Eigen RadarAI
Analysis

Google details an agent-enabled credential attack completed in under six hours

Google Threat Intelligence Group reported that attackers compromised a cloud resource, then planned, built and executed an agent-enabled mass credential-harvesting campaign in under six hours. The Hacker News describes the same development as an autonomous, multi-agent attack framework. The compressed timeline shows how sharply the window for defenders to detect and interrupt such operations can narrow.

Artificial Intelligence··Midday
In a bright hardware room, a gloved responder removes a plain security module from an open network cabinet beside a tray of scattered access cards and hardware keys.

From cloud access to campaign in under six hours

Google Threat Intelligence Group reported that in the second quarter of 2026, attackers compromised a cloud resource and then planned, built and executed an agent-enabled mass credential-harvesting campaign in under six hours. The Hacker News describes the same incident as an autonomous, multi-agent attack framework used by a financially motivated group. Both accounts support the same core development: initial access was converted into a broad credential-harvesting operation within hours.[1], [2]

Agents compress the attack sequence

Google's report says attackers are using agent frameworks to manage scanning pipelines, resolve operational errors and execute credential harvesting at scale. In the incident reported by The Hacker News, planning, tool construction and execution all fit into the same short window. The change is not merely faster software: tasks that might normally be separated into distinct stages and human decisions can follow one another inside a single automated workflow.[2], [1]

The defender's intervention window narrows

Google says human-in-the-loop latency is being sharply reduced, compressing the traditional interval in which defenders can respond. The Hacker News also reports attackers targeting proprietary AI models in healthcare, government and media, exfiltrating API credentials and using victims' cloud environments for unauthorised AI workloads. The six-hour case matters because investigation and containment decisions made after cloud access is detected may now be too slow even when they happen on the same day.[2], [1]

References

  1. News sourceThe Hacker NewsGoogle Threat Intelligence describes a multi-agent attack that harvested thousands of credentials in six hours↩1↩2↩3
  2. News sourceGoogle Threat Intelligence GroupGTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI↩1↩2↩3