploitation opportunities.
This is just one example of a much larger shift taking place across the cybercrime ecosystem.
In August 2026, Flashpoint analysts identified 7,461,908 posts discussing artificial intelligence in the context of illicit activity, up from 5,575,564 in July. That represents a nearly 34% increase in a single month.

The increase reflects how deeply AI has become embedded within the environments Flashpoint monitors. Across forums, marketplaces, and chat services, threat actors are advertising AI services, exchanging methods, testing tools, and incorporating AI into fraud, identity verification bypass, social engineering, malicious development, and other operational workflows.
To track this evolution, our monthly AI Threat Report analyzes primary source communities across forums, marketplaces, and chat services. This month’s intelligence examines where that activity is concentrated, the sharp increase in AI-enabled identity verification bypass activity, and how malicious and unrestricted models are becoming increasingly accessible to cybercriminals.
Where AI Activity Is Concentrated
Telegram remained the dominant source of observed AI service advertisements in August.
Flashpoint identified 4,899,407 posts advertising AI services on Telegram, far exceeding activity observed across other platforms. GitHub Gist followed with 20,382 posts, Reddit with 14,084, and Pastebin with 9,487. Discord, BlackHatWorld, 4chan, Mastodon, and other sources accounted for substantially smaller volumes.

As we observed in July, raw post volume should not be interpreted as an equivalent number of unique advertisements or services. Threat actors frequently repeat or spam the same messages across multiple channels to maximize visibility.
Even with that caveat, Telegram’s concentration demonstrates its continued importance as a distribution layer for illicit AI services and related activity.
Other platforms continue to play more specialized roles. Paste sites and GitHub Gist can provide supporting technical material, while forums and community platforms facilitate discussion around particular tools, methods, and workflows.
Together, these interconnected environments allow AI-enabled techniques and services to circulate quickly once they attract interest from threat actors.
AI-Enabled Fraud and Identity Verification Bypass
Activity related to AI-enabled identity verification bypass increased substantially in August.
Flashpoint analysts observed 751,644 posts advertising or discussing Know Your Customer (KYC) bypass methods using AI technology, including deepfake technology. That compares with 394,567 posts in July, representing an increase of approximately 91% month over month.
These discussions remain concentrated within Telegram channels where threat actors advertise methods and services designed to circumvent identity verification controls.
The sharp increase is particularly important because AI-enabled identity fraud can intersect with a much broader criminal ecosystem. Synthetic identities and deepfake technologies can be combined with compromised credentials, fraudulent documentation, social engineering, and other access methods.
For organizations, this reinforces the need to look beyond individual fraud techniques. Threat actors can assemble multiple capabilities into workflows designed to target onboarding, authentication, account recovery, and other identity-dependent processes.
Malicious LLM Usage and Prompt-Based Workflows
Malicious and unrestricted LLMs remained an important part of AI-related activity observed across Flashpoint Collections in August.
Threat actors have continued to develop their own models or seek ways around safeguards imposed by mainstream LLMs. These tools are promoted for a range of malicious applications, including phishing, social engineering, malware development, harmful code generation, and offensive content creation.

