AgentsSeptember 8, 2026via SiliconAngle

Google says attackers used AI agents to steal credentials in under six hours

Why it matters

Real-world agent exploitation is no longer theoretical: threat actors are assembling autonomous AI frameworks for coordinated attacks at scale. This is the first major documented case of multi-agent compromise, signaling that agent security is now a critical operational concern for every enterprise.

Key signals

  • Multi-agent AI framework used to compromise thousands of credentials
  • Attack completed in under 6 hours
  • Campaign traced to financially motivated threat actor
  • Initial compromise via cloud infrastructure breach
  • Autonomous framework assembled post-breach for lateral movement/data theft
  • Google Threat Intelligence Group / Mandiant investigation
  • Published September 8, 2026

The hook

Under six hours. That's how long attackers used AI agents to steal thousands of credentials — and Google just documented how.

Threat actors used a multi-agent artificial intelligence framework to compromise thousands of credentials in under six hours, Google LLC’s Google Threat Intelligence Group said in a report released today. Mandiant investigators traced the campaign to a suspected financially motivated actor that firs

The week's key stories, every Friday.

For practitioners and enthusiasts — free, in your inbox.

Free forever. No spam.

Google says attackers used AI agents to steal credentials in under six hours | KeyNews.AI