Unit 42 said a human attacker directed AI agents that seized administrative credentials and cloud keys during an intrusion that would normally take about two weeks.
Palo Alto Networks’ Unit 42 said AI agents carried out much of an enterprise intrusion in less than 10 hours, then left behind an 80-page report detailing the security weaknesses they exploited.
A human attacker set the objectives and made major decisions. The agents handled much of the work between those decisions, including exploring the company’s network, searching source code for passwords, and using stolen credentials to gain wider access.
Unit 42 said comparable work would normally take human security teams about two weeks. The firm did not identify the affected company or the attacker.
Unit 42 initially described the incident as a ransomware attack. It updated the article to clarify that it was an intrusion, not a ransomware attack.
Agents moved through the company in under 10 hours
The attacker breached an unidentified company system that was accessible from the public internet, then used it to enter the company’s internal network.
Other agents searched the company’s source-code repositories and found access tokens and service passwords stored in the files. The attacker used those credentials to enter the company’s system for storing sensitive credentials and obtain administrative access.
The agents took control of a tool the company used to build and release software. They ran unauthorized tasks through it to extract keys that opened the company’s cloud services.
Using the stolen cloud keys, the attacker used the company’s own AI services to continue the intrusion. Unit 42 said the activity could blend in with normal AI use, while the company paid for the computing power.
According to Unit 42, the agents used more than 50 attack techniques during the intrusion.
The attacker claimed advanced AI models powered the operation
Unit 42 said the attacker claimed to have used advanced AI models and specialized software for coordinating AI agents. The firm said the statement was made during unspecified negotiations, but did not explain what was being negotiated or why its investigators were communicating with the attacker.
Unit 42 said it observed several signs supporting the use of AI. These included calls to multiple AI agents at the same time, structured files used to pass information between agents, and custom software that Unit 42 assessed was probably generated by AI.
Unit 42 concluded this was a human-driven attack. They described the human attacker as setting the objectives and making major decisions, while the agents handled tactical work, shared results, and adjusted their next steps.
After the intrusion, an agent produced and delivered an 80-page technical assessment describing dozens of security weaknesses the attacker had used. Unit 42 did not explain why the attacker created the report or what they intended to do with it.
One company control stopped an attempted backdoor
The attacker tried to change files that control the company’s cloud systems to maintain access after the intrusion.
The company’s protections blocked that change. These controls prevent people or automated systems from altering protected code without following the company’s required review process.
Unit 42 recommended that companies be ready to block an attacker from every compromised system at the same time, rather than closing one access point while leaving others open. That can include disabling compromised credentials, ending the attacker’s active login sessions, halting automated software tasks they started, and isolating affected cloud accounts.
The firm also called on companies to maintain an inventory of their AI services and access keys, restrict what each account can do, and record how those services are used.
Unit 42 said attackers are likely to use AI agents more frequently because they can complete multiple attack steps at once and quickly adjust when conditions change.

