Threat Intelligence
22 Million Reasons to Rethink Your 2027 Threat Intelligence Plan
Flashpoint tracked 22 million illicit AI posts in six months. See new data on AI threats, threat intelligence spending, and agentic AI to shape your 2027 plan.
22 million. That is how many illicit posts discussing, sharing, or advertising AI toolkits for criminal use Flashpoint tracked in the first six months of 2026. The figure comes from Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition, built on 3.9 petabytes of data collected from illicit forums, encrypted channels, and attacker infrastructure.
The number matters less for its size than for what it signals. Threat actors have moved AI out of the lab and into daily operations. They use it to profile targets, write phishing lures, evade detection, and generate exploits. Every one of those steps used to take skill and time. Now it takes far less of both.
That creates a planning problem. Most threat intelligence programs were built for a world where adversaries moved at human speed. As security leaders finalize 2027 budgets, the question is no longer whether AI belongs in the threat intelligence program. It is how fast the program can adapt to an adversary that already uses it.
This article takes a data-driven look at three questions:
- How is AI changing the threat landscape? What the latest data shows about the growth of AI-enabled threats and how adversary behavior is shifting.
- How are threat intelligence leaders investing in AI? New benchmark data on AI spending and adoption, where leaders are putting money, and how they approach agentic AI.
- Where is threat intelligence headed next? What these findings signal for 2027, plus a practical planning checklist and answers to the questions we hear most often.
How AI is transforming the threat landscape
AI has not invented a new kind of attacker. It has made every existing attacker faster, cheaper, and harder to see. The first half of 2026 shows that shift across six measures.
| Measure (H1 2026 unless noted) | Figure | Why it matters |
|---|---|---|
| Illicit posts about criminal AI toolkits | 22 million+ | AI is now routine in criminal operations, not an experiment |
| Illicit AI posts, July 2026 alone | 5.58 million (up 18% from June) | Volume is still climbing month over month |
| Hosts infected by infostealers | 7.4 million (1.7 billion credentials and identity artifacts) | Stolen session tokens let attackers skip the password entirely |
| Vulnerabilities published with working exploit code | 4,015 of 21,667 (nearly 1 in 5) | The gap between disclosure and attack is shrinking |
| Verified ransomware victims | 6,256 (up 45% year over year) | More victims, even as fewer pay |
| Average price of initial network access | $439 (down 69%) | Automation has made breaking in cheap |
Sources: Flashpoint 2026 Global Threat Intelligence Report: Midyear Edition, via SiliconANGLE; Flashpoint AI Threat Report, August 2026.
From experiment to everyday tooling
Threat actors now use AI for target profiling, phishing content, malware evasion scripts, and exploit generation. Flashpoint CEO Josh Lefkowitz described AI as "compressing the time between opportunity and exploitation." Work that once required a skilled operator now requires a prompt.
The underground has built a service economy around this. Telegram hosts most of the activity, functioning as a marketplace for jailbreak prompts, fraud kits, and access to unrestricted language models. When a prompt stops working, sellers push updated versions within hours.
Identity is the new front door
The fastest-growing use cases target identity. In July 2026, Flashpoint recorded nearly 395,000 posts advertising Know Your Customer (KYC) bypass methods. Many bundle deepfake video, cloned voices, and AI-written scripts into ready-to-use kits.
These kits combine with stolen credentials and session tokens in a single workflow. Help desks, account recovery, and vendor onboarding are now direct targets. A cloned voice calling the IT help desk is no longer a hypothetical scenario.
The activity is going dark
The most important finding may be the least visible. Much criminal AI tooling has moved off public forums. Threat actors now run custom models with safety guardrails removed, on private infrastructure they control.
That creates a visibility gap. Threat intelligence programs that rely on public feeds and open-web monitoring will see less of the activity that matters most.
What this means for healthcare
Healthcare feels this pressure directly. Healthcare organizations faced 410 ransomware attacks worldwide in H1 2026, up about 14% from the prior half, according to Comparitech data reported by Becker's Hospital Review. The U.S. accounted for 225 of them.
The sharpest growth came around the edges of care. Attacks on billing companies, health tech firms, and other healthcare businesses rose nearly 35%. Qilin, the most active ransomware group overall in H1 2026, was also among the most active against healthcare providers. For a clinic or practice, that means risk now arrives through vendors as often as through the front door.
