The human-led operation reached a scale normally associated with larger hacking groups and sent attack traffic through a victim company’s legitimate internet addresses.
Key Takeaways
- A suspected financially motivated attacker used AI agents to build and run a large credential-theft operation in less than six hours.
- The attacker supplied the objectives and instructions, while the agents managed much of the scanning and credential theft without constant human direction.
- Google found a separate automated system managing more than 23,800 stolen credentials and digital access keys.
A suspected financially motivated attacker used AI agents to build and carry out a large credential-theft operation in less than six hours, according to a new Google Threat Intelligence Group report.
The operation compromised thousands of credentials and reached a scale that Google said would normally be associated with a larger, better-resourced hacking group.
The attacker first accessed an organization’s cloud infrastructure. The attacker used an AI coding tool to build the operation and gave AI agents written playbooks to scan vulnerable systems and steal credentials.
Human operators remained in control of the overall attack. The AI agents handled much of the work of finding vulnerable systems and stealing the information needed to access them.
By running the attack through the victim’s cloud systems, the attacker could send malicious traffic from legitimate internet addresses associated with a real organization. This made the traffic more difficult to distinguish from normal activity.
AI agents kept the attack running with limited oversight
The written instructions told the agents how to complete their assigned tasks.
The agents managed the system that scanned for vulnerable targets and attempted to steal credentials. When the operation encountered technical problems, the agents adjusted their actions and continued without waiting for human operators to step in.
They also changed the internet addresses used to send attack traffic. Google said this reduced the ongoing attention required from the human attacker.
The case showed attackers moving beyond using AI only to answer questions or write malicious code. Google said some attackers are now assigning multiple parts of an operation to groups of AI agents.
Separate AI system managed stolen access at scale
Google also discovered an exposed server hosting a separate automated system built to find vulnerable systems and manage stolen access.
The system included a dashboard designed to organize and verify more than 23,800 stolen credentials and other access information, including digital keys for cloud and AI services.
Google said AI agents connected to the system could identify weaknesses, scan internet-facing systems, and attempt to exploit them with little human involvement.
Google has not seen fully autonomous attacks
Google said it has not yet observed a fully autonomous system select a target and carry out an entire attack without human involvement.
Instead, the report describes a gradual shift in which human attackers retain overall control while assigning more operational work to AI.
The report also documented attackers stealing proprietary AI models and related research from companies, sometimes for extortion. In separate software supply-chain attacks, malicious files contained instructions designed to manipulate AI coding assistants or make AI security scanners skip reviewing harmful code.
Google said it disabled accounts and other assets connected to the activity and used the findings to strengthen its models’ safeguards against similar misuse.
While no fully autonomous attack has been reported, the UK’s AI Security Institute (AISI) ran simulated, fully autonomous attacks using Claude Mythos earlier this year.

