The advancement of generative artificial intelligence is transforming cybercrime into a much more automated, scalable, and difficult-to-contain operation. This is according to the study "AI.Attackers," developed by Howden, a global brokerage specializing in highly complex insurance, in partnership with the cybersecurity intelligence company Malanta.
According to the analysis, the popularization of artificial intelligence has strongly accelerated the creation of digital structures used in fraud, hacking, and the distribution of malicious programs. The volume of this type of online environment jumped from 6,498 in 2022 to approximately 110,000 in 2024.
The survey also indicates that the growth rate of these criminal structures intensified after the popularization of generative artificial intelligence tools. Between 2015 and 2022, the annual expansion of this type of digital environment was around 32%. Between 2023 and 2024, it increased to a range between 285% and 340% per year.
These structures include online environments used to store malicious code, register fake domains, distribute fraudulent programs, and organize phishing and data theft operations.
The study brings together analyses of international operations linked to digital espionage, fraud, and attacks against organizations in the financial, technology, chemical, and government sectors.
“We are seeing cybercrime undergoing a process of industrialization. Artificial intelligence allows for the automation of steps that previously required highly qualified teams, accelerating attacks and expanding the operational capacity of criminal groups,” highlights Marta Schuh, Director of Cyber and Technology Insurance at Howden Brazil.
Companies lose reaction time
The report highlights a case analyzed by Anthropic in 2025 involving a cyber espionage campaign attributed to a Chinese state actor. According to the study, between 80% and 90% of the attack's tasks were executed autonomously by artificial intelligence agents, with minimal human intervention.
The operation automated activities such as vulnerability assessment, development of intrusion tools, credential theft, movement within compromised systems, and data extraction.
“The AI-driven attack is no longer a theoretical scenario. Today, there are already real operations in which autonomous agents execute virtually the entire attack cycle, drastically reducing the time available for companies to react,” says Marta.
The study also points out that the average interval between the registration of malicious infrastructure and its effective use in attacks reaches 72 days. Furthermore, approximately 82% of the domains analyzed in the monitored operations had not yet been detected by security vendors at the time of the analysis. In practice, this means that much of the infrastructure used by criminals remains invisible for weeks before the effective launch of the campaigns.
The study also estimates that criminal groups can maintain more than ten simultaneous digital operations for less than US$100,000, expanding the scale and repeatability of attacks.
Data from Malanta also shows that each digital criminal operation uses, on average, dozens of domains, subdomains, digital certificates, and fake social media accounts to structure scams, phishing attacks, and the distribution of malicious software.
“This new scenario reduces the effectiveness of traditional cybersecurity models, which typically only act after identifying clear signs of intrusion. With artificial intelligence, attack cycles are becoming increasingly faster, and prevention before the attack is likely to gain prominence in the coming years,” says Marta.