One model attracting attention is MessiahGPT.
First observed in January 2026, MessiahGPT is promoted by “dabial leaks,” one of the operators associated with WormGPT. The service is marketed as an unrestricted AI model and offers both a free tier and paid plans ranging from $9.99 to $39.99 per month.
Advertisements reviewed by Flashpoint claim that the model can assist with malware development, phishing-kit generation, social engineering scripts, fraud-related activity, and breach analysis, among other uses.
Flashpoint analysts also identified an August 24 Pastebin post indicating that an anonymous user was using MessiahGPT to analyze the results of port scans and identify potential software weaknesses and exploitation opportunities.
The accessibility of services like MessiahGPT is noteworthy. Rather than requiring threat actors to develop a specialized model themselves, commercially packaged malicious LLMs can put AI-assisted capabilities behind a relatively inexpensive subscription.
That lowers the barrier to experimenting with AI across existing criminal workflows and creates another mechanism through which techniques can be packaged, shared, and operationalized.
Other AI-Related Activity Observed in August
Flashpoint also observed several notable offers involving AI companies, infrastructure, and unrestricted AI services during August.
In one listing, an actor using LAPSUS$ branding claimed to be offering 4 TB of data and source code from Mercor, an AI-powered recruiting and hiring platform. The allegedly compromised material included proprietary AI models, candidate information, client records, and internal platform source code.
Separately, a threat actor advertisement claimed access to the infrastructure of an unnamed major U.S. cloud and AI technology enterprise. According to the listing, the access included internal cloud infrastructure, AI platform assets, and enterprise systems.
Flashpoint also observed Kriminal.ai advertising an unrestricted AI service for hackers for $12.99 per month. The service claimed to use established AI models with built-in jailbreak prompts designed to circumvent their normal safety restrictions.
These examples show that AI’s role within illicit communities extends beyond the use of generative models themselves. AI companies, platforms, models, infrastructure, and data can also become targets, commodities, or components of broader criminal operations.
What Security Teams Should Take Away
August’s activity reinforces both the scale and accessibility of AI-enabled criminal activity.
Flashpoint observed nearly 7.5 million posts discussing AI and criminal activities during the month, while discussions of AI-enabled KYC bypass methods nearly doubled from July.
At the same time, services such as MessiahGPT illustrate how malicious AI capabilities are being packaged for easier consumption. Threat actors do not necessarily need to build their own models or develop sophisticated AI expertise. They can increasingly access tools marketed specifically around criminal use cases, then incorporate those capabilities into existing workflows.
For security teams, direct visibility into these environments is increasingly important. Tracking overall volume can reveal the scale of activity, but understanding the tools, services, and techniques gaining traction provides the context organizations need to identify how AI-related threats could translate into real-world risk.
Want to dig deeper into what the growth of AI-enabled threats means for threat intelligence teams? Join Flashpoint’s upcoming webinar, 22 Million Reasons to Rethink Your 2027 Threat Intelligence Plan, for a data-driven look at how AI is changing the threat landscape and what security leaders should consider as they plan for 2027.
If you want to see how this activity maps to your environment, request a demo.
Frequently Asked Questions (FAQ)
What is the Flashpoint AI Threat Report?
The Flashpoint AI Threat Report is a monthly intelligence analysis tracking how threat actors operationalize artificial intelligence across illicit communities. Built on Flashpoint’s primary source collection, the report provides proprietary visibility into underground forums, chat services, marketplaces, and other environments where AI-related criminal techniques and services are discussed and exchanged.
How are threat actors currently using AI in cybercrime?
Flashpoint continues to observe AI being used across a range of criminal workflows, including identity verification bypass, phishing and social engineering, malicious code generation, fraud, and the analysis of potential targets and vulnerabilities.
Threat actors are also advertising unrestricted LLM services designed specifically to remove or circumvent safeguards that would otherwise limit malicious use.
How rapidly is illicit AI activity growing in cybercrime communities?
Flashpoint analysts identified 7,461,908 posts discussing AI and criminal activities in August 2026, compared with 5,575,564 in July. That represents a nearly 34% month-over-month increase.
AI-enabled KYC bypass activity also increased sharply. Flashpoint observed 751,644 posts advertising or discussing KYC bypass methods using AI technology in August, compared with 394,567 in July.
Which messaging platforms and forums host the most illicit AI chatter?
Telegram continues to account for the largest concentration of observed activity. Flashpoint identified more than 4.8 million posts advertising AI services on Telegram in August, compared with substantially smaller volumes across GitHub Gist, Reddit, Pastebin, Discord, BlackHatWorld, 4chan, and other sources.
Post counts do not represent unique advertisements, as threat actors frequently spam or repeat content across channels to maximize exposure.
What are malicious LLMs?
Malicious LLMs are models that are developed, modified, or marketed for uses that mainstream AI services typically restrict. Threat actors advertise these models for activities such as phishing, social engineering, malicious code generation, fraud, and analysis of compromised data.
In August, Flashpoint observed continued discussion of these models, including MessiahGPT, an unrestricted LLM marketed specifically around malicious use cases.
See Flashpoint in Action
Get real-time curated data, expert analysis, and AI-driven insights to monitor threats across the surface, deep, and dark web—including closed sources.