From Cybercrime to AI‑Crime
The shift from conventional cybercrime toward AI enabled and AI specific criminality, and how this reshapes future threat landscapes
IBONIS
MSc. José L.T. Ayala
10/11/20261 min read


The rapid diffusion of artificial intelligence (AI) is transforming the organisation, scale, and sophistication of criminal activity, extending traditional cybercrime into new forms of AI enabled and AI specific offending. This paper maps the emerging “AI crime” threat landscape by synthesising evidence from recent threat assessments, academic research, and policy reports (2020–2026). We distinguish three interrelated layers: (i) AI as a force multiplier for established cybercrimes (e.g., automated phishing, malware generation, and large scale social engineering); (ii) AI as an enabler of novel harms (e.g., deepfake based fraud, synthetic identity abuse, and manipulation of information ecosystems); and (iii) AI systems themselves as targets (e.g., model theft, jailbreaking, guardrail removal, and adversarial attacks).
(i) AI as a force multiplier for established cybercrimes refers to the use of AI systems—especially generative AI, machine learning, and automation—to enhance the speed, scale, personalisation, credibility, and concealment of recognised cybercriminal activities such as phishing, malware development, fraud, and social engineering, without fundamentally changing their underlying criminal objective. In this framing, AI is an amplifier of capability: the crime remains, for example, phishing or malware distribution, but AI enables it to be conducted more efficiently and with fewer human resources.
(ii) AI acts as an enabler of novel harms when it is used to generate or amplify deceptive, abusive, or manipulative practices that exploit synthetic content and synthetic identities. Key examples include deepfake-based fraud, synthetic identity abuse, and manipulation of information ecosystems through AI-generated disinformation, impersonation, and coordinated influence operations. These harms are distinctive because AI increases their realism, personalisation, speed, scalability, and accessibility, while undermining trust in digital information and institutional verification processes.
(iii) "AI systems themselves as targets” means that the AI model or AI-enabled application is not merely a tool used by an attacker; it is the direct object of attack. The attacker seeks to compromise its confidentiality, integrity, availability, safety controls, or intellectual property. Adversarial machine learning studies attacks against machine-learning systems across development, training, and deployment.
