In July 2026, the UK's AI Security Institute (AISI) reported that the cyber capabilities of two leading open-weight AI models, GLM-5.2 and DeepSeek V4-Pro, had closed to within 4–7 months of the closed frontier models. Anyone can download a model's weights, and once they are released, the developer cannot take them back.
In September, large-scale data breaches were announced in Japan one after another, including about 23.62 million records at Gyazo and about 6.6 million accounts at Times Car. However, none of the 12 Japanese announcements and news reports we could verify states that AI was used in the attacks.
The view that "open-weight AI has increased criminals' attack capabilities" needs to be broken into four steps: model capability, real-world cases overseas, connections to Japan, and a causal link to damage in Japan. At present, the strength of the evidence behind each step differs greatly.
A 4–7 month gap, with exercise costs about half for GLM-5.2 and about 1/71 for DeepSeek V4-Pro

For a cyber exercise using 100 million tokens, the UK AISI estimated the cost at about $85 for Opus 4.5 and Opus 4.6, and $1.19 for DeepSeek V4-Pro. DeepSeek V4-Pro works out to about 1/71 of the cost. GLM-5.2 was an estimated $46 or so, about 54% of Opus's roughly $85, or about half. All of these figures are our own calculations.
However, the large gap of about 1/71 applies only to DeepSeek V4-Pro, which fell below Sonnet 4.5 in the exercise. These figures were also calculated by AISI from each company's published prices, and do not show what actual attackers pay.
AISI's "4–7 month gap" is also not a difference in model release dates. It indicates how many months earlier a closed model able to solve tasks of similar difficulty had appeared.
On 70 cyber tasks divided into four levels, from technical non-experts to experts, GLM-5.2, released on June 16, 2026, performed on par with Opus 4.6 and GPT-5.3-Codex from about four months earlier. DeepSeek V4-Pro performed on par with Opus 4.5 from about five months earlier.
In a 32-step attack exercise targeting about 20 hosts, which human experts are estimated to need about 20 hours to complete, GLM-5.2 got as far as Opus 4.5, while DeepSeek V4-Pro fell below Sonnet 4.5.
In 2025 internal evaluations, the gap between open-weight models and closed frontier models was 6–10 months, so the shortening to 4–7 months means the gap has narrowed. But AISI evaluated only the cyber capabilities of these two models, and the findings cannot be applied to other capabilities or to models in general.
AISI also restricted the comparison to tasks that both models in a pairing reliably solved, and gave a per-task cost.
| Model | Cost per exercise (100M tokens) | Per task (comparison partner) |
|---|---|---|
| Opus 4.5 | About $85 | $12.50 (vs. DeepSeek V4-Pro) |
| Opus 4.6 | About $85 | $15.17 (vs. GLM-5.2) |
| GLM-5.2 | Estimated about $46 | $6.12 (vs. Opus 4.6) |
| DeepSeek V4-Pro | $1.19 | $0.28 (vs. Opus 4.5) |
Even when the solved tasks are matched, there is a large gap: $0.28 for DeepSeek V4-Pro against $12.50 for Opus 4.5.
That said, the closed models used for the 4–7 month comparison were those released by February 2026. Mythos Preview (Anthropic) and GPT-5.5 (OpenAI), which appeared in April, showed major performance gains, but AISI states explicitly that it cannot predict that future open-weight models will repeat the same progress.
Safeguards have not been a strong barrier either. AISI's evaluation was hardly hindered by refusals, and where DeepSeek V4-Pro refused mainly reverse-engineering tasks, retrying the same tasks several times got around this.
A 2024 study showed, for 13 open-source models of up to 72 billion parameters, that refusal behavior is concentrated in a specific direction inside the model, and that removing that direction stops the model from refusing.
