Hackers Use Autonomous AI Agents to Launch Mass Credential Theft Attacks in Under 6 Hours
Attackers are using AI tools to break into cloud accounts and steal passwords at breakneck speed, launching full credential-theft campaigns in under six hours. Google Cloud spotted this new wave of automated attacks, where AI writes the code and automates the theft for them.
- Report priority
- High
What is known
- Attackers first break into a company's cloud account.
- Then they use an AI coding chatbot to write scripts that scan for weak passwords and security gaps.
- The AI handles fixing errors and automates the password theft itself.
- This lets attackers steal thousands of third-party credentials in just hours, without needing a big team or manual work.
What to do
Check your cloud provider's security logs for unusual login attempts or unauthorized access. If you see suspicious activity, assume your credentials may have been stolen.
If you suspect your cloud account was compromised, immediately reset all passwords and enable multi-factor authentication (MFA). Contact your cloud provider's support team to review security logs and block any stolen credentials. Monitor for unusual activity in your accounts and consider a security audit of your cloud setup.
Reported details
In one case, attackers compromised a cloud account, then used an AI chatbot to build and run a password-stealing script. Within six hours, they stole thousands of credentials from other companies' cloud services, all without human intervention.
A financially motivated threat group exploited compromised cloud environments to deploy autonomous AI agents capable of launching large-scale credential theft campaigns in under six hours. The attackers leveraged AI-driven automation, including AI coding tools and preconfigured instruction files, to scan for vulnerabilities, harvest third-party credentials, and rotate IPs without manual intervention. By operating from a trusted cloud infrastructure, they evaded detection by blending malicious activity with legitimate traffic.
This approach enabled rapid, large-scale credential theft, surpassing traditional stealer malware, which typically relies on victim execution. The technique demonstrates how AI accelerates cybercrime by reducing operational complexity and speeding up post-compromise actions.