AI agents stole thousands of credentials in six hours
Google's Threat Intelligence Group reports that attackers used a multi-agent AI framework to compromise thousands of credentials in under six hours. The autonomous system required minimal human involvement, with troubleshooting and IP rotation running independently while traffic appeared legitimate by exiting through the victim's own addresses.
The report also highlights criminal group UNC6780, which poisoned AI development tools across PyPI, npm and Docker Hub, and deployed credential stealers targeting hidden AI project directories. Google's chief analyst warns that attack speed is the primary concern, with criminals now targeting AI systems themselves as they become embedded in enterprise infrastructure.
