Skip to content
Menu
Menu

AI Agents Carry Out 10-Hour Intrusion and Leave 80-Page Security Audit Afterward

Unit 42 said a human attacker directed AI agents that seized administrative credentials and cloud keys during an intrusion that would normally take about two weeks.

 

Palo Alto Networks’ Unit 42 said AI agents carried out much of an enterprise intrusion in less than 10 hours, then left behind an 80-page report detailing the security weaknesses they exploited.

A human attacker set the objectives and made major decisions. The agents handled much of the work between those decisions, including exploring the company’s network, searching source code for passwords, and using stolen credentials to gain wider access.

Unit 42 said comparable work would normally take human security teams about two weeks. The firm did not identify the affected company or the attacker.

Unit 42 initially described the incident as a ransomware attack. It updated the article to clarify that it was an intrusion, not a ransomware attack.

Agents moved through the company in under 10 hours

The attacker breached an unidentified company system that was accessible from the public internet, then used it to enter the company’s internal network.

Other agents searched the company’s source-code repositories and found access tokens and service passwords stored in the files. The attacker used those credentials to enter the company’s system for storing sensitive credentials and obtain administrative access.

The agents took control of a tool the company used to build and release software. They ran unauthorized tasks through it to extract keys that opened the company’s cloud services.

Using the stolen cloud keys, the attacker used the company’s own AI services to continue the intrusion. Unit 42 said the activity could blend in with normal AI use, while the company paid for the computing power.

According to Unit 42, the agents used more than 50 attack techniques during the intrusion.

The attacker claimed advanced AI models powered the operation

Unit 42 said the attacker claimed to have used advanced AI models and specialized software for coordinating AI agents. The firm said the statement was made during unspecified negotiations, but did not explain what was being negotiated or why its investigators were communicating with the attacker.

Unit 42 said it observed several signs supporting the use of AI. These included calls to multiple AI agents at the same time, structured files used to pass information between agents, and custom software that Unit 42 assessed was probably generated by AI.

Unit 42 concluded this was a human-driven attack. They described the human attacker as setting the objectives and making major decisions, while the agents handled tactical work, shared results, and adjusted their next steps.

After the intrusion, an agent produced and delivered an 80-page technical assessment describing dozens of security weaknesses the attacker had used. Unit 42 did not explain why the attacker created the report or what they intended to do with it.

One company control stopped an attempted backdoor

The attacker tried to change files that control the company’s cloud systems to maintain access after the intrusion.

The company’s protections blocked that change. These controls prevent people or automated systems from altering protected code without following the company’s required review process.

Unit 42 recommended that companies be ready to block an attacker from every compromised system at the same time, rather than closing one access point while leaving others open. That can include disabling compromised credentials, ending the attacker’s active login sessions, halting automated software tasks they started, and isolating affected cloud accounts.

The firm also called on companies to maintain an inventory of their AI services and access keys, restrict what each account can do, and record how those services are used.

Unit 42 said attackers are likely to use AI agents more frequently because they can complete multiple attack steps at once and quickly adjust when conditions change.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!