AI agents steal thousands of credentials in six-hour campaign
A suspected financially motivated threat actor used an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential-harvesting campaign in less than six hours, according to Google Threat Intelligence Group's September 8, 2026 report, *From Prompting to Autonomy: The Evolution of Adversarial AI*.
The attack demonstrates how agentic systems—AI agents capable of autonomous planning and execution—can be weaponized at machine speed to compromise enterprise security. Google's threat report stated, "The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours." Thousands of third-party credentials were stolen from the unnamed organization's cloud infrastructure.
The Attack Method
The attacker employed a multi-agent framework capable of automated scanning, troubleshooting, and IP rotation—capabilities that would have required significantly more time and human intervention using traditional hacking tools. By chaining an AI coding assistant with agentic instructions, the actor automated reconnaissance, payload development, execution, and credential exfiltration. The speed—less than six hours from initial access to mass credential theft—underscores a critical shift in threat actor capability: agentic AI systems eliminate the manual labor bottleneck that has historically constrained large-scale campaigns.
Broader Context
This disclosure arrives as cybercriminals increasingly adopt AI-powered tools for offensive operations. In August 2026, Russian-speaking hackers used SpaceX's Cursor AI tool to breach a Belgian chemical company and at least six other organizations, according to Reuters reporting. That incident, however, did not involve the autonomous agent orchestration documented in Google's September report.
Implications for Agent Governance
The incident raises urgent questions about the real-world harm enabled by agentic AI systems. Unlike traditional code-generation tools that require human direction at each step, autonomous agents can be given a single high-level instruction—"harvest credentials from this environment"—and execute a complete attack with minimal further human input. The six-hour timeline suggests that defensive measures built around human-paced threat detection will be insufficient against agent-powered intrusions.
Google's disclosure does not identify the location, victim organization, actor identity, legal penalties, or regulatory response. No charges have been filed or sentences handed down in connection with this attack. The threat report, however, serves as a concrete example of how developer tools and AI capabilities are reshaping the criminal threat landscape in real time.