
Threat intelligence firm Flashpoint has published the midyear edition of its 2026 Global Threat Intelligence Report, which says criminals have stopped experimenting with AI and started operating on it.
In the six months to 30 June 2026, Flashpoint counted more than 22 million threat actor posts discussing, sharing or advertising AI toolkits built for criminal use. Over the same period, it logged more than 7.4 million compromised hosts worldwide, from which attackers extracted 1.7 billion credentials and identity data points.
Stolen credentials on their own are a haystack: millions of usernames, passwords and session cookies, most of them dead. Finding the few that still work was the slow part. AI can now test them all, and quickly.
“AI is compressing the time between opportunity and exploitation,” said Flashpoint co-founder and CEO Josh Lefkowitz. “Capabilities that once took significant expertise, coordination and time to develop are becoming faster to build, easier to scale and harder to detect.”
The cycle Flashpoint set out in its annual report in March runs in four steps:
- Infostealer malware drains credentials and live session cookies from infected machines;
- The logs are fed into agentic AI systems;
- Those systems test the credentials against thousands of endpoints at once – corporate VPNs, SaaS platforms, cloud providers; and
- Successful logins are flagged for fraud or resale.
Flashpoint said such systems can run without continuous human oversight. The cost of a failed attempt falls to almost nothing, so attackers can afford to try everything. And an attacker arriving with a valid session cookie is not breaking a perimeter at all. They look like the employee whose laptop was infected.
Fewer victims pay, so demands rise
Flashpoint recorded a 45% period-on-period increase in ransomware-as-a-service activity in the first half of 2026. The money went the other way: Chainalysis found on-chain ransomware payments fell 8% in 2025 to US$820-million, and that the share of victims who paid dropped to 28% – the lowest it has recorded, down from 62.8% in 2024. Those who did pay paid far more: the median ransom rose 368% to $59 556.
More attacks and fewer payers is what pushes criminals away from encryption and towards data-leak extortion and social engineering.
Read: AI fraud is outrunning South African banking defences
Interpol’s African Cyberthreat Assessment Report 2026 reaches the same conclusion, but from the opposite end. It found AI was linked to 55% of reported cybercrime in Africa, and that South Africa accounted for 92% of ransomware detections recorded on the continent in 2025.
That figure needs care, though: it is a share of detections logged by TrendAI, one of Interpol’s private-sector telemetry partners, not a share of attacks. South Africa has far more security sensors deployed than its neighbours, so it sees more of what happens to it. Reported continental losses more than doubled to $484-million in 2025 from $192-million, while Interpol put the true direct economic damage at $5-billion or more, against continental cybersecurity spending of $15.3-billion.

Southern Africa carried the heaviest burden of ransomware, phishing and denial-of-service attacks, and South Africa alone recorded more than 213 000 DDoS incidents, one of them peaking at 312Gbit/s.
“AI is automating every stage of a cyberattack from reconnaissance and phishing to extortion and evasion,” said Neal Jetton, director of Interpol’s cybercrime directorate.
Sabric’s 2025 banking crime statistics, published last week, show where the local exposure lies. Digital banking claims reached R2.4-billion across 110 074 investigations, up 29.2% on 2024’s R1.86-billion, with the average loss per case climbing to R21 865 from R19 095. The money grew faster than the case count. Banking apps accounted for 88.6% of investigations and 70.5% of claim value.
Impersonation
Sabric made it clear that this is not evidence of banking systems being breached. “In many cases, the fraud began outside the banking platform, when criminals impersonated trusted organisations, created urgency or guided customers through transactions in real time.”
Flashpoint identifies the same weakness globally. It logged 91 321 insider recruitment and solicitation posts in 2025 and said telecommunications drew more insider-related activity than any other sector, because telecoms staff control number porting and Sim provisioning. South African bank security still leans on the SMS one-time Pin, although Sabric noted that Sim-swap indicators were less common in 2025 than in earlier years. Telecoms fraud costs the country an estimated R5.3-billion a year. – © 2026 NewsCentral Media
- Subscribe to TechCentral’s daily newsletter
- Get breaking news alerts on WhatsApp



