Google GTIG: attackers used AI agents to run a credential campaign
Google's threat team saw attackers use agents to shrink a credential-theft campaign to a few hours.
· Google Threat Intelligence Group · Research by Google Threat Intelligence Group (Google)

Google Threat Intelligence Group reports a threat actor who planned, built and ran an agent-enabled mass credential harvesting campaign in under six hours. GTIG says it has not yet seen fully autonomous attack pipelines in the wild.
01What happened
Google Threat Intelligence Group (GTIG) published its AI Threat Tracker report on September 9, 2026. In one case, an actor who had compromised a cloud resource used AI agents to plan, build and run a mass credential harvesting campaign in under six hours, with a dashboard managing more than 23,800 harvested secrets, including API keys for cloud and AI services.
02How it works
GTIG describes attackers using AI to cut the human delay between steps of an operation, which compresses the time defenders have to respond. The report also covers model distillation campaigns, some exceeding 100 million prompts, and AI-assisted n-day exploit development about one month after a vendor patch. Named actors include UNC6780 (TeamPCP), UNC6240 (ShinyHunters) and several state-backed groups.
03Who is affected
Organizations whose developer credentials, cloud keys and AI platform accounts are exposed. GTIG states it has not yet observed threat actors deploying fully autonomous pipelines against targets in the wild.
04What to do
GTIG advises protecting GitHub tokens and AI platform credentials, watching for malicious workspace hooks in .claude/, .vscode/ and .cursor/ directories, hardening CI/CD with signed build attestations and limiting cloud IAM permissions.
Sources 2 links, all fetched
- 1cloud.google.comGTIG Report
- 2cyberinsider.comCyberInsider Coverage