When Anyone Can Hack: How AI Is Turning Beginners Into Capable Attackers

The old ranking of hackers by skill is breaking down as chatbots hand novices tools that used to take years to learn.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
A person's hands on a keyboard with an AI chatbot interface visible on the monitor, showing how easy-to-use prompts are generating sophisticated attack code and
Share

Key points

  • Security teams have long ranked attackers by skill, from nation-state groups at the top to inexperienced "script kiddies" at the bottom.
  • Cheap access to AI coding assistants is closing that gap, letting beginners produce working attack code without deep expertise.
  • Analysts call the trend "vibe hacking," borrowing from the "vibe coding" label used for AI-assisted software development.
  • Capability is now easier to acquire than intent, which changes how defenders should think about risk.
  • No single group has been publicly attributed to a mass "vibe hacking" campaign yet, but researchers say the tooling is already in criminal hands.

For most of the last twenty years, the security industry sorted hackers into a neat pyramid.

At the top sat nation-state groups: teams paid by governments to spy or sabotage, tracked under names like Sandworm (CrowdStrike's label for a Russian military intelligence cluster) or Mustang Panda (a China-nexus espionage group in the same vendor's taxonomy). Below them came organised criminal gangs running ransomware, malicious software that locks a company's files until a payment is made. At the bottom sat "script kiddies," a slightly cruel label for beginners who copy-pasted public tools they didn't really understand.

That pyramid is starting to wobble.

The reason, as first reported by The Hacker News, is the rapid spread of AI coding assistants: chatbots that write software when you describe what you want in plain English. Analysts have started calling the criminal version "vibe hacking," a nod to "vibe coding," the term developers use when they let an AI do most of the typing. We first covered the tactic on 4 August 2026.

What is "vibe hacking" in plain English?

It's when someone with limited technical skill uses an AI assistant to generate working attack code or phishing lures without needing to understand how any of it works under the hood.

A beginner used to need years to learn how to write a convincing phishing email in six languages, build a small program that steals passwords, and hide it from antivirus software. An AI model can now draft all of that in minutes if the user knows what to ask for. The human steers. The machine does the hard part, and that's what's changed.

The industry's whole risk model assumed skill was the bottleneck.

Who is actually doing this?

No single named group has been publicly tied to a mass "vibe hacking" wave, and defenders should be cautious about single-source attribution here. What researchers are seeing is broader: low-tier criminals on underground forums sharing prompts, jailbreaks (tricks that bypass a chatbot's safety rules), and wrappers around mainstream AI services.

Purpose-built criminal tools marketed as "uncensored" AI assistants exist, though their real capability versus their marketing is still debated. Medium confidence, at best, that any of them match a competent human operator today.

More established clusters are watching too. Groups tracked as Kimsuky (a North Korea-linked espionage actor in Mandiant's naming) have long used social engineering at scale, and generative AI lowers the cost of that work. Overlapping tradecraft with earlier campaigns is likely; wholesale replacement of human operators is not.

What does this mean for ordinary people?

More phishing, better written, in more languages. That's the near-term reality.

Emails that used to give themselves away with clumsy grammar will read cleanly. Fake voice messages and cloned websites will be cheaper to produce. The people targeted, hospital staff, small business owners, council workers, will face more attempts, not fewer. Our earlier reporting on Southeast Asia's fraud factories showed how AI has already industrialised social-engineering operations at scale.

A few sensible habits still hold. Slow down on anything urgent that arrives by email or text. Check web addresses before typing a password. Turn on two-factor authentication, which asks for a second code alongside your password, on email and banking accounts.

The shift defenders need to accept

Capability and intent used to travel together. A skilled attacker was usually a determined one.

That link is loosening. Determined but unskilled people can now reach for capability off the shelf. Defenders who rank risk purely by attacker sophistication will misread the threat picture for the next few years.

The pyramid isn't gone. Its base just got a lot wider.

© 2026 Threat Vectr