- John Hammond said one report found a ransomware gang spent 40 cents to $4 in AI costs per company attacked.
- Our reading is that if such costs are typical, defenders should plan for attack volume, though Hammond did not say this.
John Hammond, on his show in the episode "Black Hat AI", described one report on a ransomware gang. According to him, the attackers spent as little as 40 cents to four dollars in AI costs for each company they attacked. Hammond argued that dollars are now an extra variable in cybersecurity, and that the amounts involved are small.
What was said
Hammond said the figure came from a report on the Gentleman ransomware gang, published in early September. He explained that tokens, the units AI services bill by, cost money on the big commercial models. That changes when attackers run models on their own machines, he said. The cost per target therefore depends on which kind of model the attacker uses.
He also described how such an attack starts. The attacker hands an AI agent a web address and perhaps some access already found, likely from stealer logs (stolen saved logins) bought from initial access brokers. Then the agent carries out the attack. Hammond put it this way: "Most attacks start as AI prompts."
His evidence for how these setups work came from two write-ups. In a Palo Alto Networks Unit 42 case, an autonomous agent accidentally launched a file server in its own home folder. That exposed its tools, models and exploits to researchers. In a Hunt.io case, attackers chained together several AI models, including Claude and Qwen, to target Asian governments. Hammond added that criminals mostly wrap or resell existing AI products instead of building their own.
Why it matters
Our reading, offered as a hypothesis: if the cost per target really is this low, money stops being the main brake on attacks. Access may become the scarce item, and Hammond tied access to stolen logins and brokers. Hammond did not say attackers are widening their targets, or that defenders should plan for volume. That step is ours.
For managers, the practical start follows from his description. Find out which of your staff logins may already sit in stealer logs. Know which of your systems face the internet, since a web address is all the agent was given in the flow he described.
The other side
Hammond himself urged nuance. He said the hype holds some truth, but he rejected doom-and-gloom talk about killer AI. In the Unit 42 case, he said, the first way in was still done by a human, by hand. He expected machines to take over that step, but not yet.
The cost figure rests on one report about one gang, relayed on a podcast. It may not hold for attackers who pay frontier-model prices. Hammond called the situation a rallying cry, not a reason for despair.
Written by the WebPulse Newsroom with AI assistance, and checked by our editorial review: every quotation was verified against the recording's transcript. How we use AI.
The conversation this talking point comes from
- John Hammond: Black Hat AI (2026-10-01)