Anthropic tried this modification technique, "abliteration," on the latest GLM-5.3. Even a team doing the work for the first time could do it in about 2,200 GPU hours at about $4,400, and refusal rates fell from over 90% to about 3% on JailbreakBench, 2% on HarmBench and 12% on StrongREJECT. Modified versions were reportedly distributed by multiple developers within days of release.
Near 0% on benchmarks, yet models used to breach 27 companies
In measurements Anthropic published on September 29, on ExploitBench, which uses 41 known Chrome V8 vulnerabilities, the share of cases in which a fully working exploit was produced from start to finish was 14% for Claude Mythos Preview and 12% for GLM-5.3. GLM-5.3 succeeded in 50 of 410 attempts.
GLM-5.2, Kimi K3 and DeepSeek V4.1-Flash, meanwhile, scored 0% or close to it.
Japan's AISI likewise concluded, regarding GLM-5.2 evaluated in July 2026, that it could not say advanced cyber capabilities had spread widely, and that the breadth of exploit-development capability it assessed was limited for now.
Still, in an attack reported by Gambit Security on September 22, at least 27 companies were compromised to varying degrees in just six days, from September 10 to 15.
"Cairn," which advanced the intrusions autonomously in this attack, ran on DeepSeek V4.1 Flash. "Strix," which searches for vulnerabilities, used GLM-5.2 from August 23 to 31 and was then switched to DeepSeek V4-Pro.
DeepSeek V4.1 Flash and GLM-5.2 are among the models that scored almost 0% on the ExploitBench mentioned above. DeepSeek V4-Pro was not included in Anthropic's measurements.
There is a reason for this discrepancy. ExploitBench evaluates the ability to create exploits that abuse browser-engine vulnerabilities. The attack Gambit reported, by contrast, chained together several known weaknesses in web applications.
In one completed case, the attacker used an unauthenticated SQL injection to read a one-time password in plaintext and bypass multi-factor authentication. They then ran code on the host through the image-upload function of an admin panel, and obtained root privileges by exploiting a sudo misconfiguration. In the end, they extracted 46 secrets from AWS's secrets management service and even reached the encryption key for card numbers.
Because the capabilities being evaluated differ, near-0% results on a benchmark do not mean such attacks cannot succeed.
The attack used three harnesses, meaning mechanisms that give an AI tools and set it running, each with a separate role.
Strix was run 146 times against 138 hosts from August 23 to 31, with cumulative scanner running time of 633 hours, or 195 hours in real time.
Cairn was given a target domain and goals such as "obtain a shell" or "gain admin privileges," and ran for hours until it achieved the goal or hit the time limit. In September 10–15 alone, 105 attack projects were launched.
The human input to "Hermes," which oversaw the whole operation, was 1,951 instructions across 260 sessions. Per target, it amounted to only a few short instructions in Chinese. Gambit explains that most of the attack proceeded without human intervention.
Targets were drawn from the shopping category of an access-ranking service, excluding stores that use major e-commerce platforms and narrowing to stores run on custom code. According to Gambit, the attacker believed such sites were more likely to have vulnerabilities.
When an intrusion succeeded, the time required was usually under a day, and often a few hours.
The cost was estimated from OpenRouter balance records. $7,005.71 was spent in the four weeks through August 25, and since call volume over the following three weeks was about double, Gambit estimates the total at $12,000–$18,000.
By the attacker's own tally, the 101 completed scans cost an average of $25.46 each, in a range of $3.13 to $79.31.
However, it would not be appropriate to regard this case as "an attack made possible by open-weight AI alone."
Hermes also used Anthropic's opus-4.6 after newer models refused requests. There was a single attacker, and the models were called through OpenRouter's API; there is no record of open-weight models being run in a local environment.
Gambit itself acknowledges that parts of its account depend on logs left on the attacker's server and on the AI's self-reports, and that errors may be included.
A report published on September 8 by Google Threat Intelligence Group (GTIG), covering mainly the second quarter of 2026, identified attackers using both commercial and open-weight models for vulnerability research and exploit prototyping.
