When Anyone Can Hack: How AI Is Turning Beginners Into Capable Attackers

The old ranking of hackers by skill is breaking down as chatbots hand novices tools that used to take years to learn.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style 16:9 image of a dark server room with faint green code reflections across black rackmount hardware, a single keyboard resting on
Share

Key points

  • Security teams have long ranked attackers by skill, from nation-state groups at the top to inexperienced "script kiddies" at the bottom.
  • Cheap access to AI coding assistants is closing that gap, letting beginners produce working attack code without deep expertise.
  • Analysts call the trend "vibe hacking," borrowing from the "vibe coding" label used for AI-assisted software development.
  • Capability is now easier to acquire than intent, which changes how defenders should think about risk.
  • No single group has been publicly attributed to a mass "vibe hacking" campaign yet, but researchers say the tooling is already in criminal hands.

For most of the last twenty years, the security industry sorted hackers into a neat pyramid.

At the top sat nation-state groups: teams paid by governments to spy or sabotage, tracked under names like Sandworm (CrowdStrike's naming for a Russian military intelligence cluster) or Mustang Panda (a China-nexus espionage group in the same vendor's taxonomy). Below them came organised criminal gangs running ransomware, which is malicious software that locks a company's files until a payment is made. At the bottom sat "script kiddies," a slightly cruel label for beginners who copy-pasted public tools they did not really understand.

That pyramid is starting to wobble.

The reason, as first reported by The Hacker News, is the rapid spread of AI coding assistants: chatbots that write software when you describe what you want in plain English. Analysts have started calling the criminal version "vibe hacking," a nod to "vibe coding," the term developers use when they let an AI do most of the typing.

What is "vibe hacking" in plain English?

It is when someone with limited technical skill uses an AI assistant to generate working attack code, phishing lures, or malware, without needing to understand how any of it works under the hood.

Think of it like this. A beginner used to need years to learn how to write a convincing phishing email in six languages, build a small program that steals passwords, and hide it from antivirus software. An AI model can now draft all three in minutes if the user knows what to ask for. The human still points and steers. The machine does the hard part.

That matters because the industry's whole risk model assumed skill was the bottleneck.

Who is actually doing this?

No single named group has been publicly tied to a mass "vibe hacking" wave, and defenders should be cautious about single-source attribution here. What researchers are seeing is broader: low-tier criminals on underground forums sharing prompts, jailbreaks (tricks that bypass a chatbot's safety rules), and wrappers around mainstream AI services.

There are also purpose-built criminal tools marketed as "uncensored" AI assistants. Their real capability, versus their marketing, is still debated. Medium confidence, at best, that any of them match a competent human operator today.

More established clusters are watching too. Groups tracked as Kimsuky (a North Korea-linked espionage actor in Mandiant's naming) have long used social engineering at scale, and generative AI lowers the cost of that work. Overlapping tradecraft with earlier campaigns is likely; wholesale replacement of human operators is not.

What does this mean for ordinary people?

More phishing, better written, in more languages. That is the near-term reality.

The emails that used to give themselves away with clumsy grammar will read cleanly. Fake voice messages and cloned websites will be cheaper to produce. The people targeted, hospital staff, small business owners, council workers, will see more attempts, not fewer.

A few sensible habits still work. Slow down on anything urgent that arrives by email or text. Check web addresses before typing a password. Turn on two-factor authentication, which asks for a second code as well as your password, on email and banking accounts.

The shift defenders need to accept

Capability and intent used to travel together. A skilled attacker was usually a determined one.

That link is loosening. Determined but unskilled people can now reach for capability off the shelf. Defenders who still rank risk purely by attacker sophistication will misread the threat landscape for the next few years.

The pyramid is not gone. Its base just got a lot wider.

© 2026 Threat Vectr