Skip to Content
Join the Network with Us — Join Membership


Google Warns Hackers Are Moving From AI Prompts to Autonomous Cyberattacks

September 10, 2026

Hackers recently built and launched an AI-assisted credential-stealing operation in under six hours, compromising thousands of third-party credentials in the process, according to new research from Google Threat Intelligence Group (GTIG). The finding marks a genuine shift in how cybercriminals are using artificial intelligence, no longer just writing convincing phishing messages or researching potential victims, but instructing AI systems to carry out multiple stages of an attack with far less human oversight.

A Six-Hour Attack, Start to Finish

Google's latest GTIG AI Threat Tracker, released September 8, says both state-backed hacking groups and financially motivated criminals are moving away from simple AI prompting toward what researchers call "agentic" workflows, AI systems capable of pursuing a broader goal through multiple connected steps, rather than waiting for a fresh instruction at every stage.

In one case observed during the second quarter of 2026, attackers first compromised an organisation's cloud infrastructure. They then used an AI coding chatbot, along with instructions and operational playbooks, to build a multi-agent system. Within just six hours, this system was actively scanning targets and harvesting credentials from third parties. According to Google, the framework could troubleshoot its own problems, rotate IP addresses, and continue vulnerability scanning with minimal manual intervention, effectively running much of the attack on autopilot once set in motion.

Notably, the attackers operated through compromised cloud infrastructure themselves, meaning malicious activity could appear to originate from legitimate internet addresses rather than obviously suspicious criminal servers, making detection considerably harder for defenders relying on traditional threat signatures.

Another system GTIG uncovered contained a dashboard capable of organising and validating more than 23,800 harvested credentials, including API keys tied to cloud and AI services. It's worth being clear here: these systems aren't evidence that cyberattacks have become fully autonomous, human attackers still choose targets, provide instructions, and control the broader operation. What's changing is how much can now happen automatically between those human decisions.

How AI Agents Differ From Ordinary Chatbot Prompts

A typical AI interaction begins when someone asks a chatbot to perform one specific task; the AI responds, and the person decides what happens next. An AI agent, by contrast, can be given a broader goal and allowed to take several connected steps toward it, scanning a system, analysing findings, correcting errors, and moving to the next target, all without waiting for fresh human instruction at each stage.

That distinction matters significantly in cybersecurity. A criminal could previously use AI to help write malicious code; an agentic system could potentially help run parts of the actual operation itself, shrinking the gap between discovering a vulnerability and exploiting it. Google says a China-linked espionage group it tracks as BASIN CASTLE has already integrated generative AI across several stages of its cyber operations, using large language models to research high-value targets, translate and draft social-engineering material, help create obfuscated malware, and troubleshoot commands after gaining access to compromised systems.

AI Infrastructure Itself Is Now a Target

The threat runs in both directions. Criminals aren't just using AI, they're increasingly attacking the infrastructure that powers it. GTIG found attackers targeting proprietary models, source code, prompts, developer credentials, and cloud computing resources across sectors including government, healthcare, and media.

A financially motivated group tracked as UNC6780, or TeamPCP, has been targeting open-source platforms including PyPI, npm, and Docker Hub since March 2026. According to Google, this group compromised developer accounts, inserted malicious code into legitimate software projects, and even designed malware specifically to interact with AI coding assistants. In some cases, malicious instructions were hidden inside project files so that an AI coding tool could unknowingly execute attacker-controlled commands, essentially weaponising the developer's own trusted AI assistant against them.

This creates a newer, less obvious supply-chain risk: a developer might reasonably trust an AI assistant to inspect or install a software component, without ever realising that component was specifically designed to manipulate the AI tool itself. Google had already flagged this trajectory in May, when it identified a threat actor using a zero-day exploit the company believed had been developed with AI assistance, an early signal that AI's role in cyberattacks was moving well past simple productivity gains.

LLMJacking: Stealing Someone Else's AI Bill

Another growing problem Google identified is "LLMJacking", attackers stealing credentials or compromising an organisation's cloud environment specifically to use expensive AI computing resources without paying for them themselves. GTIG found growing demand on criminal forums for stolen Gemini and Claude credentials, as well as accounts linked to autonomous coding tools, alongside malware specifically designed to hunt for configuration files that may contain AI API keys.

For businesses, the risk here extends well beyond an unexpectedly large cloud bill. Stolen AI credentials can expose proprietary models, internal source code, prompts, or sensitive corporate data that was never meant to leave the organisation.

Why Speed Is the Real Problem for Defenders

The core challenge facing security teams isn't that AI has replaced human hackers, it's that AI now lets attackers research targets, write convincing messages, modify malicious code, and troubleshoot failures far faster than before. The gap between an attacker spotting an opportunity and actually exploiting it is shrinking, giving defenders considerably less time to detect and respond to an intrusion before real damage is done.

What This Means for You

Treat AI and cloud account credentials with the same seriousness as banking passwords: never reuse them across services, and enable multi-factor authentication wherever it's available. Companies should also actively monitor for unusual cloud or AI usage patterns, since a sudden spike can be an early signal of stolen credentials or an attacker quietly using an organisation's own infrastructure against it.

FAQs

Q1. How quickly did the attackers in Google's case study compromise credentials?

Within six hours, they went from initial cloud infrastructure compromise to actively scanning systems and harvesting third-party credentials at scale.

Q2. What makes an AI "agent" different from a normal chatbot interaction?

An agent can pursue a broader goal through multiple connected steps, scanning, analysing, correcting errors, moving to the next target, without needing fresh human instructions at each stage.

Q3. What is LLMJacking?

When attackers steal credentials or compromise a cloud environment specifically to use expensive AI computing resources without paying for them, often reselling stolen AI credentials on criminal forums.

Q4. How are attackers targeting AI tools themselves?

By compromising developer accounts on platforms like PyPI, npm, and Docker Hub, inserting malicious code into software projects, and hiding instructions that can manipulate AI coding assistants into executing attacker-controlled commands.

in News
Share this post
Archive