Every year the security industry adopts a phrase that spreads faster than the thing it describes. This year the phrase is stuck to a genuinely new problem, which is unusual. The barrier that kept most people out of cybercrime was never motive or opportunity. It was skill. Writing working malware, chaining exploits and running a convincing social engineering campaign took years to learn. That barrier has quietly collapsed.

Vibe hacking is the name that stuck to the collapse. It describes criminals using conversational AI to plan, build and run attacks they could never have written themselves, in the same way vibe coding describes developers shipping software they could not have written by hand. This guide explains what vibe hacking is, the real cases behind the headlines, why it defeats defences that worked perfectly well two years ago, and the practical steps a business of any size can take this quarter.

What Vibe Hacking Actually Means

vibe hacking latest buzzword blocking ai generated phishing emails

Strip away the marketing and vibe hacking has a simple definition: using an AI assistant as the technical expert in a criminal operation. The attacker supplies intent and context. The model supplies the code, the reconnaissance, the persuasive language and increasingly the tactical decisions. No deep expertise required on the human side.

The working definition

Vibe hacking is when someone uses a large language model to trick, exploit or attack systems and people without possessing the underlying technical skill themselves. The attacker describes a goal in plain language. The model translates that goal into scripts, payloads, phishing copy or infrastructure. The gap between wanting to run an attack and being able to run one has narrowed to a conversation.

Two distinct meanings, often confused

The term gets used in two ways, and the confusion matters. The first is using AI as an offensive tool, which is the sense most reporting means. The second is manipulating an AI system itself, coaxing a model past its safety guardrails through carefully framed prompts. Both are real. Both fall under the vibe hacking umbrella. But they demand very different defences, so it is worth being precise about which one you are discussing.

Why the analogy to vibe coding is exact

Vibe coding described a developer who describes an outcome and accepts whatever the model produces, often without fully reading it. Vibe hacking is the same posture with hostile intent. The operator does not need to understand the exploit any more than a vibe coder needs to understand the framework. They need it to work once. That asymmetry — attackers only need one success, defenders need to be right every time — is what makes the shift dangerous.

From Vibe Coding to Vibe Hacking: Where the Term Came From

vibe hacking latest buzzword criminal ai tools on underground markets

The phrase entered mainstream security vocabulary through incident reporting rather than academic work, which is part of why it spread so quickly. It named something practitioners were already seeing but had no shorthand for.

The Anthropic report that named it

In its August 2025 threat intelligence report, Anthropic described an extortion operation it tracked as GTG-2002 and characterised the trend as vibe hacking. A single operator used Claude Code to run reconnaissance, harvest credentials, move through networks and decide which data to steal. The same tooling analysed stolen financial records to size ransom demands, some exceeding $500,000, and generated the ransom notes. You can read Anthropic’s own account of the case for the full technical detail.

Seventeen organisations, one operator

The GTG-2002 campaign reached at least seventeen organisations across healthcare, emergency services, government and religious institutions. What made it notable was not the victim count. It was the staffing. Work that would historically require a small team with distinct specialisms — network intrusion, data analysis, negotiation psychology — was carried out by one person directing a model. That compression of headcount is the economic core of vibe hacking.

From advisory to operational

Earlier misuse of AI in cybercrime was advisory. Criminals asked models to explain a vulnerability or draft a phishing email, then did the work themselves. The step change is that models now execute. They run the scan, parse the output, choose the next move and act on it. Vibe hacking marks the point where the assistant stopped consulting and started operating.

Why the naming mattered

Naming a threat changes how organisations budget for it. Before the term existed, these incidents were logged as ordinary intrusions with an unusual tooling footnote, which meant nobody counted them and nobody funded a response. Giving the pattern a label turned scattered anecdotes into a category that boards could ask questions about. That is the useful function of a buzzword, and it is worth remembering when the phrase starts to sound tired.

The Cases That Made Vibe Hacking Real

vibe hacking latest buzzword defending against autonomous attack chains

Buzzwords survive when incidents keep validating them. Several have.

