cloud.google.com 8 Sept 2026, 13:35 UTC

Google Says AI Agents Automated Credential Theft in Under Six Hours

Google Says AI Agents Automated Credential Theft in Under Six Hours
CyberSIXT Evidence Panel Source marked as original reporting
Threat Actor
UNC6780

GOOGLE Threat Intelligence Group (GTIG) says adversaries are moving from simple prompting towards agentic AI workflows and automated attack pipelines. In Q2 2026, one financially motivated actor reportedly compromised cloud infrastructure and used an AI coding chatbot, prompts and agent instructions to plan, build and run a mass credential-harvesting campaign in less than six hours. The framework automated vulnerability scanning, troubleshooting and IP rotation, compromising thousands of third-party credentials.

Another exposed system, called “Recon”, provided a dashboard for managing more than 23,800 harvested secrets, including cloud and AI service API keys.

The report also describes growing attacks on AI-related software and intellectual property. Since March 2026, UNC6780 (TeamPCP) has compromised PyPI, npm and Docker Hub ecosystems, using its DUSTMAKER malware to target developer accounts, hidden AI assistant workspace files and CI/CD credentials. Its techniques included malicious MCP servers, hijacked GitHub Actions tokens and prompt injection designed to make LLM security scanners overlook malware.

GTIG also observed theft of proprietary models, prompts, source code and research from organisations in healthcare, technology, government and media. In one April 2026 incident, an exposed GitHub personal access token enabled unauthorised AI infrastructure and high-performance compute workloads in a victim’s cloud environment.

GTIG stressed that it has not observed tracked actors deploying fully autonomous zero-day exploitation against targets in the wild, nor breakthrough automation in information operations. However, groups are using AI across reconnaissance, phishing, malware development, exploitation and post-exploitation. Google says it disabled assets and accounts linked to the activity, strengthened Gemini’s classifiers and model safeguards, and used threat intelligence to improve protections.

View full article

Article by CyberSIXT