Analysis · curated 2 Aug 2026

Cybercriminal abuse of large language models

Coverage timeline

25 Jun 2025talosintelligence.comprimary

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Talos's overview shows criminals are operationalizing uncensored and jailbroken LLMs connected to external tooling, lowering the barrier to phishing, vulnerability scanning, and fraud at scale.

Cisco Talos analyzes how cybercriminals abuse large language models, detailing the use of uncensored LLMs (e.g. Llama 2 Uncensored via Ollama, WhiteRabbitNeo), custom-built criminal LLMs advertised on hacking forums like OnionGPT, and the jailbreaking of legitimate frontier models. The report notes these malicious LLMs are being wired to external tools for sending phishing email, scanning sites for vulnerabilities, and verifying stolen credit card numbers.