It also stated that, at that point, it had not observed attackers deploying fully autonomous attack pipelines against real-world targets.
What was confirmed was a growing speed at which attackers create exploit code for "n-day" vulnerabilities, meaning known flaws, by exploiting the gap between the release of vulnerability information and the application of patches.
The "AI Security Brief" that IPA published on September 7 also summarizes that multiple attack cases using open-weight models and publicly available AI-agent platforms were reported for June 8 to August 10.
In a case it introduced, the autonomous-execution component failed because it could not correctly recognize the preconditions of the attack. It nonetheless points out that an autonomous attack cycle itself can work in real operations.
Gambit's report touches on Japan in only one place: a "Japanese travel booking site" is cited as an example that loaded vla.js from the same host that distributed a card-information-stealing script, a "skimmer," planted on payment pages.
The site name, the timing, and the models used were not disclosed. Of the more than 600,000 card records leaked from two companies in that report, 488,372, or 79.0%, were US-issued cards.
Breach announcements clustered, but total numbers cannot be said to have surged

In statistics for the first half of 2026 that the National Police Agency released on September 10, ransomware damage reports reached 123, the most for any half-year since statistics began in the second half of 2020.
However, the same period a year earlier had 116, so the increase is 7 cases, or 6.0%. This is our own calculation.
According to Tokyo Shoko Research's tally, personal-information leaks and losses announced by listed companies and their subsidiaries in 2025 numbered 180, down 4.7% from the previous year.
The number of people affected, however, rose 93.1% to 30,636,910, with six large-scale incidents exceeding one million people. The number of companies making announcements, at 158, was also a record.
Even if the number of incidents falls, the impression that breaches are frequent can grow if the scale of each incident increases.
According to press coverage of the Personal Information Protection Commission's fiscal 2025 annual report, private businesses had 17,139 incidents of personal data leakage and the like. That is down about 10% from the record 19,056 in the previous fiscal year.
The increases confirmed in the statistics are the half-year ransomware damage reports, the number of people affected by listed companies' leaks, and the number of companies announcing. But the organizations covered and the tallying periods differ, so they cannot be simply compared.
Behind the string of September announcements are also cases where investigations into breaches discovered over the summer were completed and results disclosed at this time.
The Digital Agency detected access to a large number of files on June 25 and determined on July 9 that the intrusion came through a VPN, but announced it on September 11.
Murauchi.com confirmed traces of unauthorized access on July 16 and published its investigation results on September 14. Times Car, by contrast, detected its breach on September 25 and issued its first report the same day.
The period from detection to announcement varies greatly by case.
The open-weight GLM-5.2 was released on June 16, 2026, before July, the earliest activity period of the attack campaign Gambit could confirm.
Meanwhile, the breaches announced in Japan in September include some discovered in June or July, such as the Digital Agency's June 25 detection and Murauchi.com's July 16 confirmation of traces.
The Digital Agency's June 25 detection came nine days after GLM-5.2's release, earlier than the activity Gambit could trace. However, the Digital Agency's entry point was a VPN device, which differs from the attacks Gambit recorded, which began with web application vulnerabilities.
The two cannot be linked on the basis of Gambit's report.
The actual start of an intrusion may also have preceded its detection date. The timeline alone can neither prove that open-weight models were used in Japanese breaches nor establish that they were not.
The National Police Agency's official statistics cover only through June, and no figures yet exist that would allow the announcements since July to be compared with the same period last year.
It is true that announcements of large leaks came in quick succession in September, but there are currently no statistics showing that "cyber damage itself surged in September."
None of 12 domestic announcements and reports states that AI was used
According to the National Police Agency's first-half 2026 report, in a survey of organizations hit by ransomware, about half of the intrusion routes were VPN devices.
In individual cases, Murauchi.com had multiple systems compromised starting from a vulnerability in its web system, and Gyazo was attacked through a vulnerability in its image-upload server.
