What changes for your business when someone can buy help with a cyberattack instead of learning how to carry one out?
An October 6 Axios article points to new Halcyon research on criminal AI services. For business leaders, the practical question is how to protect operations when attack preparation becomes more accessible.
Key takeaway: AI can lower the cost and effort of familiar attacks without making every attacker an expert. Businesses should strengthen payment and identity verification while restricting what compromised Windows applications and accounts can do.
So what exactly did the researchers find?
Halcyon documented a growing market for AI tools promoted to criminals. Its findings describe marketplace activity, not a measured increase in successful breaches.
In its Underground AI-as-a-Service report, Halcyon analyzed nearly 4,000 posts collected from October 1, 2025, through May 1, 2026. Advertisements increased from fewer than 50 a month in late 2025 to more than 1,400 by February 2026; 40% of observed messages advertised free offerings.
The offerings covered malicious language models, identity fraud, malware and attack infrastructure, and stolen or jailbroken AI access. Listings can include exaggerated claims and scams. Advertising volume should not be confused with verified capability, purchases, or attack success.
Why does cheaper cybercrime matter to a business?
Our CHIPS analysis is that cheaper assistance can let more attackers attempt familiar crimes and allow existing attackers to spend less time preparing them. That creates a reason to review how much trust everyday business workflows place in convincing communications.
Consider a request to change a supplier’s banking details. If an employee accepts it without independent verification, the loss can happen through a legitimate payment system. There may be no ransomware file for an endpoint security product to block.
A separate path starts when someone follows a fraudulent support instruction and runs software. That could expose business files, credentials, or applications, depending on the access available. Investigation and recovery can interrupt work even when the affected computer is inexpensive to replace.
For MSPs, the useful discussion is customer-specific: Which workflows could authorize a payment, expose credentials, or allow a workstation to reach multiple customers?
Does this prove autonomous AI ransomware is here?
No. This research does not establish a marketplace of reliable systems that independently complete entire cyberattacks.
Generating attack material, automating one step, and running an end-to-end operation are different capabilities. Leaders should ask which capability was actually observed before changing budgets or accepting a vendor’s claim.
The business does not need to wait for complete autonomy to address exposure. A single compromised account or poorly verified payment request can create a material problem. Controls should address those outcomes rather than depend on proving how much AI the attacker used.
Could EDR detect an attack using these tools?
EDR can detect suspicious endpoint activity whether the attacker used AI or wrote the code manually. Its effectiveness depends on the behavior, visibility, configuration, and response available in that environment.
AI assistance does not automatically make malware invisible. Equally, having EDR does not establish that every harmful action will be stopped before damage occurs.
Detection and response remain important for investigation and containment. But endpoint monitoring cannot serve as the approval process for a bank transfer, and an alert arriving after credential theft may still leave recovery work to do.
Ask two questions: “Can we see this activity?” and “What is already prevented while we investigate?”
Can an attack be stopped without identifying it?
Some endpoint attack actions can be prevented by enforcing boundaries without first identifying the threat. That is the practical purpose of Isolation and Containment.
What if you did not have to detect the attack in order to stop it?
In business terms, applications receive limited freedom to perform their work. Controls can restrict unauthorized launches and constrain access to memory, protected files, and system resources. Properly designed boundaries reduce usable Windows attack surface and can prevent damaging writes, including encryption, where the relevant policy applies.
Changing the attack does not necessarily change the endpoint actions the attacker ultimately needs in order to succeed. New code may still need to launch a process, steal information, create persistence, or modify files. Unknown does not automatically mean unstoppable.
AppGuard’s prevention approach illustrates this principle: it restricts out-of-bounds endpoint behavior without requiring the attack to first be identified as malicious. It complements EDR. Endpoint protection still needs identity, network, and business-process controls, particularly for fraud that never involves malware.
What Should Businesses Do Next?
Review both the decisions employees can authorize and the actions applications can perform. Use realistic scenarios to find where one mistake could become a larger loss.
- Verify sensitive requests independently. Confirm banking changes, urgent payments, and credential requests through a known contact method.
- Reduce endpoint execution freedom. Review unnecessary software, administrative privileges, and application access to protected resources. Add Isolation and Containment where appropriate.
- Limit access and blast radius. Review privileged accounts, third-party support access, shared credentials, and connections to critical systems.
- Test prevention and response together. Establish which actions are blocked, which generate alerts, and who responds.
- Practice recovery. Test backup restoration and rehearse stolen-account and payment-fraud scenarios alongside ransomware exercises.
The objective is not to predict every attack. It is to restrict the actions an attacker needs in order to succeed and verify the business decisions that technology alone cannot protect.
For a related discussion, listen to the CHIPS Cybersecurity Podcast episode The Detect and Respond Mirage: Why AI Attacks Demand Isolation and Containment. Use it to ask what your current controls prevent before an alert becomes an incident.
October 10, 2026