Written by Kevin B. McDonald, COO & CISO at Alvaka
The Question Everyone Is Asking About AI
Understandably and rightfully, AI aware humans are genuinely concerned about AI replacing them and diminishing their value in the commercial marketplace. Many developers are sitting on the edge of their seat, wondering when AI development will fully replace them. Writers are seeing people who could not construct complete sentences putting out materials that on the surface seem well informed and insightful. Analysts are worried that machines can read a million times more data points and draw correlations is seconds that a typical human could spend a lifetime working toward. It seems that every business conference, podcast, publication, and LinkedIn thread no matter the vertical revolves in some way around the same question.
Who’s getting replaced by Artificial Intelligence and what then?
What About the Cybercriminal Workforce?
After reading Google’s latest GTIG report, I found myself thinking a lot about a different “workforce” that has a real problem, unless they start their own operations from the ground up.
Cybercriminals who are simple affiliates or specialists in activities that can be replicated by AI consistently.
This is certainly a possibility, but entrepreneurial behavior is unusual, so it is likely that many will just not see future criminal opportunity. For years, ransomware, BEC operations and other cybercrime groups have been operated like a business. My decades of experience shows in fact that some of cybercriminal syndicates are better organized, better funded and more “professional” and effective than far too many legitimate businesses. Of course, cybercriminals are not ethical businesses, but businesses, nonetheless. Much of what holds the hacker and cybercriminal ecosystem together is specialized and unique skills that are (or were) difficult to replicate.
Cybercrime Has Its Own Supply Chain
One group specializes in access and breaking into organizations’ systems. They phish users, steal credentials, exploit vulnerabilities, and plant persistent access. Then they sell that access to the next specialist in the supply chain. The next link in the chain buys access and deploys a myriad of criminal playbooks inside victim environments. While all this is going on yet another group develops the ransomware, builds delivery infrastructure and vets affiliates and finally there are still more that do negotiations and collect the cash.
Everyone gets a piece of the proceeds and supply chains work because different people perform different jobs effectively.
AI Could Disrupt the Cybercrime Business Model
Google’s report suggests that like other industries, something important is changing in the cybercrime world. Threat actors are moving beyond using AI for individual tasks and experimenting with fully autonomous workflows. AIs now perform larger portions of the supply chain with less human involvement. The report also calls out that the crooks are increasingly targeting AI infrastructure, the models themselves, source code, and more.
Most will read all of this and think about faster phishing emails, easier deployment, etc. I think there is a bigger story to celebrate. What happens to an irrelevant access broker? Why pay a human to find vulnerable systems when an AI agent can do it continuously, at greater speed and at a superhuman scale? Why pay to validate credentials or spend days mapping a network when an agent can do it more accurately in hours?
Could AI Create Cybercriminal Unemployment?
Despite all the high-tech headlines, most traditional cybercrime takes people. People create problems. They make mistakes, get lazy, disappear and get arrested. Any group of people can have potential conflicts and otherwise create friction. AI removes human fallibility and friction. We know this worries defenders and it should. But it should also worry criminals that are just cogs in the machine. Productivity tools may end up creating unemployment in the cybercrime economy.
Ironically, the criminals who spent years perfecting everyone else’s misery may soon find themselves competing with automation itself.
What Happens When the Criminals Become the Cogs?
I have often said that ransomware groups are some of the most entrepreneurial organizations on the planet. They have built franchises, complex and functional partner programs, revenue sharing models, effective support desks, service delivery teams, and recruiting processes. They have created an entire underground employment marketplace.
If AI can perform your criminal function with less drama for less money, faster, and around the clock, what exactly is an affiliate’s role? Less humans in a criminal conspiracy means less risk. More AI means the top-level operators keep more of the pie. So, only time will tell if we see more or less criminal actors and whether AI actually helps to take down the criminal economy on a broader scale.
What Executives Should Do Now
- Prepare for fewer attackers but more attacks: Don’t assume shrinking criminal workforces means less risk. AI may allow fewer operators to generate significantly more attacks.
- Adjust threat models for automation: Many security programs still assume human adversaries with limited capacity. Plan for advanced adversaries operating continuously, at scale, and around the clock.
- Invest in security speed, not just security controls: Faster detection, faster decisions, and faster containment are becoming more important than adding another point solution.
- Expect more sophisticated attacks at lower cost: As criminal operations automate, the cost of launching campaigns may fall dramatically.
- Increase monitoring of identity and cloud resources: Identity remains the most valuable target.
- Track AI-enabled changes in criminal behavior: Security teams should monitor how attacks are changing, not just how technology is changing.
- Build security automation carefully: Criminals are automating aggressively. Defenders need automation too, but with governance, oversight, and testing.
- Protect AI assets as business assets: Treat models, prompts, APIs, source code, training data, and cloud infrastructure as critical assets.
Bottom Line
AI may not eliminate cybercrime. It may eliminate cybercriminal jobs. If that happens, organizations should expect leaner, faster, cheaper, and more scalable attacks. The winning strategy will be building defenses that operate at the speed of the threat, not the speed of traditional security operations.