At the Digital Agency's Government Solution Service, a vulnerability in a VPN device used for maintenance and operations was exploited.
On October 5, Daiwa Securities announced that a server of Scala Communications, to which it had outsourced inquiry management, was accessed without authorization and that the information of about 110,000 people may have been leaked.
Times Car, Keio Corporation and Seicomart, meanwhile, had not disclosed the cause of intrusion, as far as we could confirm.
According to the Digital Agency's Q&A, the exploited vulnerability had been made public before attacks were confirmed, and its rating at the time of announcement was "Medium" on CVSS.
The agency had moved to take countermeasures faster than usual, but the vulnerability was exploited before the fix was applied.
It has not disclosed the specific vulnerability, citing the risk of hindering future security.
The announcements explain only which device's vulnerability was used to get in, and which accounts were used to access what. There is no explanation of whether the series of operations was performed manually by humans or left to automated tools or AI.
The 12 items, covering 10 cases, are announcements and reports published from August to October 5, 2026, from Times Car (first and third reports), Keio, Gyazo, Murauchi.com, the Digital Agency (press coverage and Q&A), infoQ, Daiwa Securities, E-Store, Yellow Hat and EPARK.
None of nine terms appeared in the text of these 12 items: "generative AI," "artificial intelligence," "AI agent," "LLM," "GLM," "DeepSeek," "Claude," "open-weight" and "large language model."
We could not find any organization that explained it had used AI in an attack.
A private company's blog tallying 26 unauthorized-access and data-leak cases announced in Japan from September 1 to October 4 likewise says no organization disclosed that AI was used in the attack.
However, this does not prove that AI was not used. Some cases have not disclosed their cause, and if whether AI was used was never investigated, it may simply not appear in announcements or reports.
Professor Hiroyuki Takakura of the National Institute of Informatics told ASCII on October 5 that, regarding recent corporate damage, "I think AI was used to automate the attacks, but it did not play a major role," and expressed the view that the fundamental cause is inadequate countermeasures.
The National Police Agency's first-half report lists four arrest cases involving AI misuse.
Of these, the two that constitute cyberattacks are the June arrest of a 19-year-old company employee who built ransomware by combining AI-written code, and the July arrest by the Metropolitan Police Department of a 15-year-old boy who used an attack program modified with generative AI to cancel the memberships of about 46,800 accounts on a video-streaming service.
The other two were a special fraud in which an AI-generated face image was used to impersonate a police officer, and the creation of obscene images using AI.
The agency's report does not link these cases to the large-scale corporate data breaches.
Vulnerability scanning up 50.7%, and time to exploitation shortening
If AI is advancing the automation of attack preparation, its effect could first appear in the volume of "scanning" for vulnerable targets.
The National Police Agency's first-half 2026 report contains one figure pointing in that direction.
Suspicious access aimed at vulnerability scanning and the like, detected by the agency's sensors, reached 13,687 per day per IP address in the first half of 2026, a sharp 50.7% rise year on year. Most of it originated overseas.
The agency explains that attackers sometimes scan targets in advance as preparation for an attack.
However, this figure shows only the volume of scanning activity. It does not reveal whether it was carried out by humans, conventional automated tools or AI agents, nor which models were used.
In the attack Gambit reported, Strix ran scans against 138 hosts for a cumulative 633 hours, confirming that AI-driven automation of scanning is technically feasible.
There is, though, no basis for attributing the rise in suspicious access the National Police Agency observed to the spread of open-weight AI.
There are also figures showing change in the speed from vulnerability disclosure to confirmed exploitation.
According to VulnCheck's tally for the first half of 2026, the median time from a CVE (Common Vulnerabilities and Exposures) being published to its listing in the KEV catalog of known exploited vulnerabilities shortened from 120 days to 80 days.
The company cautiously describes this as vulnerabilities "appearing to be exploited faster."
However, the KEV listing date is set when evidence of exploitation is found and recorded. It does not necessarily match the day attackers actually began exploiting.
