The digital black market is evolving

If you thought cybercrime was already a massive issue, the plot thickens. According to fresh data from Halcyon's Ransomware Research Center, hackers are currently on a shopping spree for AI tools in underground forums. Real talk: what used to require elite-level skills is now being commoditized, making it lowkey dangerous for companies and individuals alike.

By the numbers

The growth here is actually wild. Back in late 2025, you’d see fewer than 50 ads for AI tools per month on these platforms. By February, that number exploded to over 1,400. It’s giving "corporate storefront" but for illegal activity; cybercriminals are now using subscription models and streamlined Telegram channels to push their wares.

Some of the price points are alarmingly low. You can grab access to a ChatGPT Plus account for just 10 cents, or jailbreak prompts—which strip away AI safety guardrails—for around 32 cents.

What’s for sale?

Hacker markets are currently pushing four main categories of tools:

  • Jailbroken AI: Prompts to bypass model safety filters.
  • Identity fraud/Phishing: Kits that make impersonating real people a total breeze.
  • Malicious models: Tools like WormGPT, specifically trained to write malware and convincing phishing emails.
  • AI-augmented infra: Systems designed to automate scams, like bots that can call 120 people simultaneously.

Why it matters

While the tech is getting more sophisticated, don't panic just yet. Cynthia Kaiser, head of the Ransomware Research Center, notes that we aren't seeing "autonomous agents" that can run a whole cyberattack from start to finish on their own. Right now, AI is mostly serving as a force multiplier—it’s helping criminals do existing, nasty tasks faster and for way less money. It’s an L for cybersecurity teams everywhere, as the barrier to entry for becoming a dangerous hacker has never been lower.