An attacker used AI agents to build a credential harvest in under six hours

Illustration for the AI agent credential harvesting story

The notable artifact is not the intrusion. It is that the attacker’s tooling built itself an operations dashboard.

What Google observed

Google Threat Intelligence Group described a suspected financially motivated actor who compromised a cloud resource and then planned, built and executed a mass credential harvesting campaign in under six hours.

The framework was assembled from an AI coding chatbot, a prompt and a set of preconfigured markdown instruction sets acting as operational playbooks, which drove the automated scanning and harvesting that followed. The resulting system included a dashboard that organized and validated more than 23,800 harvested secrets in real time, including API keys for cloud and AI services.

Google observed the campaign in the second quarter of 2026.

What changes and what does not

Credential harvesting at scale is old. The compression is new: planning, building and running an operation inside a single working day, with tooling generated on the spot rather than acquired.

The 23,800 figure describes what the dashboard was managing, not a count of breached organizations, and the distinction matters for anyone sizing the incident.

Why the tooling detail is the story

Attackers have always automated. What changed is where the automation comes from. Historically an operation at this scale meant either buying a kit or spending days writing one, and both left traces: a purchase, a reused codebase, a signature that defenders could learn.

Tooling generated on the spot from a prompt and a set of playbooks leaves much less of that. It is bespoke to one intrusion, it does not match anything in a repository of known tools, and it can be rebuilt differently on the next job. The dashboard is the clearest expression of that shift, because building an operator interface used to be the sort of investment only a mature crew made.

What it means for defenders

The durable lesson is about lead time. Defenses calibrated to the assumption that building tooling takes an attacker days or weeks are calibrated to a schedule that no longer holds, and detection windows measured in days are now longer than the entire operation.

The practical implication points at credential hygiene rather than detection speed. Short-lived keys, scoped permissions and automatic rotation reduce what a six-hour harvest is worth, which is a control that does not depend on noticing the intrusion in time.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.