This metric alone therefore cannot distinguish whether attacks themselves became faster or whether the time taken to detect and record exploitation became shorter.
There were 1,061 vulnerabilities discovered with AI assistance, of which 14, or 1.3%, were confirmed exploited in the wild. VulnCheck explains that this rate is about the same as the exploitation rate for all vulnerabilities confirmed in the first half of 2026.
Even for a vulnerability found through scanning, an attack does not succeed if a fix can be applied before it is exploited.
GTIG analyzes that attackers are using both commercial and open-weight models to speed up the creation of n-day exploits that hit known vulnerabilities by exploiting the gap before patching.
An example it cited is a group of LLM-generated exploits, confirmed about a month after the patch was released, targeting an already-fixed Firefox vulnerability.
The Digital Agency case is also an example of a published vulnerability being exploited before the fix was applied, and fits this pattern structurally. There is, however, no statement that AI was used.
We could not find official statistics showing how quickly Japanese organizations fix vulnerabilities.
One reference is a survey by Tanium: in 2021, only 4% of 653 valid respondents completed responses within one day, and in 2024, 89% of 683 respondents applied patches once a quarter or less often.
Both, however, are self-reported surveys by a private vendor, not statistics measuring whether Japanese companies actually lag behind attackers' exploitation.
Hirotsubasa Fujii of Accenture Japan pointed out in an ITmedia interview published on September 3 that in Japanese companies, systems are complex and there is a practice of spending time on pre-verification, preparing procedure documents and post-application checks, which tends to delay patching.
In the same interview, Fujii said he expects the spread of open-weight models not to suddenly increase the number of people able to carry out advanced attacks, but to make the long-standing approach of "searching en masse for easy targets and striking them" still more efficient.
He also said that, because of GPU and server costs, fully autonomous attacks are "not yet widespread." That interview was published about three weeks before Gambit's report.
Professor Takakura also told ASCII that AI is speeding up attacks, saying, "Attack tools for published vulnerabilities can be made in an instant."
Both are expert opinions, not statistics that measured attack speed itself.
Activity searching for vulnerabilities is increasing, and AI and tools that can automate that work do exist. But most of the suspicious access the National Police Agency observed came from overseas, and it is also unknown whether it targeted the vulnerabilities exploited in domestic data leaks.
When can the model used in an attack be identified?
Gambit was able to identify the models used in the attack because it recovered the staging server the attacker was using and could reconstruct how the attack worked from the records left there.
Which model each of Strix, Cairn and Hermes used became clear through that investigation.
Another method is to identify the model from the logs of the company providing it.
In a November 2025 report, Anthropic explained that at the peak of AI-driven attack activity, thousands of requests were sent, often at a pace of several per second.
The company also admitted that it can see only Claude usage on its own side.
With open-weight models, this premise changes.
AISI points out that once model weights are released, safeguards can be removed, copies redistributed, and the model run on private systems beyond the reach of the developer's monitoring.
In activity GTIG observed that appears to be by the China-nexus espionage actor UNC6508, a local open-weight model was deployed on a compromised cloud environment to avoid monitoring by commercial APIs.
The attacker Gambit investigated, by contrast, used open-weight models as an API via OpenRouter, so per-request metadata remained on the intermediary service's side.
OpenRouter explains that it does not store prompts or response bodies unless the user consents, but does store metadata such as token counts and latency.
In other words, using open-weight models does not necessarily make the traces of an attack invisible. Visibility from the provider's side becomes difficult when a model is downloaded to a local environment and run without going through an external service.
There is also research that tries to tell AI use apart from observations on the victim side alone.
The 2024 paper "LLM Agent Honeypot" planted hidden instructions aimed at AI on a decoy SSH server and analyzed the attacker's reactions and response times.
From 8,130,731 attack attempts observed over about three months, it detected eight that were "possibly AI agents."
