TechChannels Expert Insights

Q&A: ESET’s Jake Moore on Future Crime: How AI Is Changing the Economics and Speed of Cybercrime

Written by Teri Robinson | Sep 14, 2026, 2:00:02 PM

Cybercrime has always evolved alongside technology, but AI is changing the speed, accessibility, and economics of that evolution. Capabilities that once required specialized technical knowledge, purpose-built tools, or days of experimentation are becoming available to a much broader pool of potential attackers. AI-assisted coding makes it easier to build and modify malicious tools, while rapid experimentation allows criminals to test an approach, encounter a defense, and change direction in a fraction of the time it once required. Activity that might previously have taken days to thoroughly test can now happen in 15 minutes.

That acceleration does not mean AI is behind every cyberattack. Instead, the more immediate concern is how AI can lower barriers to entry, accelerate knowledge-sharing, and enable attackers to operate at greater speed and scale. At the same time, AI is making familiar threats such as scams and social engineering potentially more convincing by allowing criminals to coordinate interactions across text, email, voice, and other channels.

At Infosec Europe in London earlier in the summer, Jake Moore, Global Cybersecurity Advisor at ESET, spoke to Tech Channels about what the emerging era of future crime means for defenders. Moore contends that organizations can’t eliminate cyber risk but must continuously adapt to it. As threats evolve, strong security fundamentals, engaged employees, realistic testing, collaboration, and a refusal to become complacent become even more important.

Q. How is generative AI changing who can participate in cybercrime?

A. Everything's taken a different direction since Claude Code came along. There has been the hype, and rightly so. That hype is exciting. Like with any new technology, we want to be able to play with it, but so do the criminals, and now criminals can very easily adapt and not have to wait for someone else to create applications or services that they might have used in, say, cybercrime as a service, or phishing kits, or anything that we would have seen before on the internet, and particularly on the dark web. They can now go and bridge those gaps with their own code, and the accessibility is now extremely easy. The level of entry is much, much lower because of it.

Q. Are we entering a period where people with relatively little criminal or technical experience can become attackers?

A. We're now seeing people who probably wouldn't have been called a script kitty 10 years ago. They're just people experimenting. But now all it takes is someone who's got a criminal mindset of a very low degree to think about a side hustle. It’s now possible to manipulate many chatbots as well, for example, to say that you're doing a demo. It might say “no,” but if you say you're a security researcher, you can get around the very simple safeguard. So guardrails are getting better, but they're going to get abused and taken advantage of throughout the process. We're early on, we're in this infant stage, and that's what's making it very interesting—we don't know where it's really going.

Q. How is AI changing the speed at which cybercriminals can experiment and adapt?

A. Criminals are able to literally test anything out, and do so very quickly. Previously, that would have taken a day or two to put through thorough testing now takes 15 minutes, so criminals can see rapidly if things work, and then when they don't, they can change direction. If they come up against something that stops them, blocks them from targeting a specific business, it takes no time at all to go a different way. Usually, it’s that experimentation that will find exploits.

Q. What happens when faster experimentation is combined with criminal knowledge-sharing?

A. The criminals all talk and learn together, so, especially if they're using forums where they can discuss where they have found vulnerabilities, they can share that at scale and speed. That is something that we're used to but now we're seeing everything explode. That doesn't mean that AI is using every attack, that's something that I think the media like to think is possible. And the knowledge exchange is much more rapid. That experimentation will no doubt lead to more vulnerabilities being located and that's where it's scary for defenders to not completely understand where they've got to protect.

Q. If attackers are sharing information more quickly, do defenders need to collaborate more closely?

A. To a certain extent we already share knowledge, and that is extremely important, but there comes a point where private companies don't want to share their IP, they don't want to share business secrets that are specific to them and the makeup of their business. Because, why would you? In any other industry, that's a huge no-no, especially when in the defense industry and the cybersecurity industry, knowledge is actually the brains behind it. So, there's a certain level you can't ever exchange with other people. Sharing live grid known vulnerabilities, for example, amongst all the companies is brilliant. We find a zero day, we'll share it amongst all the others. That's a great start, but at the same time it's already feeling a little bit dated. So now we're looking at other tactics. We can talk about the tactics, but talking about how they're being protected sometimes might mean that those companies can't disclose them because it could put their organizations at risk through competition.

Q. Where does information sharing work particularly well, and where does it become more difficult? Several years ago, after a series of large DDoS attacks, banks were praised for sharing information.

