Ensign: Frontier AI Models Demonstrate Capability to Reduce Cyberattacks to Hours at Fraction of Cost
Lowering the Barriers to Sophisticated Cyberattacks as Ransomware, Data Theft, and Hacktivism Continue to Rise Across Asia Pacific

A new report from Ensign InfoSecurity, Asia Pacific’s largest pure-play cybersecurity service provider, reveals that frontier AI models are already capable of executing multiple stages of a realistic enterprise cyberattack chain. The findings suggest that offensive cyber capabilities are becoming increasingly accessible as frontier AI lowers the cost, time and expertise required to conduct sophisticated cyberattacks. Ensign’s assessment of 10 generally available frontier AI models also found that performance is converging across Eastern and Western models, suggesting that cost, rather than capability, may increasingly become the deciding factor for threat actors.
The findings are part of the seventh edition of Ensign’s 2026 Cyber Threat Landscape Report, which combines Ensign’s regional cybersecurity operations, threat intelligence, incident response work and international engagements. This edition includes findings from Ensign’s proprietary AI Cyber Range Assessment, which evaluates the offensive capabilities of frontier AI models and their implications for cyber defence.
Frontier AI Is Changing the Economics of Cyberattacks
Since the start of 2026, Ensign has built an AI range to assess and understand the capabilities of frontier models in cybersecurity. In one assessment, 10 generally available frontier AI models assumed the role of an advanced cyber threat actor and were sequentially presented with eight attacker objectives.
Among the models, OpenAI’s GPT-5.6 Sol, Anthropic’s Claude Opus 4.8 and Z.AI’s GLM 5.2 proved most capable, achieving high success in seven out of the eight attacker objectives. Meanwhile, Z.AI’s GLM-5.2 delivered offensive performance comparable to GPT-5.6 at roughly one-fifth of the operating cost, while open-source Eastern models consistently delivered significantly higher capability per dollar. Looking at model capabilities across all 10 models, gaining initial access was shown to be a trivial task. This underscores the need for organisations to treat a breach as inevitable, rather than a remote possibility.
When assessing model reliability, at least half the models struggled to steal credentials and move between systems consistently, suggesting that network segmentation, trust boundaries and controls limiting lateral movement remain effective to create friction for the AI model attackers. This reinforces the importance of strong internal defences as AI-enabled attacks become more capable. Additionally, none of the models were able to confidently evade detection tools, with even the leading models recording only partial success. This highlights the continued importance of effective detection capabilities as a practical defence against AI-enabled cyberattacks.
Regional Trends Show the Shift to an AI-Enabled Threat Tandscape
The Cyber Threat Landscape Report also shows how the wider threat environment across Asia Pacific is evolving as AI becomes an increasingly important enabler of existing cyberattack techniques. While frontier AI is making sophisticated attacks more accessible, attackers continue to rely on living-off-the-land techniques that can be difficult to distinguish from legitimate activity. AI is acting as a force multiplier rather than replacing existing tradecraft.
-
AI is accelerating the industrialisation of ransomware: AI is enabling ransomware groups to scale their operations by accelerating reconnaissance, identifying vulnerabilities and crafting more convincing phishing lures, making attacks faster, more sophisticated and easier to repeat. The impact differs across regions.
-
ASEAN: Ransomware activity doubled in 2025, with the top 18 ransomware groups targeting the region.
-
-
Data theft is becoming more valuable than encryption: Data theft is increasingly replacing encryption as the primary driver of cyberattacks. Edge devices, remote access infrastructure and third-party suppliers remain common entry points into organisations, exploiting vulnerabilities that have remained unpatched for years.
-
Within ASEAN, Singapore provides a compelling example of this shift, with the highest underground value attributed to Singaporean 1Fullz identity package at USD 95. This is more than three times its price in 2023 at USD 30.
-
The growing premium reflects the country’s position as one of Asia’s most trusted and digitally connected economies, where high-quality identities, financial information and enterprise data command greater value for cybercriminals. As digital economies across the region continue to mature, trusted ecosystems are becoming increasingly attractive targets for sophisticated threat actors.
-
-
Hacktivism is increasingly targeting critical infrastructure: ASEAN recorded the highest level of hacktivist activity (19.1%) among the three regions. Targeting has expanded beyond government organisations to include critical infrastructure, including utilities, energy, transportation and telecommunications providers. Banking, Finance & Insurance (BFI), Manufacturing & Industrial and Telecommunications, Media and Technology (TMT) remained among the most targeted sectors due to the value of their data and operational importance. Business & Professional Services are also actively targeted in ASEAN as it serves as important information processors and suppliers to many larger organisations.
“Organisations should strengthen their cybersecurity foundations by prioritising the scanning and patching of critical internet-facing assets and continuously validating their defences against the latest AI models. With frontier AI capabilities advancing on a roughly two-month cycle, security controls cannot afford to remain static. Agility and dynamism in cyber defence defines the good cyber defender from the rest.”