How threat intelligence leaders are investing in AI
Budgets are rising and AI is in production, but defenders are adopting it far more cautiously than attackers. Four recent industry studies tell a consistent story.
| Benchmark | Figure | Source |
|---|---|---|
| Security professionals planning to increase threat intelligence spending in 2026 | 91% | Recorded Future (600+ respondents) |
| Organizations that spent more than $250,000 on threat intelligence in 2025 | 76% | Recorded Future |
| Organizations using AI in their CTI program today / planning to | 45% / 32% | 2026 SANS CTI Survey (~500 respondents, incl. 67 CISOs) |
| Organizations running AI in the SOC today / evaluating or piloting | 40% / 56% | Prophet Security State of AI in the SOC 2026 (250 respondents) |
| CISOs who have fully deployed agentic AI in security operations | 6% | Splunk CISO Report 2026 (650 CISOs) |
| CISOs who rate CTI as valuable / say it significantly influences decisions | 91% / 26% | 2026 SANS CTI Survey |
Spending follows the threat
The investment case is no longer hard to make. Security teams cite AI-assisted attacks as a leading reason to spend more on intelligence. In Recorded Future's research, 83% of organizations now staff dedicated, full-time threat intelligence teams. Two in five reported fewer incidents after launching a threat intelligence program.
The priorities are shifting, too. In Prophet Security's survey, securing AI systems (56%) and using AI to improve security operations (53%) both ranked among the top three priorities for the next 12 months. That is the first time both sides of AI made the list together.
AI is doing the unglamorous work first
Where AI is deployed in CTI programs, it handles volume, not judgment. The SANS survey found the top uses are data summarization and report writing (56%), data parsing and extraction (46%), and workflow automation (45%). Another 42% get AI through features embedded in vendor products.
That is the right place to start. CTI teams are small, often four people or fewer, and 44% say lack of time is a top barrier. AI that clears the collection and reporting backlog gives analysts hours back for analysis.
The early results are measurable. Among teams running AI in the SOC, 72% cut alert investigation time by at least 25%. But building it alone is risky: 46% of teams that built their own AI tooling have since abandoned or replaced it.
Agentic AI: interest is high, autonomy is earned
Agentic AI refers to systems that plan and take multi-step actions on their own, such as triaging an alert, gathering evidence, and proposing a response. Security leaders want it, but few let it act unsupervised.
- Human review stays standard. 57% of SOC teams using AI still require a human to review every AI verdict before an alert is closed.
- Autonomy is tiered by risk. 44% let AI recommend actions that people execute. 30% allow auto-execution of low-risk actions. No respondent grants full unsupervised autonomy.
- Trust is the blocker, not budget. The top barriers are data privacy concerns (44%) and lack of explainable reasoning (41%).
- Early adopters see the payoff. In Splunk's research, CISOs who had adopted agentic AI were twice as likely to strongly agree it sped up reporting (39% versus 18%).
The same CISOs see the risk on the other side. 86% fear agentic AI will make social engineering attacks more sophisticated.
The real gap is influence, not information
The most telling number in this research is not about AI at all. Nine in ten CISOs value threat intelligence, but only about one in four say it significantly shapes their decisions. CISOs say they want two things above all: intelligence on actively exploited vulnerabilities (79%) and specific adversary tactics, techniques, and procedures (TTPs) (77%).
That gap is where AI investment should land. Programs that use AI to produce more reports will not close it. Programs that use AI to turn findings into clear recommendations will.
Where threat intelligence is headed next
The data points to one conclusion: in 2027, threat intelligence programs will be judged on speed and decisions, not on volume of reporting. Five shifts follow from that.
| From | To | What drives the change |
|---|---|---|
| Public feeds and open-web monitoring | Primary-source visibility into closed communities | Criminal AI tooling is moving to private infrastructure |
| Severity-sorted patch queues | Exploit-driven prioritization | Nearly 1 in 5 disclosures ship with working exploit code, and thousands appear before they reach the National Vulnerability Database |
| Password-centric identity defense | Session, token, and help-desk defense | 7.4 million infostealer infections and deepfake-ready KYC bypass kits |
| Human-speed triage | AI-assisted triage with human judgment on top | Machine-speed attacks against teams that need 30+ minutes per alert |
| Threat reports | Decision-ready recommendations | Only 26% of CISOs say CTI significantly influences their decisions |
1. Visibility will become the scarce resource
As adversaries move AI tooling into private channels, the open web shows less of what matters. Programs will need sources that reach closed forums, chat services, and marketplaces. For most organizations, that means buying access through a partner rather than building it.
2. Exploitation, not severity, will set priorities
A Common Vulnerability Scoring System (CVSS) score tells you how bad a flaw could be. It does not tell you whether anyone is using it. With thousands of new vulnerabilities each half-year, teams that patch by severity alone will fall behind. Intelligence on active exploitation becomes the sorting key.
