Military & Security

Google says attackers used AI agents to steal credentials in under six hours

· September 8, 2026
Google says attackers used AI agents to steal credentials in under six hours

What happened

Google’s Threat Intelligence Group reported that attackers used an AI-powered multi-agent framework to steal thousands of credentials in under six hours. The campaign began with a breach of a company’s cloud infrastructure, after which the attacker deployed autonomous AI agents to move fast and expand access. Mandiant traced this activity to a financially motivated criminal group leveraging AI automation to accelerate credential theft.

The risk

This attack exposes how AI can dramatically speed up the process of breaking into enterprise environments. Automated agents handle tasks that normally require manual hacking steps, reducing time windows for detection and response. The rapid credential harvesting makes traditional security controls like monitoring and manual investigation less effective, increasing the operational risk for organizations relying on cloud infrastructure.

Why it matters

Organizations face higher pressure to adopt automated, AI-driven defense tools that operate at machine speed. Manual security workflows will struggle to keep pace against AI-powered intrusions that move laterally and escalate privileges quickly. This also raises the bar for cloud security hygiene, identity management, and incident response, as attackers using AI frameworks will target any gaps with faster, more persistent attempts.

Who should pay attention

Security teams, cloud operators, and risk managers must treat AI-enabled attacks as a new baseline threat model. Founders and CIOs should prioritize investment into AI-enhanced detection and response platforms that automatically identify and thwart autonomous adversary agents. Regulators and compliance officers should consider updating standards to address the risks introduced by AI-assisted intrusions.

What to watch next

Look for new defensive AI tools designed specifically to counter autonomous attacker frameworks. Expect more threat intelligence on how adversaries combine AI with cloud vulnerabilities. Monitor shifts in cloud security protocols emphasizing identity and access management, automated threat hunting, and rapid incident containment to stay ahead of AI-enabled credential theft.

AI Quick Briefs Editorial Desk

Stay ahead of AI Get the most important AI news delivered to your inbox — free.