Skip to content
Security & Trust Talking point

Hammond: criminals can skip scam brands, as uncensored models are a free download

John Hammond showed criminal AI brands that looked like scams, then a forum guide to running uncensored models anyone can download.

W
WebPulse Newsroom
AI-assisted · 2 min read
Share on X LinkedIn
Hammond: criminals can skip scam brands, as uncensored models are a free download
In brief
  • John Hammond showed criminal AI brands that looked like scams or resold wrappers, then a forum guide to running uncensored models from Hugging Face.
  • Our reading: takedowns aimed at named products would miss modified models that are already public and can be run on rented servers.

John Hammond toured criminal AI listings on his show's "Black Hat AI" episode (October 1, 2026). Several looked like scams or repackaged products. He then showed a forum guide to running an uncensored model that anyone can download. His point was that criminals do not need to build offensive AI, because they can rent or buy it.

What was said

Hammond browsed cybercrime forum listings. One tool cost $10 a month, which he compared to a streaming subscription. Its footer links led nowhere. Another cost $100 a month and had an enterprise tier and an FAQ. A forum user wrote that he had paid and the site did not work.

Hammond agreed with a report he cited: criminals are not building advanced AI platforms from scratch. They wrap or resell other solutions. In his words, "Hackers don't need to build offensive AI because they could just rent or buy whatever they want."

He found the forum guide to the alternative more interesting. You pick a model from Hugging Face, which he likened to GitHub for AI models. The guide used models with the prefix "obliterated", which he said means they have no censorship. You then rent a server on RunPod, paying only while the model is in use, and connect it to a coding tool. Hammond called the setup easy.

He also cited an industry report, which he noted was somewhat dated, saying such models were downloaded more than 22 million times in 30 days.

Why it matters

Our reading: a branded criminal product is a storefront, and storefronts are easy to replace. The models in the guide are modified copies of public models, posted on a public hub. Once copies are downloaded, removing one listing or brand does not reach them. A rented server also means the attacker owns no hardware. A rule aimed at named products would hit the layer attackers need least.

For security leaders, we suggest three questions. What does your detection assume about the attacker's tooling? Which of your controls depended on attackers' AI tools refusing to help? Does any vendor promise rest on blocking misuse at the AI provider?

The other side

Hammond did not claim every branded tool is fake. He said one "could very well have some legitimacy". He also said the hype holds some truth, but that the picture needs a lot of nuance.

A download count does not show attacks. The excerpts do not say how many of those 22 million downloads were used for crime.

Mainstream models also appear in his examples. He described attackers chaining Claude, Qwen and probably DeepSeek against Asian governments. In another case he cited, the first break-in was still done by a human. So the threat is not only obliterated models.

Hammond did not discuss regulation. The step from his findings to policy is ours, and the conversation left it open.

Written by the WebPulse Newsroom with AI assistance, and checked by our editorial review: every quotation was verified against the recording's transcript. How we use AI.

The conversation this talking point comes from

Share this insight