- What: AI is giving cybercriminals a time advantage
- Impact: Cybersecurity professionals
Informa TechTarget | SearchSecurity Cybersecurity Dive InformationWeek Channel Dive Explore our brands Dark Reading Resource Library Black Hat News Omdia Cybersecurity Advertise NEWSLETTER SIGN-UP Cybersecurity Topics World The Edge DR Technology Events Resources THREAT INTELLIGENCE CYBERSECURITY OPERATIONS CYBERSECURITY CAREERS VULNERABILITIES & THREATS INTERVIEWS AI Gives Cybercriminals a Dangerous Time Advantage Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers. Kristina Beek,Associate Editor,Dark Reading September 2, 2026 SOURCE: DARK READING Brett Johnson has seen cybercrime from both sides. Once dubbed the "original Internet Godfather" by the US Secret Service, Johnson built and ran Shadow Crew, an early organized cybercrime community, before eventually leaving that life behind. Now, he works with law enforcement and businesses to help defend against the kinds of threats he once deployed. In this conversation with Dark Reading's Kristina Beek, Johnson shares what he spoke about at Black Hat USA in Las Vegas alongside Illumio, demonstrating how artificial intelligence (AI) can compress the time it takes to carry out an attack. Johnson also shares his insights on how AI may be playing both sides for now, but the attackers are getting the better end of the deal. The technology helps threat actors research targets, identify valuable data, and find exploitable weaknesses faster, giving them an advantage over defenders who may still be reacting to threats. Related:'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks AI is also lowering the barrier to entry for would-be cybercriminals. As technical skills become less necessary and criminal communities continue to share information and tutorials, more people can learn how to carry out cyber fraud and other attacks. That shift, Johnson warns, could put hospitals, schools, and other critical organizations at greater risk — and make it even more difficult to trust what people see and hear online. Listen and read along for the full conversation, and take a look at Dark Reading's other video content here. Kristina Beek and Brett Johnson: Full Transcript This transcript has been edited for clarity and length by Informa TechTarget's internal AI assistant. For the full experience, please watch the video. LOADING... Dark Reading's Kristina Beek: Thanks so much for joining us today, Brett. I'm so excited to talk to you. My understanding is that you are giving a demo at Black Hat USA this year in Las Vegas, and I would love if you could just tell me about your background and what it is that you plan on sharing at Black Hat. Brett Johnson: I'm the guy that's responsible for a lot of modern cybercrime. The United States Secret Service dubbed me the original Internet Godfather. And the way I got that title was I pled guilty to 39 felonies. I was placed on the United States Most Wanted list. I had an escape from prison. Yeah, I did. And I built and ran the first organized cybercrime community. It's called Shadow Crew. It's a precursor of today's darknet, darknet markets, lays the foundation for the way modern financial cybercrime channels still operate today. Shadow Crew is interesting because it's not only the first Dark Web marketplace of its type, but it also established that trust mechanism that these channels and platforms would continue to use, actually through today, unless you're talking about Telegram. But that's what I did. Nothing to be proud of, but it made the front cover of Forbes, August of 2004. Related:Interpol's Jackal IV Disrupts West African Crime Infrastructure October 26, 2004, United States Secret Service, they arrested 33 people, six countries, six hours. I was the only guy publicly mentioned as getting away. They picked me up about four months later. They gave me a job. And I continued to break the law from inside Secret Service offices for the next 10 months until they found out about it. Then I took off on a cross-country crime spree, stole $600,000 in four months, wake up one morning in Las Vegas. US Most Wanted. What does idiot here do? Well, I sat there and looked at the screen and I said it out loud. Well, Brett, you've made the US Most Wanted list. What are you gonna do now? And I said, I'm going to Disney World. And I did. DR's Kristina Beek: Yeah. Brett Johnson: Lasted about six weeks. Got arrested, sent to prison, escaped from prison, arrested again, served up my time. And the interesting thing is I always had people that looked out for me when I was on the bad side, today on the good side. And a lot of people really wanted to see me turn my life around. I kept being given the opportunity. Related:Tricky 'SynkLoader' Multitool May Herald Ransomware Finally it stuck. And there was a number of people that was responsible for that. My wife, Michelle, ex-wife Michelle, she was responsible for that. Keith Mularski, FBI agent, he was responsible