But what this method can determine is only the possibility of an AI agent, not which model was specifically used.
In the reports and research we reviewed, we found no public case in which the model used in an attack was identified from the logs of a victim company in Japan.
We also found no primary source that stated outright that "identification from the victim side is impossible."
In the data breach cases announced in Japan, there are no announcements of cases like Gambit's, where the attacker's infrastructure was recovered, or of investigations that went as far as the logs of model-providing companies.
Capability and overseas cases are confirmed; a causal link to Japanese breaches is not

The one case Gambit recorded as a completed attack combined SQL injection, file upload and a sudo misconfiguration, which are known types of vulnerabilities and configuration errors. It was not an attack that newly created an advanced zero-day vulnerability.
The same report also explains that the techniques used differed almost from victim to victim, so the method of this one case cannot be applied to all 27 companies.
By the attacker's own tally, the average cost per target was $25.46.
It can be called a real example of an AI system, including open-weight models, automatically carrying out the work of finding known types of vulnerabilities and combining several weaknesses to attack.
However, there is no evidence linking this attack infrastructure to the data breaches announced in Japan.
Breaking the hypothesis that "open-weight AI has increased criminals' attack capabilities" into four steps, what can be confirmed at present is as follows.
| Step | What was confirmed | Main sources |
|---|---|---|
| Capability | The cyber capabilities of the two evaluated models approached a level 4–7 months behind closed frontier models. The comparison partners are models up to February 2026. Cost for the same token volume is about half for GLM-5.2 and about 1/71 for DeepSeek V4-Pro. Modifications that weaken safeguards are also possible | UK AISI, Anthropic |
| Cases overseas | In Gambit's report, a single attacker used a setup including Strix (GLM-5.2 in August, then DeepSeek V4-Pro) and Cairn (DeepSeek V4.1 Flash in September), breaching at least 27 companies between September 10 and 15. GTIG and IPA also observed and summarized attacks using open-weight models | Gambit, GTIG, IPA |
| Connection to Japan | Gambit mentions one Japanese travel booking site, but the name, timing and model used are unknown. Some domestic cases had web systems as the entry point, and suspicious access observed by the National Police Agency is up 50.7% year on year. But there are no domestic announcements or statistics showing use of a specific model | Gambit, National Police Agency, 12 domestic announcements and reports |
| Causal link | No public case has been confirmed in which the AI model used in an attack was identified in a Japanese data breach | Not confirmed |
From public information as of October 7, 2026, it cannot be said either that open-weight AI was the cause of Japan's data breaches or that it was not.
What has been confirmed is that the cyber capabilities of open-weight models are improving and that there are cases of their use in real attacks overseas.
The connections to Japan that can be confirmed are limited to three points: Gambit mentions one Japanese travel booking site; some domestic cases and Gambit's attacks both used web-system vulnerabilities as the entry point; and suspicious access that appears to be vulnerability scanning is increasing.
None of these is evidence that a specific AI model was used in an attack within Japan.
The claim that "AI has increased criminals' attack capabilities" and the claim that "recent data breaches in Japan were caused by AI" need to be considered separately.
The former is backed by overseas cases, but we cannot find published material supporting the latter at present.
There are three things that could change the assessment going forward.
First, Gambit's final report or other security firms' research could specifically identify Japanese victim companies or sites.
Second, the intrusion routes and whether AI was used could become clear for cases announced in Japan. In its third report on September 29, Times Car said it would provide further details of the leak "in about two weeks." Whether that report includes the intrusion route will be the first thing to check.
Third, the National Police Agency's second-half 2026 statistics could be released, making it possible to compare damage and the clustering of announcements since July with the previous year.
The more the search for targets is automated, the more the period during which published vulnerabilities are left unfixed translates directly into time handed to attackers.
The Digital Agency case was one in which a vulnerability was exploited between its disclosure and the application of the fix. Whether or not AI was used, the basic structure, in which this time gap is what gets targeted, does not change.
