AI Adoption Challenges for Cybercriminals, Study Reveals

The Role of AI in Cybercrime: A New Challenge
Recent research has revealed that cybercriminals are finding it difficult to effectively utilize artificial intelligence (AI) in their illegal activities, despite the growing presence of AI technologies in various sectors. This insight comes from an analysis of approximately 100 million posts from underground and dark web cybercrime communities.
The study was conducted by a team of researchers from the universities of Edinburgh, Strathclyde, and Cambridge. They examined discussions from the CrimeBB database, which contains over 100 million posts collected from dark web and underground cybercrime forums. Using a combination of machine learning tools and manual sampling techniques, the researchers analyzed conversations for mentions of AI experimentation among cybercriminals.
The research focused on how cybercriminals, often referred to as hackers, have been exploring AI technologies since November 2022, a period that coincided with the release of ChatGPT. Surprisingly, the findings indicate that AI coding assistants are not significantly lowering the skill barrier required for committing cybercrime. Instead, these tools are proving more beneficial for those who already possess advanced skills and knowledge.
Key Findings from the Research
- Social Media Bots: AI is being used most effectively for running social media bots that engage in misogynistic harassment and generate income through fraud.
- Hiding Patterns: Cybercriminals are also using AI to obscure patterns that could be detected by cybersecurity defenders.
- Guardrails on Chatbots: The researchers noted that the guardrails implemented on major chatbots are helping to reduce potential harm caused by AI misuse.
Dr. Ben Collier, a senior lecturer in digital methods at the University of Edinburgh’s School of Social and Political Science, emphasized that while cybercriminals are experimenting with AI tools, they are not yet reaping significant benefits from them.
"Our message to industry is: don’t panic yet. The immediate danger comes from companies and members of the public adopting poorly secured AI systems themselves, opening them up to catastrophic new attacks that can be performed by cybercriminals with little effort or skill," he said.
Cybercriminals' Concerns and Potential Risks
The research also highlighted that many individuals in cybercrime communities are worried about losing their "day jobs" in IT due to the impact of AI in mainstream software industries. This fear could potentially push them and others toward increased cybercriminal activity.
The report authors warned that the main risks to industry are likely to come from the adoption of poorly secured agentic AI systems—AI that can act autonomously, performing specific tasks and making decisions without human intervention. They also raised concerns about insecure "vibecoded" products, where computer code is written using AI by legitimate industry players.
Implications for the Future
The findings of this research have undergone peer review and will be presented at the Workshop on the Economics of Information Security in Berkeley, US, in June. As AI continues to evolve, it is crucial for both industry and the public to remain vigilant about the security implications of adopting AI technologies.
While the current use of AI by cybercriminals may not pose an immediate threat, the long-term risks associated with its misuse cannot be ignored. Companies must ensure that any AI systems they implement are secure and well-guarded against potential exploitation.
As the landscape of technology continues to shift, staying informed and proactive about AI security will be essential for preventing future cyber threats.