Key Facts

Google Threat Intelligence Group says it observed a threat actor compromise cloud resources and then plan, build, and execute an agent-enabled mass credential-harvesting campaign in under six hours during Q2 2026.

Technical Details

Google says the multi-agent workflow autonomously managed scanning pipelines, resolved operational errors, and conducted credential harvesting at scale. Its report also describes adversaries targeting proprietary AI models, source code, prompts, API credentials, and cloud resources.

Impact & Mitigation

Review cloud and developer credential exposure, protect AI development and deployment environments, and monitor for unauthorized AI workloads. Google recommends treating enterprise AI assets, including model weights and compute quotas, as high-value targets.

Sources

By Allan