A Former Internet Godfather Explains How AI Gives Criminals a Head Start

Brett Johnson built some of the first organised online crime networks. Now he's showing security conferences exactly how fast AI lets attackers work, and why defenders are still catching up.

ThreatVectr Newsdesk· 4 min read
Close-up overhead shot of a plain laptop keyboard in a dimly lit office, the screen glowing pale blue, an inbox interface faintly reflected on the desk surface,
Share

Key points

  • Brett Johnson, once placed on the US Most Wanted list for 39 felonies, now consults with law enforcement and businesses on cybercrime defence.
  • At Black Hat USA 2025 in Las Vegas, Johnson demonstrated alongside security firm Illumio how AI dramatically shortens the time criminals need to plan and carry out an attack.
  • Johnson argues AI currently benefits attackers more than defenders, and expects that imbalance to last three to seven years.
  • AI is lowering the skill level needed to commit cybercrime, meaning more people can now attempt attacks that once required specialist knowledge.

Who is Brett Johnson and why should I listen to him?

Johnson is not a pundit. He built and ran Shadow Crew, the first organised online criminal marketplace, which laid the groundwork for the hidden online markets that still operate today. The US Secret Service called him the "original Internet Godfather." He pleaded guilty to 39 felonies, landed on the US Most Wanted list, escaped from prison once, and later stole $600,000 in four months before his luck finally ran out. After serving his sentence, he changed direction. Today he advises law enforcement agencies and private companies on how to stop the kinds of attacks he once ran.

His Black Hat presentation, first reported by Dark Reading, was built with Illumio, a network security company. The subject: how AI, meaning computer systems that can learn and reason, has changed the economics of launching a cyberattack.

How does AI actually help criminals work faster?

Before any break-in, criminals do homework. Which company is worth targeting? Which employees have useful access? Where is the most valuable data kept? That research used to take real time.

AI cuts that waiting. Feed it basic details about a target organisation and it identifies the most valuable information to steal, the weakest points to push through, and the fastest path once inside. Johnson describes it as compressing the attack: instead of researching for hours or days, a criminal can move almost straight to the break-in itself.

Defenders, by contrast, are still working in the old rhythm. When they spot an intruder inside their systems, they have to figure out what is happening in real time. The attacker already has AI-generated answers. The defender is still asking questions.

Phase Before AI With AI
Target research Hours to days Minutes
Identifying valuable data Manual digging Automated summary
Planning the attack path Skilled work Guided by AI
Defender response time Same Unchanged

Is AI helping the defenders too?

Some, but not enough yet. Johnson is blunt: AI is reactive on the defence side. To learn how to stop a new type of attack, a defensive AI system first has to see that attack succeed. It learns from damage already done. Criminal AI, meanwhile, helps plan attacks that have not happened yet.

Johnson expects this gap to persist for three to seven years before defensive tools catch up. For now, attackers are getting the better end of the arrangement.

There is a second, quieter concern. Because AI handles so much of the technical work, criminals no longer need deep expertise. Online criminal communities already share tutorials and techniques freely. AI makes those communities even more accessible. Hospitals, schools, and other organisations that might once have seemed low-value targets because attackers lacked the skill to hit them properly are now well within reach.

What should ordinary people actually do?

If you work for an organisation of any size, assume the people trying to break in are faster and better-equipped than they were two years ago. Watch for phishing emails, which are fake messages designed to trick you into handing over your login details. Question urgent or unusual requests, even from addresses that look familiar. Report anything odd to your IT team rather than handling it yourself.

MFA, short for multi-factor authentication, meaning a second check beyond just a password (such as a code sent to your phone), remains one of the most effective basic defences. It would not stop every attack Johnson describes, but it raises the cost of entry enough to matter.

© 2026 Threat Vectr