Guest Post: Claude Opus 4.6 release saw the biggest surge in AI discussions on the dark web

As individual users and organizations are increasingly adopting AI, cybercriminals are not lagging behind. New dark web analysis from NordLayer, a toggle-ready network security platform, reveals that dark web discussions surrounding AI surged at the beginning of 2026, and dark web posts discussing AI and cybercrime are following an alarming upwards trajectory.

NordLayer analyzed data from NordStellar, a threat intelligence platform, and found that dark web user discussions surrounding AI spiked in February 2026, following the release of Claude Opus 4.6. Compared to a month prior to the release, the number of posts mentioning AI on dark web forums increased by 44%.

The data reveals that the Claude Opus 4.6 release coincided with the biggest surge on record, far above the average increase of around 11% observed around previous large language model (LLM) releases. Previous releases were followed by temporary spikes that eventually subsided. The Claude Opus 4.6 release, however, appears to have elevated the baseline itself — discussions have remained strong at around 2,518 posts per month with no sign of dropping back to pre-release levels.

“Today’s cybercriminals are highly opportunistic — they most likely monitor new releases to gauge potential impact and shifts in the digital ecosystem. The pre-release baseline for Claude Opus 4.6 was already elevated — a reflection of how normalized AI has become as a topic across all online communities, including underground forums,” says Andrius Buinovskis, cybersecurity expert at NordLayer. “The additional spike likely reflects the broader cultural moment. This release came at a point of intense public debate around AI capabilities, safety, and regulation, and it goes to show that these conversations don’t stay on the surface web.”

How cybercriminals are utilizing AI

The findings reveal that the baseline for dark web discussions surrounding AI and cybercrime has also been steadily increasing, now averaging around 500 posts per month. Phishing dominates the landscape of AI-related dark web activity. The 303 posts recorded through January-May 2026 represent 61% of the 497 posts seen in all of 2025, signaling a sharp year-over-year acceleration.


“When it comes to phishing, AI is instrumental to eliminating the initial red flags — before the rise of LLMs, users would often identify scammers through poor grammar and awkward phrasing,” explains Vakaris Noreika, cybersecurity expert at NordStellar. “AI enables even non-native speakers to craft highly convincing messages. Furthermore, LLMs allow accelerated personalization for massive scale attacks, tailoring hundreds or even thousands of phishing emails and messages by including various personal information that was scraped from public databases, like social media profiles.”

The data highlights another interesting trend — despite the rise in general AI discussions, mentions of branded malicious AI tools like WormGPT and FraudGPT totaled just 155 in 2025 and 93 in the first five months of this year — a stark contrast to the growth seen in broader categories.

“It seems that cybercriminals have realized that jailbreak versions of traditional AI tools are more powerful than custom-built malicious solutions,” says Noreika. “Malicious AI tools are very niche, and they lack the same level of training that’s present in widespread LLMs.”

Ramping up defenses against AI-powered cybercrime

According to Buinovskis, the analysis of dark web discussions surrounding AI is a clear indicator that while AI adoption is rising, cybercriminals are following fast behind. He says that users and organizations can expect an increase in attacks and urges them to prepare for the new AI-powered cyber threat landscape.

“Highly convincing, mass-volume attacks are becoming the new baseline,” says Buinovskis. “It’s now easier than ever to become a cybercriminal — technical skills are no longer a necessity. Users and organizations are getting hit from both sides. Veteran hackers are utilizing AI to scale their operations, and a whole new wave of beginners is joining the ranks every day.”

He says that in the new age of massive attacks, anyone can become a victim. Buinovskis emphasizes that, especially now, vigilance and awareness are key.

“A cautious approach is now more vital than ever — spotting AI and AI-powered attacks can be difficult even for seasoned cybersecurity experts,” says Buinovskis. “These attacks are designed to bypass both filters and human intuition, especially when we’re rushed. My key recommendation is to step back and critically assess any message that pushes to act now. In the age of AI, a healthy dose of skepticism is our first wall of defense.”

Despite that, Buinovskis explains that eventual user error is inevitable. Having proper security guardrails in place helps to minimize the possibility of a data breach and fallout of a cyberattack.

“Regarding AI-powered cyberattacks, solutions that identify malicious websites and block malware download attempts are the first step,” says Buinovskis. “For organizations, this must be part of a more comprehensive approach. True resilience requires a zero-trust architecture that treats every access request as a potential threat, combined with proactive dark web monitoring to identify leaked data before it can be weaponized.”

Buinovskis highlights that while cybercriminals are ramping up operations with AI, the fundamental attack vectors remain the same. This makes basic cybersecurity hygiene more critical than ever. Effective defense starts with rigorous password management — avoiding reuse and moving away from vulnerable consumer-browser password managers, while remaining aware of the digital footprint left behind through publicly available personal information, which attackers now routinely exploit to personalize social engineering attacks.

Methodology

NordLayer and NordStellar analyzed dark web activity between January 2024 and May 2026, tracking keyword-specific discussions across underground forums and Telegram. The research focused on the volume of AI-related mentions and how these trends shifted in direct response to major LLM product releases, with release dates sourced from public records.

Disclaimer. This analysis is based on detected activity and is for informational purposes only. It does not constitute professional advice or a guarantee of security. All third-party trademarks and references remain the property of their respective owners and are used for identification purposes only. This research tracks discussion trends in deep and dark web spaces and does not assess the safety, security, or intent of any AI provider or product.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading