Security

AI Agents Now Automate Credential Theft in Under Six Hours

Google researchers document how autonomous software frameworks are coordinating multi-stage cyberattacks without human intervention.

Omega Editorial· September 9, 2026· 3 min read

AI-powered credential harvesting reaches industrial scale

Cybercriminals are deploying autonomous AI agents to orchestrate credential theft operations that previously required extensive manual coordination. Google's Threat Intelligence Group documented a financially motivated attacker who used an AI coding chatbot and a multi-agent framework to plan, build, and execute a mass credential harvesting campaign in less than six hours, according to findings first reported by Biometric Update.

The operation compromised thousands of third-party credentials by leveraging AI to manage vulnerability scanning, credential collection, technical troubleshooting, and IP address rotation without any manual intervention.

How the autonomous attack unfolded

Mandiant researchers observed the attacker deploy the multi-agent framework after gaining initial access to an organization's cloud infrastructure. Operating from within the victim's environment allowed the attacker to send requests from legitimate IP addresses, evading basic security controls.

The cybercriminal created the framework using an AI coding chatbot, a prompt, and agent instructions stored in preconfigured Markdown files. These files functioned as operational playbooks, directing different agents to execute specific campaign phases. The resulting system managed the entire attack pipeline autonomously, from scanning to credential extraction.

In a separate discovery, Google's team found an exposed command-and-control server hosting an automated reconnaissance and credential management system. The server contained more than 23,800 secrets, including API keys for cloud platforms and AI services. Researchers were able to build a functioning dashboard from the exposed directory to visualize how the system organized and managed harvested credentials in real time.

The expanding market for AI credentials

Google describes this approach as a fundamental shift beyond conventional infostealers that passively search infected endpoints. Autonomous agents now actively identify vulnerabilities, scan infrastructure, conduct targeted exploitation, and feed harvested credentials into centralized management systems.

The underground market for AI-related access expanded significantly during 2026, according to Google's Threat Intelligence Group. The average advertised price per account more than doubled during the year as both buyer demand and seller supply increased.

The financial stakes are substantial. AI research organization METR reported that an attacker who discovered an exposed agent dashboard and extracted a model provider API key consumed approximately $600,000 worth of model credits over three weeks.

Why it matters

The shift from human-operated to agent-orchestrated attacks fundamentally changes the identity governance challenge facing organizations. As autonomous software agents increasingly authenticate to cloud services using API keys and tokens rather than passwords, the volume and velocity of machine-to-machine authentication events is outpacing traditional security controls. Organizations that focus exclusively on human identity verification while treating API keys as static secrets are missing the larger attack surface.

Machine identity emerges as the critical gap

Strong authentication for human users remains essential, but Google's findings indicate the larger challenge now centers on machine identity. Organizations must authenticate and govern the API keys, tokens, and credentials used by applications, cloud workloads, and autonomous AI agents.

NIST has warned that static API keys and long-lived bearer tokens do not prove the identity of the person or service presenting them. The agency recommends that credentials used by AI agents should be dynamically issued, restricted to the intended recipient, and valid only for the required period.

These findings were first reported by Biometric Update, based on research from Google's Threat Intelligence Group and Mandiant.

#credential theft#ai agents#api security#machine identity#cybersecurity#google threat intelligence

This is an original analysis by the Omega editorial team. Source reporting: Automation Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

Cisco Adds Agentic AI Failure Category to Security Framework

The company's updated taxonomy addresses autonomous systems that exceed authority, drift from goals, or game success metrics without external attacks.

Via AI Watch · Sep 9, 2026
Security· 3 min read

Infostealer Logs Expose Replayable AI Session Tokens and API Keys

Cybercriminals are harvesting authentication credentials from compromised systems to hijack accounts for Claude, ChatGPT, Gemini, and other LLM services.

Via AI Watch · Sep 9, 2026
Security· 4 min read

Cymphony raises $30M to secure AI agents with enterprise access

Sequoia Capital backs startup addressing security gaps as autonomous AI systems gain access to sensitive corporate data and systems.

Via AI Watch · Sep 9, 2026