for that. Went by the name of Master Splinter on criminal groups. Friend of mine now, he was responsible for that. And then Karisse Hendrick, editor of the Card Not Present group. She was also responsible for giving me that chance to turn my life around. Today I speak across the planet, consult with everyone, work with law enforcement, and work hard to protect businesses and consumers from that guy that I used to be. So that's it in a nutshell. DR's Kristina Beek: Perfect. Well, that is way more exciting than I expected. Brett Johnson: [laughs]. DR's Kristina Beek: So now you're coming back to Las Vegas and you plan on giving a demo. Can you talk about that? Brett Johnson: Sure. Working with Illumio, what's interesting, we've had a lot of chatter the past few years about how criminals use AI. Whether it be coding, whether it be building layering trust, what happens in that type of attack? And to be honest with you, the same thing happened with the metaverse. You know, metaverse comes in and we had all these 8,500-plus security companies that said, all this fraud's going to happen on the metaverse. Meanwhile, some of these metaverses have like three people on there. No, it doesn't happen that way. It really doesn't. But that's the same type of chatter that started as AI was ramping up. And to be honest with you, AI just back then kind of sucked. You know, it really did. And today that's not the case. Today, it's extremely competent. It's beyond competent. So what I'm showing with Illumio is how AI compresses an attack. From an attack side, from a criminal point of view, it takes me time to do things. If I'm looking for a specific company to hit, to gain access to, I have to do research on that company. I have to find out which targets I'm going to hit. I'm gonna find out what I'm looking for: information, access, data, cash. So I have to find out what are the crown jewels of that company, gain access to that. All of that takes time to do research. Once I'm in the environment, I still have to do research once I'm in the environment. AI largely compresses that. It will do the research for me. It will tell me what the crown jewels are. So it compresses the time to the point that from an attack side, all I need to do is gain entry and go to work. From the defense side, though, they've still got time on their hands. They see me inside, and they've got to worry about what to do. Meanwhile, I don't. I've already had AI that assists me in that. So it's not that in this demo, it's not so much that AI is launching the attack, but AI is helping to compress everything to the point that I'm able to act much faster and be much more successful at the end of the day. Gives me — I do my thing in less time while it takes the defender much more time. So that's basically it. DR's Kristina Beek: So you're talking about how AI can just essentially help streamline everything that attackers need to do in order to get into your systems. Brett Johnson: Right. DR's Kristina Beek: So is there, you know, sort of a reverse side on the defenders of how they can use AI to sort of do the same thing on their end? Brett Johnson: So I want to be clear about AI as a whole. My thought and view on this is that AI right now benefits the attacker much more than the defender. AI is a learning environment. For it to learn from an attack, it has to see the attack, and that attack needs to be successful. So it's reactive, it's not proactive. And I really believe that's what it's gonna be for the next three, five, maybe even seven years. At the end of that, though, it's going to be a much different ballgame. Right now, I think the criminals and attackers are successful and they use AI much more to their benefit than defenders do. Now, that's not to say that you can't use AI to mitigate attacks or to, you know, shore up your security. It's not to say that. For example, 90% of every single attack uses a known exploit. You've got over 41% of every single router has the default password. Most breaches begin with phishing attacks. So that threat landscape that's out there, it's known how that threat landscape is developed. So you can absolutely use AI to scan that threat landscape, figure out which exploits you have at your organization, and then update and plug those holes that are there. The same thing from an attack side. I'm going to scan the environment looking for those exploits and potentially new ones because evidently Anthropic is somewhat good about finding that. So I'm going to scan the environment and see what exploits are available to me. From that point of view, what you're talking about is, and we had that same, we have that same problem with just old school updates. An update comes out. A lot of people or a lot of organizations will not act on that update immediately. They'll sit on it. But an update is really a broadcast to every single attacker on which door you need to knock on to gain entry. And what I'm trying to get at is that