A. That’s a good example. A DDoS attack is effectively not a real cyberattack. It's a way of taking organizations and websites or applications offline. But the defense of it won't give anything away. If anything, we know that the actual best defense to a DDoS isto have DDoS protection, which pushes that flood to other devices to keep your mainframe online at all times. By sharing that and building upon it, even working together, you can reduce and at least mitigate risk. But when criminals get in and penetrate the core parts of a business, an organization starts worrying about how their defense is made up. Then it becomes an embarrassment, and you could even start pointing fingers at [which vendor] provided protection. Because they should have stopped it, regardless of who bypassed it with a workaround. That’s where the worry comes, especially from the top, who don't maybe necessarily understand the problem or listen to the C suite, the CSO, who might say “we don't want to talk about this publicly, apart from we admit it happened, and that's as much as we're going to talk about.”

Q. Can organizations ever become truly proactive about cybersecurity?

A. You can't make a proactive security structure, because the whole essence of it is threat actors looking to work around. So, if you go in one direction, you can choose any direction you want, they'll find a different direction. Therefore, you can't be anything but reactive, that is how it's just generated. That’s actually a good point. I've never actually thought of it like that, but we have to be continually on it, and not just as defenders. This is all organizations, from staff training right the way through to patch management to backups to MFA, simulation of attacks. There's a whole plethora of things you can do, it's just you've got to be on it and hope for the best, but prepare for the worst.

Q. What is the most important thing business leaders need to understand about cyber risk today?

A. Never become complacent. And that's not for CISOs, because I don't think CSOs are ever complacent. If CEOs are looking at this, they need to understand that this is a moving target, or actually, it’s a moving gun with a target. It's a moving gun the whole time.

Q. How can organizations make cybersecurity readiness more practical and engaging?

A. It’s like having 20 lasers on you and wherever you move, and you probably move into the line of another one. It's actually a fun analogy. We want to continually reinvent training, which has become boring for most people but they still must be reminded of security–and that needs to be fun and engaging. Targeting your own company, shooting yourself in the foot, is the most amazing way to actually prove where you were weak. That brings a community into a business so they realize we can work together on this, and they’ll get much better longevity, and people believe in their own data. I find, particularly people that don't stay at companies very long, they don't feel so invested in the data, and they don't care so much.

Q. Why does employee engagement matter to an organization's security posture?

A. We have to make people realize that security is everyone's responsibility. That sounds cliche, but it's never been more apparent than now. These attacks are good, and they're relentless.

Q. What qualities should organizations look for when building a security-conscious workforce?

A. We need to find people, regardless of background, that care about where they work. When you care for something, you're much more risk averse, much more just security minded. And if you can find that in staff, then everything improves.

Q. Why can showing employees how an attack works be more effective than conventional training?

A. That’s a key point. When I hack into businesses with their permission, I like to then reenact that on stage. When I show businesses that it's possible, but that no data was harmed in the making of this, it makes everyone watching have a little laugh to themselves and question would that [a simulated attack] have gotten them. And for those that laugh a little bit too nervously, then potentially it would have gone through.

Q. How is AI changing the economics and sophistication of scams?

A. It’s a numbers game for scammers and for all cybercriminals. So, if we're talking numbers in the hundreds of thousand, in just one country, like the UK, you can then very easily purchase a scam agent that would do much more than just a scam bot. “We'll go do it for you,” and by targeting, say, the multi-layer folks who text them, you get AI to phone them, you email them. tk

Q. Why are multi-stage AI-enabled scams particularly convincing?

A. They are much more convincing, and you let your guard down. They might not even ask you to do anything for much of the conversations they will keep you thinking, “well, they haven't asked me to do anything, so what's their game, I'll carry on with them.” And it's the very ending that is the dropper, and only afterwards will you then think “that's what they meant to do.”

Q. Why is awareness alone becoming less effective against emerging scams?

A. By the time you hear about a new scam, 10,000 people have been already been victimized

Q. What makes social engineering so effective even against intelligent or experienced people?

A. It is very believable. That’s the thing with all attacks, if they include an element of psychology that has the power of influence, they are known to be much more successful.

AI may be changing the tools available to cybercriminals, but the interview makes clear that many of the fundamentals of effective defense remain remarkably consistent. Organizations still need disciplined patch management, backups, MFA, employee training, attack simulations, information sharing, and a security-conscious workforce. What has changed is the speed at which those capabilities must evolve. Attackers can experiment more rapidly, learn from one another at scale, and increasingly use AI to make existing tactics more efficient and persuasive.

That reality makes complacency particularly dangerous. Attackers continually look for alternative routes, requiring defenders to test themselves, expose weaknesses, learn from failures, and reinforce security across the organization.

Ultimately, preparing for future crime is less about predicting the exact form of the next attack than building an organization capable of responding when it arrives. The technologies and tactics will continue to change. The strongest defense will be a culture of continuous readiness: understand the fundamentals, test them relentlessly, share what can safely be shared, educate people about how attackers influence behavior, and “hope for the best, but prepare for the worst.”