AI-augmented campaigns in Latin America

Trend Micro documented two AI-augmented campaigns targeting government and financial organisations in Latin America. Between late December 2025 and early January 2026, threat actors compromised six government entities in Mexico, running activity across the full kill chain with AI agent support and successfully exfiltrating targeted data. These were not proof-of-concept experiments. They were funded operations with clear objectives.

The AI-written intrusion script

Huntress researchers described an intrusion in which an attacker deployed a custom, AI-generated script to enumerate an entire internal network. The script was not sophisticated by expert standards. It did not need to be. It was written in minutes, tailored to that specific environment, and had never been seen before by any signature-based tool. That combination — mediocre code, perfect novelty — is the recurring signature of vibe hacking.

Phishing that stopped looking like phishing

The clearest measurable impact is in email. In November 2025, roughly 4% of reported phishing emails showed indicators of AI assistance. By early 2026, researchers put the AI-assisted share at over 80%. Successful phishing attributed to AI tooling rose sharply through 2025, and click rates on AI-generated lures have been reported above 50%. The spelling mistakes and awkward phrasing your staff were trained to spot have simply disappeared.

Deepfakes and voice cloning as standard equipment

Voice phishing incidents climbed steeply through the same period, with reported losses running into the tens of billions. Cloning a voice convincingly now takes seconds of source audio, and most executives have published far more than that. A finance team trained to phone the CFO to verify an unusual transfer is following advice that vibe hacking has quietly made obsolete.

Why Vibe Hacking Works So Well

vibe hacking latest buzzword establishing an ai usage policy

Understanding the mechanics matters more than memorising the headlines, because the mechanics tell you where to spend money.

It removes the skill barrier, not the intent barrier

There has never been a shortage of people willing to commit fraud. There was a shortage of people able to. Vibe hacking dissolves that constraint, expanding the pool of viable attackers from skilled operators to anyone with a grievance, a target and a subscription. The number of attempts your business faces rises even if the sophistication of any individual attempt does not.

Every artefact is unique

Traditional detection leans heavily on knowing what bad things look like: file hashes, sender reputation, known phrasing. When a model generates a fresh script and fresh copy for every target, there is no repeated artefact to match. Vibe hacking produces attacks that are individually unremarkable and collectively invisible to signature-based tooling.

Personalisation at industrial scale

Spear phishing used to be expensive, so it was reserved for high-value targets. Everyone else got generic spam. That economic distinction has gone. A model can read a target’s public posts, infer their role, reference a real project and produce a tailored message in seconds. Vibe hacking makes spear-phishing-quality personalisation available at bulk-mail cost, which means junior staff now receive the treatment previously reserved for directors.

Speed compresses your response window

The interval between a vulnerability being disclosed and being exploited has shortened dramatically, because turning an advisory into working exploit code is now a prompt rather than a project. Patch windows measured in weeks were always uncomfortable. Against vibe hacking they are indefensible.

The quality floor has risen, not the ceiling

It is worth being accurate about what improved. Elite operators were always capable of everything described here, and AI has not made the best attackers dramatically better. What changed is the floor. The clumsy, obvious, easily blocked attempts that made up the bulk of what most businesses faced have been replaced by competent ones. Your median inbound threat is now substantially better than it was, even though your worst-case threat is roughly unchanged.

The Underground Economy Behind the Buzzword

vibe hacking latest buzzword final security review with the team

The criminal marketplace has responded to demand in the way marketplaces do, and the branding tells you a lot about the intended customer.

FraudGPT, WormGPT and the rest

Underground forums advertise a growing catalogue of AI-branded services: FraudGPT, PhishGPT, WormGPT, various red-team GPTs. They promise automated phishing, scam scripts, vulnerability explanation and step-by-step attack guidance. Some are genuine jailbroken models. Many are thin wrappers around commercial APIs, and a fair number are outright scams aimed at other criminals.

