September 9, 2026

AIincider

AI News. No Noise. Just Signal.

Autonomous AI Agents Stole Thousands of Credentials

3 min read
Google's threat intel team found attackers using autonomous AI agents to harvest thousands of credentials in under six hours. Read the full breakdown.

Google’s Threat Intelligence Group says a financially motivated attacker used a framework of autonomous AI agents to plan, build and run a mass credential harvesting campaign in under six hours, walking away with thousands of third-party credentials.

What Changed

Criminals have leaned on AI for a while now, mostly to sharpen phishing lures or debug their own tooling. A human still drove every step. GTIG’s new report describes something different. The operator supplied an AI coding chatbot, a prompt and a set of agent instructions, then let the system run.

Preconfigured markdown files acted as operational playbooks. From there the framework managed its own scanning pipeline, troubleshot problems in real time and handled its own IP rotation logic without anyone holding its hand.

Autonomous AI Agents Are a Speed Problem

John Hultquist, chief analyst at GTIG, put the risk plainly: criminals will gravitate toward attacks that move faster than defenders can respond. Six hours from setup to thousands of stolen credentials sits comfortably inside that gap.

The report catalogs a wider shift. Google now assumes every threat actor is using AI in some capacity. A China-aligned espionage group used Gemini to design an automated penetration testing framework. Another China-nexus actor, tracked as UNC6508, ran open-weight models on compromised cloud infrastructure specifically to sidestep the monitoring that commercial model providers apply. Russian, Iranian and North Korean groups appear throughout, using commercial models for reconnaissance, social engineering and workflow automation.

AI Systems Are Now the Target

The other half of the story is that enterprise AI has become worth stealing. Google observed attackers exfiltrating API credentials, hijacking victim cloud environments to run their own AI workloads, and lifting proprietary models, prompts and research outright. A group tracked as TeamPCP has hit PyPI, npm and Docker Hub, deploying credential stealers that specifically go after AI coding assistants, according to The Hacker News.

Why It Matters

Google’s own recommendation is uncomfortable for anyone hoping for a clean fix. Simply gating open-weight models is impractical, the company argues, because those models drive real innovation. Its answer is enforceable industry-wide safety baselines for open source AI plus coordinated platform policies on uncensored model variants. That is a slow remedy for a fast problem.

For defenders the practical takeaway is narrower and more urgent. Credentials sitting in CI/CD pipelines and AI developer configurations are now first-class targets, and a response window measured in days no longer matches an adversary measured in hours.

Continue Reading…

Leave a Reply