3. Identity will be the main battleground
Stolen session tokens bypass passwords and multi-factor authentication (MFA). Cloned voices target help desks and account recovery. Expect intelligence programs to watch for leaked credentials and tokens tied to their own staff and vendors, and to feed that directly into identity controls.
4. Agentic AI will expand, one guardrail at a time
The adoption data shows the path. Teams start with summarization and enrichment, measure AI verdicts against their own analysts, and widen autonomy only as accuracy is proven. Expect 2027 to bring more auto-executed low-risk actions, not unsupervised agents.
5. Intelligence will be measured by the decisions it changes
CTI teams that cannot show impact will struggle to defend budgets. The programs that thrive will lead with a recommendation, back it with evidence, and tie it to a business decision: which vendor to onboard, which system to patch first, what to tell the board.
What this means for healthcare organizations
Healthcare providers rarely have a dedicated threat intelligence team, yet they face the same machine-speed adversaries. Attacks on billing firms, health tech vendors, and other healthcare businesses grew fastest in H1 2026. That makes vendor risk a threat intelligence problem, not just a compliance checkbox under HIPAA (the Health Insurance Portability and Accountability Act).
The practical answer for most clinics and practices is not to build a CTI function from scratch. It is to work with a fully managed security partner that brings primary-source intelligence, AI-assisted triage, and human analysts, so your team stays focused on patient care.
Your 2027 threat intelligence planning checklist
- Map which intelligence sources reach closed criminal communities, and where you are blind
- Re-rank your vulnerability backlog by active exploitation, not CVSS score alone
- Monitor for leaked credentials and session tokens tied to your staff and key vendors
- Harden help-desk and account-recovery workflows against voice and video impersonation
- Pick two or three high-volume, low-judgment CTI tasks to hand to AI first
- Set a written autonomy policy: what AI may recommend, auto-execute, or never touch
- Measure AI verdicts against your analysts before expanding autonomy
- Add threat intelligence review to vendor onboarding, especially billing and health tech partners
- Define two metrics that show which decisions intelligence changed this quarter
- Budget for securing your own AI tools, not only for using AI in defense
Q&A: what security leaders are asking
How are threat actors using AI in 2026?
Threat actors use AI to profile targets, write convincing phishing lures, generate exploit code, and evade detection. Identity fraud is a fast-growing use: kits that combine deepfake video, cloned voices, and AI-written scripts are sold openly to bypass identity checks. Increasingly, attackers run unrestricted models on private infrastructure, out of public view.
Should we increase our threat intelligence budget for 2027?
Most peers are. In Recorded Future's research, 91% of security professionals planned to raise threat intelligence spending. The better question is where. Prioritize sources that reach closed criminal communities, intelligence on actively exploited vulnerabilities, and AI that frees analyst time. More raw data feeds rarely improve outcomes on their own.
Is agentic AI ready to run our security operations?
Not unsupervised. Only 6% of CISOs in Splunk's 2026 research had fully deployed agentic AI, and no team in Prophet Security's survey grants full autonomy. Start with AI that recommends actions and auto-executes only low-risk steps. Measure its verdicts against your analysts, then widen its authority as accuracy is proven.
What should a small healthcare organization do without a threat intelligence team?
Focus on the threats most likely to reach you: phishing, stolen credentials, unpatched exploited systems, and compromised vendors. A fully managed security partner can deliver threat intelligence, 24/7 monitoring, and HIPAA-aligned response without an in-house security team. That gives you enterprise-grade coverage on a practice-sized budget.
How do we prove threat intelligence is worth the investment?
Tie intelligence to decisions. Track which patches were reprioritized, which vendors were flagged, and which incidents were prevented or contained faster. The 2026 SANS survey found nearly half of CTI programs do not gather systematic feedback on effectiveness. Programs that measure impact are the ones that keep their budgets.
Sources
- Criminals have moved AI out of testing and into daily use, Flashpoint finds, SiliconANGLE, August 13, 2026 (coverage of Flashpoint's 2026 Global Threat Intelligence Report: Midyear Edition)
- AI Threat Report: How Artificial Intelligence Is Used Across Illicit Communities, Flashpoint, August 27, 2026
- Healthcare ransomware attacks up 14%: 5 things to know, Becker's Hospital Review, July 10, 2026 (Comparitech data)
- AI-driven cyber threats spur surge in intel spending, SecurityBrief, December 11, 2025 (Recorded Future research)
- 6 Key Findings from the SANS CTI Survey, Flare, June 23, 2026 (2026 SANS Cyber Threat Intelligence Survey)
- CISOs cautious as agentic AI adoption in security lags, SecurityBrief UK, February 24, 2026 (Splunk CISO Report 2026)
- State of AI in the SOC 2026: 8 Key Takeaways, Prophet Security, August 3, 2026