The marketing is the tell

These services advertise with phrases like “no experience needed” and “the AI handles everything.” That copy is not aimed at experienced operators, who do not need it. It is aimed at newcomers. As one analysis put it, AI is not changing what is being sold on these markets so much as changing how safe it feels to buy it. Vibe hacking is as much a psychological shift in the criminal talent pool as a technical one.

Jailbreaks as a traded commodity

Prompt sequences that reliably bypass a model’s safety filters circulate openly in Russian-language Telegram channels and dark web forums, updated as vendors patch them. This is the second sense of vibe hacking — attacking the model rather than with it — and it functions as a supply chain feeding the first.

What Vibe Hacking Looks Like When It Hits Your Business

Abstract threat descriptions do not help anyone make a decision. Here is the concrete shape.

The invoice that is almost right

Your accounts team receives an email from a genuine supplier contact, referencing a real project, in the supplier’s usual tone, with updated bank details. There is no typo, no odd greeting, no mismatched logo. The only anomaly is the account number. Vibe hacking removes every signal your staff were trained to notice and leaves only the one that requires a phone call to a number you already had.

The internal request that arrives at the worst moment

A message appears to come from a senior colleague, timed to a period when they are genuinely travelling, referencing a real deadline. Urgency plus plausibility defeats process. Attackers know this, and models are extremely good at generating plausible urgency.

The quiet enumeration

An attacker who obtains a single valid credential — bought, phished or reused — no longer needs to know your environment. They ask a model to write something that maps it. The script is bespoke, runs once and looks like administrative activity. Detection depends on behavioural monitoring rather than on recognising a known tool.

The small business assumption that no longer holds

The old reasoning was that a twenty-person firm was not worth an attacker’s time. That reasoning depended on attacks being expensive to run. When the marginal cost of one more target approaches zero, small organisations move from ignored to routinely included. Vibe hacking has removed the protection that obscurity used to provide.

Why Traditional Defences Miss It

If your controls were designed around what attacks looked like in 2022, there are specific gaps worth naming.

Signature-based tooling has less to match

Antivirus and email gateways built around known-bad indicators still catch commodity attacks, and you should keep them. But they were designed for a world of reused artefacts. Vibe hacking generates novel artefacts by default, so the proportion of attacks these tools catch falls even as the tools themselves work exactly as designed.

Awareness training is teaching outdated tells

Most phishing awareness modules still teach staff to look for poor grammar, generic greetings and suspicious formatting. Those tells are gone. Training that has not been rewritten in the last eighteen months is actively harmful, because it builds confidence in a detection method that vibe hacking has already defeated.

Verification habits assume voices are trustworthy

“Call them to check” was excellent advice until voice cloning became trivial. Verification now needs to run over a separate, pre-agreed channel — a known internal number, a second approver, a callback to a directory entry rather than to whatever number appeared in the message.

Volume-based alerting drowns the signal

Many monitoring setups were tuned on the assumption that a real attack generates noise: repeated failed logins, scanner traffic, malformed requests. An operator working through a model tends to be quieter, because the model reads the environment and adapts rather than brute-forcing it. Thresholds calibrated for loud attacks will not fire on a patient one, and that miscalibration is one of the least discussed gaps that vibe hacking exposes.

Practical Defences Against Vibe Hacking

None of this requires exotic technology. It requires updating assumptions and closing the gaps that AI-assisted attackers are best at finding.

Make identity the control plane

Phishing-resistant multi-factor authentication — passkeys or hardware keys rather than SMS codes — removes the value of most credentials an attacker can extract. If a stolen password alone cannot get anyone in, a large share of vibe hacking scenarios end at step one. This is the single highest-return control available to most organisations.

Rebuild verification around out-of-band steps

Any payment change, credential reset or unusual access request should require confirmation through a channel that was agreed in advance and does not depend on the message that triggered it. Write the rule down, apply it without exception, and make it explicitly acceptable for a junior member of staff to delay a director’s request while they follow it.

Retrain staff on the threats that actually exist

Replace the spot-the-typo material with realistic examples: fluent, personalised, contextually accurate messages. Teach staff to react to the nature of a request rather than its polish. Run simulations that use the same techniques attackers use, and treat a high click rate as a process problem rather than an individual failing.

