
Anastasiya Novikava
Copywriter
Trends & statistics

Summary: Dark web AI discussions rose after each LLM release and surged by 44% following Claude Opus 4.6.
New analysis from NordLayer shows that the volume of AI discussions on the dark web changes after each new large language model (LLM) release. The largest jump on record happened in February 2026, when AI discussions on dark web forums spiked right after the Claude Opus 4.6 release and then stayed high.
NordLayer analyzed data from NordStellar, a threat intelligence platform, and tracked how AI mentions on dark web forums and Telegram channels changed around major model launches. Each new LLM release is followed by a jump in AI discussion on the dark web.

Data reflects the total volume of dark web posts containing keywords for major AI tools like ChatGPT, Claude, and Gemini.
On average, dark web discussions about AI rise by around 11% after a new LLM release. Most of these jumps used to be temporary. A model would launch, discussion would spike, and then activity would return to normal after a few weeks.
However, in February 2026, following the Claude Opus 4.6 release, the number of posts mentioning AI on dark web forums rose by 44% compared to the month before. This was the biggest increase on record.
Discussion then stabilized at a new, higher level of roughly 2,500 posts per month, and it has stayed there for 4 straight months.
Before Claude Opus 4.6, the discussion always returned to its earlier level. This time, however, it did not, and the new, higher volume has become the norm.
One clarification on the timing: the number of posts went up right after the release, but the data only counts how often AI is discussed. It does not measure why. The increase reflects the wide public interest around a major release, not any action by the company behind the model.
Why does the dark web react so quickly to new releases? “Today’s cybercriminals are highly opportunistic. They most likely monitor new releases to gauge their potential impact on the digital ecosystem. The pre-release baseline for Claude Opus 4.6 was already elevated, a reflection of how normalized AI has become as a topic across all online communities, including underground forums,” says Andrius Buinovskis, Head of Product at NordLayer. “The additional spike likely reflects the broader cultural moment. This release came at a point of intense public debate around AI capabilities, safety, and regulation, and it goes to show that these conversations aren’t just happening on the surface web.”
This part looked only at general AI discussion, meaning any post that mentions ChatGPT, GPT-4, Claude AI, Gemini AI, or Copilot AI. We see that interest in AI among criminal communities keeps rising with each release, and after Claude Opus 4.6, it settled at a permanently higher level.
The number of dark web discussions that mention AI alongside cybercrime has also been climbing, and now averages around 500 posts per month. This section covers how often AI shows up next to cybercrime topics.
To measure this, the research looked at posts where an AI keyword appeared together with a specific crime keyword in the same forum or Telegram post: AI and crime, AI and ransomware, AI and phishing, AI and stealer, and AI and jailbreaking. The terms do not need to appear next to each other, so the counts reflect how often these topics overlap in dark web posts rather than exact phrases.
The main AI-plus-crime categories changed as follows, based on full-year totals for 2024 and 2025 and the first 5 months of 2026.

Phishing leads AI-related dark web activity. From January through May of 2026, 303 AI-plus-phishing posts were recorded, which is already 61% of the 497 posts seen across all of 2025. AI removes the telltale signs people once used to spot a scam.
“When it comes to phishing, AI is instrumental in removing the initial red flags. Before the rise of LLMs, users would often identify scammers through poor grammar and awkward phrasing,” explains Vakaris Noreika, cybersecurity expert at NordStellar. “AI enables even non-native speakers to craft highly convincing messages. On top of that, LLMs allow for the accelerated personalization of large-scale attacks by tailoring hundreds or even thousands of phishing emails and messages with personal information scraped from public databases, like social media profiles.”
Microsoft has reported that AI-driven phishing is now 4.5 times more effective than conventional phishing. The company also warns that AI-generated IDs and deepfakes can get past verification steps, including the selfie and liveness checks many platforms rely on.
Phishing is both the most common and the fastest-growing way criminals are applying AI, and it is getting harder for people and automated checks to catch.

But phishing is not the only category rising. AI jailbreaking discussions rose 73% in 2025, discussions pairing AI with infostealer malware rose 52%, and AI-plus-ransomware discussions rose 50%.
However, discussions about branded malicious AI tools have stalled. Purpose-built criminal tools like WormGPT and FraudGPT barely moved, with 155 posts in 2025 and 93 in the first 5 months of 2026. “It seems that cybercriminals have realized that jailbroken versions of mainstream AI tools are more powerful than custom-built malicious solutions,” says Noreika. “Malicious AI tools are very niche, and they lack the same level of training present in widespread LLMs.”
Users and organizations should expect more attacks and prepare for a wave of AI-powered cybercrime.
“Highly convincing, high-volume attacks are becoming the new baseline,” says Buinovskis. “It’s now easier than ever to become a cybercriminal. Technical skills are no longer a requirement. Users and organizations are getting hit from both sides. Veteran hackers use AI to scale their operations, and a whole new wave of beginners joins the ranks every day.”
Because these attacks are built to get past both software filters and human judgment, awareness comes first.
“A cautious approach is now more vital than ever. Spotting AI and AI-powered attacks can be difficult, even for seasoned cybersecurity experts,” says Buinovskis. “These attacks are designed to bypass both filters and human intuition, especially when we’re rushed. My key recommendation is to step back and critically assess any message that pushes you to act immediately. In the age of AI, a healthy dose of skepticism is our first line of defense.”
Awareness helps, but people still make mistakes under pressure, so it needs to be backed by technical controls. Buinovskis points to a set of steps that work together:
While criminals are scaling their operations with AI, the underlying attack methods have not changed, so the basics still work when they are applied consistently.
Turn on multi-factor authentication, keep software and browsers updated, train staff to slow down on urgent-sounding messages, and monitor for leaked credentials. AI raises the volume and quality of attacks, but the ways in remain the same, which is why steady, well-covered fundamentals are the most reliable defense.
NordLayer and NordStellar analyzed dark web activity between January 2024 and May 2026, tracking keyword-specific discussions across underground forums and Telegram. The research focused on the volume of AI-related mentions and how these trends moved in relation to major LLM releases, with release dates taken from public records. The data shows discussion volume, not confirmed active services, but sustained high volume is a reliable proxy for market activity.
Disclaimer: This analysis is based on detected activity and is for informational purposes only. It does not constitute professional advice or a guarantee of security. All third-party trademarks and references remain the property of their respective owners and are used for identification purposes only. This research tracks discussion trends in deep and dark web spaces and does not assess the safety, security, or intent of any AI provider or product.
Subscribe to our blog updates for in-depth perspectives on cybersecurity.