AI

Google Says Hackers Are Moving Toward Agentic AI Attacks — What That Means for Cybersecurity

By Nino Ray Yeh · September 11, 2026 · 5 min read
Google Threat Intelligence diagram showing an automated AI reconnaissance and credential management framework

For much of the generative AI boom, the cybersecurity question has been fairly simple: how much easier can a chatbot make life for a hacker?

Google says that question is starting to change.

In a new threat intelligence report published on September 8, Google Threat Intelligence Group (GTIG) says it has observed attackers moving beyond one-off prompts and AI-assisted coding toward agentic AI workflows that can coordinate multiple stages of an operation with much less human involvement.

The important distinction is not that hackers have suddenly handed the keys to fully autonomous cybercriminal machines. Google explicitly says it has not yet observed threat actors deploying fully autonomous pipelines for zero-day discovery and network intrusion against real-world targets. What it has seen, however, is a meaningful step in that direction: AI being used to remove more of the manual work that traditionally slows an attack down.

A credential-theft campaign built in under six hours

The clearest example in Google’s report came from a financially motivated threat actor that compromised an organisation’s cloud infrastructure and deployed an autonomous multi-agent framework.

According to GTIG, the attacker used an AI coding chatbot, a prompt and a set of agent instructions to plan, build and execute a mass credential-harvesting campaign in less than six hours. The system was able to manage vulnerability scanning, troubleshoot problems as they appeared and rotate IP addresses with limited human intervention.

Google says the campaign compromised thousands of third-party credentials.

That speed matters. Cybersecurity has always been a race between attackers finding an opening and defenders recognising what is happening. If AI agents can automate more of the repetitive work between those two points, the window available to security teams becomes smaller.

This is more than AI writing phishing emails

Generative AI has already been used for reconnaissance, social-engineering lures, malware development and troubleshooting. The newer development is orchestration.

Instead of asking an AI model to produce a single script, an attacker can potentially build a workflow in which different tools and agents scan systems, interpret results, retry failed actions and pass information between stages.

GTIG also discovered an exposed command-and-control server running an automated reconnaissance and credential-management framework known as “Recon.” Google says the system was designed to organise and validate more than 23,800 harvested secrets in real time, including API keys for cloud and AI services.

Separately, Google observed state-linked actors experimenting with AI-assisted exploitation pipelines and using models including Gemini, Claude and Codex for tasks such as writing exploit scripts, creating phishing material and debugging errors.

The AI itself is becoming a target

There is another side to Google’s findings that may prove just as important.

Attackers are not only using AI. They are increasingly trying to steal the infrastructure, credentials and intellectual property behind it.

GTIG says it has investigated theft involving proprietary AI models, source code, prompts and research. It has also observed large-scale model-distillation campaigns against Google’s systems, with some coordinated operations exceeding 100 million prompts.

That puts AI credentials and cloud access alongside passwords and financial data as increasingly valuable targets. An exposed API key can provide access not only to information but also to expensive computing resources that can be hijacked for unauthorised workloads.

The trend echoes recent reporting from other frontier AI companies. The Tech Boom recently covered Anthropic’s disclosures about attempts to extract Claude’s capabilities and the use of AI in cyber operations. Different companies are now describing variations of the same broader problem: powerful AI systems are becoming both tools in cyber operations and valuable assets worth attacking.

AI is removing friction from hacking

It is tempting to frame this as the arrival of autonomous hackers. Google’s own evidence calls for a more careful conclusion.

The more immediate change is that AI can remove friction.

Tasks that once required an attacker to stop, analyse a result, rewrite code or manually move to the next stage can increasingly be chained together. That does not eliminate the need for skilled operators, and it does not mean every cybercriminal suddenly has nation-state capabilities. But it can allow smaller groups to operate faster and at a scale that previously demanded more people and more time.

That is also why defensive AI is advancing so quickly. Google recently introduced Gemini 3.8 Flash Cyber, a specialised model aimed at helping trusted defenders find vulnerabilities and generate patches. The emerging contest is increasingly AI-assisted attackers versus AI-assisted defenders.

What this means for businesses and everyday users

For most people, the response does not require a new category of security product. It makes familiar protections more important because attackers may be able to move through opportunities faster.

Passkeys and phishing-resistant multi-factor authentication can reduce the value of stolen passwords. Prompt software updates reduce the time that known vulnerabilities remain usable. Businesses also have a growing reason to treat AI API keys, cloud credentials, model access and developer tooling as sensitive security assets rather than ordinary software configuration.

Developers may need to be particularly cautious. Google’s report describes attackers targeting open-source packages, AI coding assistants and automated security scanners, including attempts to manipulate AI tools through malicious instructions embedded in code and project files.

The broader lesson is not that AI has made cybersecurity hopeless. It is that the tempo is changing.

Attackers have always automated what they could. Agentic AI gives them a more adaptable form of automation — one that can reason through some problems instead of simply following a fixed script. If that capability continues improving, the advantage will increasingly belong to whichever side can detect, decide and respond fastest.

Sources: Google Threat Intelligence Group, “From Prompting to Autonomy – The Evolution of Adversarial AI,” September 8, 2026; BleepingComputer, September 8, 2026.

Share this story

Topics

More From The Tech Boom

View all

Share with