Google: Autonomous AI Agents Stole Thousands of Credentials in Hours
A financially motivated hacking group used a multi-agent AI framework to execute a mass harvesting campaign in under six hours.
Google's Threat Intelligence Group (GTIG) has identified a financially motivated hacking group using a multi-agent AI framework to execute a mass credential harvesting campaign. The operation represents a significant escalation in attacker capabilities, as the system autonomously planned and executed the theft of thousands of credentials in less than six hours.
According to GTIG, the attack framework operated without human intervention after receiving an initial prompt and agent instructions. The AI agents managed the entire lifecycle of the operation—including planning, building, and running the campaign—utilizing preconfigured playbooks to handle scanning, troubleshooting, and IP rotation. The attackers specifically targeted proprietary AI models within the healthcare, government, and media sectors to exfiltrate API credentials and co-opt cloud environments.
The Shift to Autonomous Warfare
This incident is part of a broader global trend where threat actors are integrating artificial intelligence into their offensive workflows. While AI has previously been used for lower-level tasks such as drafting phishing emails or debugging malicious code, it is now being leveraged to create automated penetration testing frameworks. Some actors are even running open-weight models on compromised infrastructure to bypass the safety filters and monitoring present in commercial AI services.
A New 'Speed Problem' for Defenders
The transition to autonomous AI agents creates a critical temporal imbalance between attackers and defenders. By reducing the time between setup and execution to a matter of hours, adversaries can now operate at a velocity that far outpaces traditional security response times, which often span several days.
"Criminals will gravitate toward attacks that move faster than defenders can respond," said John Hultquist, chief analyst at GTIG. This shift signals that enterprise AI assets—including API keys, proprietary models, and system prompts—have become high-value targets for both resource theft and corporate espionage.
Future Outlook
Security teams must now account for a landscape where the reconnaissance and exploitation phases of an attack happen almost instantaneously. The GTIG report highlights a growing need for automated defense mechanisms that can match the speed of AI-driven agents. It remains to be seen how widely these autonomous frameworks will be adopted by other hacking collectives and whether current cloud security protocols can evolve quickly enough to protect sensitive API environments from such rapid-fire incursions.