(© Yurii - stock.adobe.com)
Cybercriminals Are Using AI the Same Way You Do: To Avoid Reading the Manual
In A Nutshell
- A new study combing through more than 175,000 cybercrime forum posts found AI hasn’t triggered the hacking revolution many feared
- Criminals mostly use AI tools the same way office workers do, to check code, look up answers, and avoid reading the manual
- Newcomers hoping AI would turn them into instant hackers are finding pre-made scripts still work better
- Researchers found that safety guardrails on mainstream chatbots are actually working, with jailbreak tricks typically dying out within a week
Doomsday predictions about artificial intelligence often go something like this: a rogue AI breaks free, seizes control of power grids and financial systems, and holds civilization hostage. It’s the stuff of blockbuster movies and breathless congressional hearings. A new research paper suggests the actual overlap between AI and cybercrime looks a lot less like a sci-fi thriller and a lot more like a teenager copying and pasting someone else’s homework.
Researchers examining how criminals in the digital underground use generative AI found something surprisingly boring: criminals mostly use these tools the way a lazy office worker might, to check code for errors, look up quick answers, and avoid reading the manual. The grand disruption many feared hasn’t materialized. Not yet, anyway.
Cambridge, Edinburgh, and Strathclyde researchers Jack Hughes, Ben Collier, and Daniel R. Thomas, in a paper posted to arXiv, coined two terms for the range of possible futures: the “Stand-Alone Complex,” where a single person could run an entire criminal operation that once required a whole gang, and “Vibercrime,” a play on “vibe coding,” where casual users let AI write software with minimal technical knowledge. Analyzing early data from real criminal communities, researchers found little evidence that even this lower-end vision has taken hold at scale.
That conclusion is drawn from CrimeBB, a Cambridge Cybercrime Centre archive of more than 100 million posts from underground hacking and fraud forums, narrowed down to more than 175,000 discussion threads that mentioned AI since ChatGPT’s debut in late 2022.
AI Could Turn One Criminal Into an Entire Cybercrime Gang
Researchers borrowed a framework from business economics, treating cybercrime as an ecosystem of small tech startups, to see where AI tools might fit.
“Cybercrime-as-a-service” has been around for years: criminal organizations sell ready-made hacking tools, stolen data, and attack infrastructure much like software subscriptions. The fear was that AI could replace these providers with a “cybercrime-gang-in-a-box,” letting one person run an entire, largely automated enterprise.
That’s the Stand-Alone Complex, the upper limit of disruption. Researchers found little evidence that it’s happening at any meaningful scale.
Real Cybercrime Use of AI Looks More Like Copy-Pasting
Early data painted a far more ordinary picture: generative AI found traction mostly in “large-scale, low-profit passive income schemes and forms of fraud.” In practice, that often looks like AI-written blog posts stuffed onto spammy SEO sites, cut-rate ebooks assembled with a chatbot’s help, and social-media bots dressed up to look a little more human. The bigger disruption showed up in logistics and automation, including bot farming, scam outreach, and social-media operations tied to romance scams. Less heist movie, more assembly line of small-time scams.
For criminals already skilled at coding, AI tools replace things they already did: copying snippets from forums, running error checks, consulting cheat sheets. It’s a productivity boost, not a revolution, helping with routine tasks rather than enabling new kinds of attacks.
Newcomers, the would-be “vibercriminals,” are finding AI coding assistants less useful than the pre-made scripts already circulating underground. A ready-to-use script from an experienced hacker still beats a beginner’s AI-generated code.
The Social Club AI Can’t Replace
One notable finding involves modified chatbots altered to answer questions a normal one would refuse, like how to hack a system or build malware. Security researchers and media outlets have warned these tools could replace experienced mentors as criminal tutors.
Researchers argue that concern is overblown, for a deeply human reason: learning to hack isn’t just technical knowledge, it’s a social process. New users value the relationships, belonging, and identity that come from learning skills from others, and the shared language and status that hold any subculture together. A chatbot can spit out instructions, but it can’t offer any of that, and for many newcomers, the journey through forums and reputation-building is inseparable from the destination.
The AI Cybercrime Threat Remains Preliminary, Not Imminent
None of this means AI will never meaningfully change cybercrime, and it would be a mistake to read these early findings as an all-clear signal. Researchers are mapping the present, not predicting the future, and adoption could shift as tools grow more capable. The Stand-Alone Complex is still a hypothetical, worth watching rather than fearing right now.
Real-world adoption of new technology, legitimate or criminal, rarely follows the explosive paths futurists predict. It’s messy, gradual, and constrained by existing habits.
Criminal ecosystems, it turns out, have the same inertia as legitimate ones: existing tools work well enough, skilled practitioners don’t need AI to do what they already know, and newcomers find it doesn’t make them any more skilled, just hands them a shinier version of resources that were already free.
There’s a reassuring wrinkle in the data, too. The safety guardrails built into mainstream chatbots appear to be working. Jailbreak tricks that circulate on hacker forums tend to stop working within a week or so, and researchers found that friction alone was often enough to keep casual users from scaling up.
Right now, the real threat looks less like a rogue superintelligence and more like the same old schemes with an updated toolkit. That distinction matters, since misdiagnosing the threat means misallocating the response, and the most grounded approach starts with looking at what criminals are actually doing, not what headline writers fear.
Disclaimer: This article is based on findings from a recent research paper. The authors describe their own conclusions as early and provisional, drawn from an initial, rapidly evolving area of study.
Paper Notes
Limitations
This research is based on what the authors describe as “early empirical data” from cybercrime underground communities. As with any study examining criminal behavior, there are built-in challenges in accessing representative data from these secretive groups. The findings represent an early snapshot of AI adoption in cybercrime and may not capture developments that emerge as generative AI tools continue to evolve rapidly. The authors themselves call their conclusions “initial results,” acknowledging that things could change.
Funding and Disclosures
Jack Hughes is supported by the European Research Council (ERC) under the European Union’s Horizon 2020 research and innovation programme, grant agreement No. 949127. The authors declare no competing interests.
Publication Details
Authors: Jack Hughes, Ben Collier, Daniel R. Thomas | Title: “Stand-Alone Complex or Vibercrime? Exploring the adoption and innovation of GenAI tools, coding assistants, and agents within cybercrime ecosystems” | Subjects: Computers and Society (cs.CY) | Submitted: March 31, 2026 (version 2 posted August 13, 2026, on arXiv) | ArXiv ID: arXiv:2603.29545 | DOI: 10.48550/arXiv.2603.29545







