
Cyber Security
Google Says Hackers Used AI Agents To Steal Thousands Of Credentials In Under Six Hours
Updated on Tue, Sep 8, 2026
Hackers are moving beyond using artificial intelligence as a coding assistant, with Google researchers observing multi-agent AI frameworks that automate vulnerability scanning, troubleshooting and credential theft, including one campaign that compromised thousands of credentials in under six hours.
TL;DR
- Google observed attackers using autonomous AI agents to automate multiple stages of cyberattacks.
- One financially motivated campaign compromised thousands of third-party credentials in less than six hours.
- A separate framework called Recon managed more than 23,800 harvested secrets.
- Google says fully autonomous real-world hacking pipelines are not yet widespread.
According to the Google Threat Intelligence Group's latest AI Threat Tracker, threat actors are increasingly shifting from basic prompts and AI coding assistance toward agentic systems capable of managing multiple stages of an attack with limited human intervention.
The findings are based on Mandiant incident response engagements, Google's threat-actor tracking and defenses across its platforms.
"Threat actors have moved beyond simple prompt-based LLM interactions," GTIG said, noting that AI capabilities are increasingly being integrated across different stages of the attack lifecycle.
AI Agents Helped Launch Credential Theft Campaign In Under Six Hours
In one case, Mandiant observed a suspected financially motivated attacker compromise an organization's cloud infrastructure and deploy an autonomous multi-agent attack framework.
Using an AI coding chatbot, a prompt and preconfigured instructions stored in markdown files, the attacker planned, built and executed a mass credential-harvesting campaign in less than six hours.
The framework automatically managed vulnerability scanning, real-time troubleshooting and IP address rotation without requiring continuous human intervention.
Google said the campaign compromised thousands of third-party credentials. By operating from compromised cloud infrastructure, the attacker could also route malicious traffic through legitimate IP addresses, making detection more difficult.
BleepingComputer noted that this approach reduced the amount of human involvement required during the operation, while also shrinking the amount of time defenders had to respond.
Recon Framework Managed More Than 23,800 Harvested Secrets
Google also uncovered a separate exposed command-and-control server running an automated reconnaissance and credential-management framework dubbed Recon.
The exposed server contained configuration and knowledge files designed for AI agents, including files named AGENTS.md, KNOWLEDGE.md and agentic_vuln_research.md, along with OpenClaw-related components.
Google later observed the exposed directory transition into a functioning dashboard capable of organizing, validating and managing more than 23,800 harvested secrets in real time.
Those secrets included API keys for cloud and AI services.
GTIG described the operation as a shift from traditional endpoint-focused information stealers toward agentic systems that can research vulnerabilities, scan infrastructure and conduct targeted exploitation with much less manual intervention.
Google said it took action against actors associated with the activity by disabling related assets and updating safeguards intended to prevent further abuse.
Topics For More Insights
State-Backed Hackers Are Experimenting With Agentic AI Too
The trend is not limited to financially motivated cybercriminals.
Google observed a China-linked cyberespionage group using Gemini while attempting to design an automated penetration-testing framework that could observe a target environment, determine possible actions and execute discovery tasks such as port scanning.
Another Russia-based threat group, UNC5792, experimented with integrating AI models into bots that monitor Telegram channels and classify information of interest to Russian authorities.
Meanwhile, financially motivated UNC6780, also known as TeamPCP, has targeted open-source software ecosystems including PyPI, npm and Docker Hub. Google says the group uses credential-stealing malware and has shown interest in AI tools and proprietary AI assets.
Fully Autonomous Cyberattacks Are Not Widespread Yet
Despite the increased use of AI agents, Google cautioned against interpreting its findings as evidence that completely autonomous hacking has become common.
Instead, Google's observations point to a gradual shift in which attackers add AI capabilities to existing tools and workflows, allowing them to automate more decisions and operate faster with fewer manual steps.
The company also said Gemini's safety systems detected several attempts to misuse the model, enabling Google to disrupt campaigns, disable associated accounts and update protections against similar activity.
For defenders, the emerging concern is therefore not that AI has completely replaced human hackers, but that attackers can increasingly use agentic systems to compress tasks that once required more people, more manual intervention and more time.
First published on Tue, Sep 8, 2026
Enjoyed what you read? Great news – there’s a lot more to explore!
Dive into our content repository of the latest tech news, a diverse range of articles spanning introductory guides, product reviews, trends and more, along with engaging interviews, up-to-date AI blogs and hilarious tech memes!
Also explore our collection of branded insights via informative white papers, enlightening case studies, in-depth reports, educational videos and exciting events and webinars from leading global brands.
Head to the TechDogs homepage to Know Your World of technology today!
Disclaimer - Reference to any specific product, software or entity does not constitute an endorsement or recommendation by TechDogs nor should any data or content published be relied upon. The views expressed by TechDogs' members and guests are their own and their appearance on our site does not imply an endorsement of them or any entity they represent. Views and opinions expressed by TechDogs' Authors are those of the Authors and do not necessarily reflect the view of TechDogs or any of its officials. While we aim to provide valuable and helpful information, some content on TechDogs' site may not have been thoroughly reviewed for every detail or aspect. We encourage users to verify any information independently where necessary.
Loading comments...

