AI and cybersecurity
An attacker used AI agents to steal thousands of credentials in under six hours
Google documents a case in which a single attacker used AI to build an automated credential-theft campaign in under six hours. What's new isn't the technique but the speed and scale — and that changes how much time any company has to react.

In 30 seconds
- According to Google, a financially motivated attacker used an AI coding chatbot and AI agents to plan and run a mass credential-theft campaign in under six hours.
- The AI handled scanning, troubleshooting and IP address rotation on its own, without manual intervention.
- The victim and the country are unknown. What matters for an SME is the pace: automated campaigns test stolen credentials far faster than anyone reviews them by hand.
- The defences that work are still the basics: two-factor authentication on email and cloud accounts, and no reused passwords.
Does this affect me?
Yes, although no Spanish victim has been identified. If your company uses cloud email (Microsoft 365, Google Workspace) or management software reachable over the internet, its passwords are exactly the kind of data these campaigns go after. What decides whether it affects you isn't your size, but whether a leaked password is enough to get in.
What happened
On 8 September 2026, the Google Threat Intelligence Group (GTIG) published its report on how attackers are using artificial intelligence. Among the cases it documents, one stands out for what it signals.
According to the report, Mandiant (Google's incident response team) observed an attacker —suspected to be financially motivated— who compromised an organisation's cloud infrastructure and deployed from it an autonomous attack framework built on several AI agents. With an AI coding chatbot, a prompt and a set of instructions for the agents, the attacker planned, built and executed a mass credential-harvesting campaign in under six hours, compromising "thousands of third-party credentials".
What we know
- The timeline: under six hours from planning to execution of the campaign, according to Google.
- The result: thousands of third-party credentials compromised.
- The role of AI: the agents autonomously handled vulnerability scanning, real-time troubleshooting and IP address rotation, "without manual intervention".
- The camouflage: because it operated from the compromised organisation's cloud, the attack traffic came from legitimate IP addresses, which makes it harder to block by reputation.
- Google's response: it says it has disabled the assets associated with this activity and updated its systems to prevent further misuse.
What we don't know yet
The report doesn't identify the compromised organisation, its sector or country, the exact number of credentials, or whom they belonged to. Nor does it attribute the attack to any specific group. Nothing links this case to Spain.
Why it matters
The technique —testing stolen credentials at scale— isn't new. What's new is who can carry it out, and how fast. Google puts it like this: AI allowed this attacker to operate "at a scale and velocity typically associated with larger and more resource-heavy groups".
In other words, what used to take an organised team is now within reach of a single person with the right tools. And when attacking costs less, more people get attacked, with little selection.
What it means for an SME
A 20-person company isn't a hand-picked target. It's one more entry on an automated list. That has two practical consequences:
- Size doesn't protect you. If one of your company's passwords turns up in a leak, an automated campaign can test it within hours, not weeks.
- You won't catch it in time by looking manually. Nobody in an SME reviews login attempts every hour. Protection has to work on its own, before the attempt arrives.
The good news is that AI doesn't change what works. A stolen credential is of little use if the account asks for a second factor, and a password used in only one place doesn't open any other door.
What your company should do this week
- Turn on two-factor authentication (MFA) for company email and admin accounts in Microsoft 365, Google Workspace or whatever management software you use. Start with the accounts that have the most permissions. Our guide to MFA (in Spanish) explains where to begin.
- Get rid of shared or reused passwords. A password repeated across several services turns someone else's data leak into a way into your company. A password manager solves this without friction.
- Review who has access and with what permissions, especially accounts belonging to former employees or suppliers you no longer work with. We cover this in our guide to former employees' access (in Spanish).
- If you use integrations or access keys for cloud services, don't keep them in emails or shared documents: treat them like an administrator password.
Sources
- Google Threat Intelligence Group — «GTIG AI Threat Tracker: From Prompting to Autonomy» (8 September 2026)Primary source
Defentria editorial team. The Defentria team selects cybersecurity news from primary sources (CERTs, official bodies and vendors) and explains what it means for a Spanish SME and what to do about it.