Shrink the patch window

Prioritise internet-facing systems and anything with a public proof-of-concept exploit. Exploitation timelines have compressed to days, sometimes hours, so a monthly cycle for external assets is no longer defensible. A structured managed IT services arrangement with defined patch SLAs is usually cheaper than staffing this properly in house.

Monitor behaviour, not just signatures

Because vibe hacking produces unique artefacts, detection has to key on what an account is doing rather than what a file is. Unusual login geography, sudden bulk data access, scripting activity from a non-technical account, off-hours administrative work. Reviewing these patterns is where security budgets deliver the most value against AI-assisted intrusion.

Governing the AI Tools You Deploy Yourself

The other half of the vibe hacking problem points inward. The assistants your own teams use are attack surface.

Apply least privilege to agents

An AI agent with broad API access, file system permissions and network reach is a powerful tool for whoever ends up controlling it. Scope credentials tightly, prefer read-only where possible, and log agent actions the way you would log a privileged human account.

Treat prompt injection as an input validation problem

Content that a model reads — a web page, a document, an email — can carry instructions the model may follow. This is the manipulation side of vibe hacking, and it does not respect the boundary between data and command. Keep untrusted content away from agents that hold real permissions, and require human approval for consequential actions.

Write a usable AI policy

Staff will use AI tools whether or not you sanction them. A policy that says no simply pushes the activity onto personal accounts where you have no visibility. Name the approved tools, state clearly what data must never be pasted into them, and explain why. Our AI models and tools hub tracks the current landscape if you are deciding what to approve.

What Comes Next for Vibe Hacking

Predictions age badly, but the direction of travel is not really in question.

More autonomy, less human involvement

The trajectory runs from AI-assisted phishing toward end-to-end automated intrusion and extortion. Each documented campaign has involved slightly more model autonomy than the last. Planning for vibe hacking that requires no human in the loop for hours at a time is prudent rather than alarmist.

Defensive AI catches up unevenly

The same capabilities work defensively — triaging alerts, correlating behaviour, spotting anomalies at a scale humans cannot. Large organisations will deploy this quickly. Smaller ones will get it bundled into products a year or two later. That gap is where most losses will concentrate.

The buzzword will fade, the problem will not

In eighteen months the phrase will sound dated, the way “APT” and “zero trust” now do. The underlying shift is permanent. Attacks assembled conversationally, personalised at scale and unique every time are the new baseline, whatever we end up calling them. Reviewing your controls against Trend Micro’s documented campaigns is a reasonable place to start.

Frequently Asked Questions About Vibe Hacking

Is vibe hacking genuinely new or just rebranded phishing?

Both, honestly. The attack types are familiar — phishing, credential theft, extortion. What is new is who can run them, how fast, how personalised and how unique each instance is. Vibe hacking describes a change in the economics and accessibility of attack production, not the invention of a new attack category.

Are small businesses actually at risk?

Yes, and more than before. The obscurity that protected small organisations depended on attacks being costly to run. Vibe hacking drives that cost toward zero, so smaller targets get swept into campaigns that would previously have skipped them.

Can AI providers stop this?

Partially. Providers ban accounts, deploy classifiers and share indicators, and that materially reduces abuse of mainstream services. But open-weight models can be run locally with no oversight, and jailbreaks circulate freely. Provider controls reduce the volume of vibe hacking. They will not eliminate it.

What is the single most effective thing to do first?

Deploy phishing-resistant multi-factor authentication everywhere it will work. It neutralises the credential theft that most vibe hacking chains depend on, and it does not rely on any employee correctly spotting a message that was designed to be unspottable.

How do we know if we have already been hit?

Look for behavioural anomalies rather than malware: logins from unexpected locations, unusual bulk data access, scripting from accounts that never script, administrative activity outside working hours. Because vibe hacking leaves few reusable indicators, an intrusion review focused on account behaviour will tell you more than another antivirus scan.