Google Warns Hackers Are Turning AI Agents Into Attack Tools

Google warns that hackers are using AI agents to automate attack stages, harvest credentials, and accelerate cyberattacks with less human direction.

Sep 9, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Attackers are beginning to use AI agents to complete in hours some malicious tasks that previously required far more manual work.

Google Threat Intelligence Group says attackers are moving beyond using AI to write code or research targets and are instead building agentic systems that can scan infrastructure, troubleshoot failures, manage attack workflows, and harvest credentials with limited human intervention. 

Rather than producing isolated answers to attacker prompts, AI agents are beginning to coordinate parts of the attack process under human direction. Although Google says it has not observed a fully autonomous, end-to-end attack in the wild, the activity documented so far suggests threat actors are moving in that direction.

From malicious prompts to autonomous attack workflows

For years, attackers have used AI much like any other tool: ask it to write malware, find vulnerabilities, craft phishing messages, or troubleshoot code, then use the output themselves.

Google Threat Intelligence Group says that approach is starting to change, with attackers increasingly giving AI agents objectives and access to tools so they can carry out multiple stages of an operation with far less human direction.

The shift is no longer entirely theoretical. Google said its threat researchers observed AI agents being used at different stages of malicious operations during the second quarter of 2026.

In one example, Google said threat actors completed “an agent-enabled mass credential harvesting campaign in under six hours.”

Google describes this as part of a broader progression from simple prompting to AI-assisted automation and, increasingly, agentic operations.

AI is becoming both the weapon and the prize

The report also shines a light on how attackers are compromising legitimate cloud infrastructure not only for the data, but to enroll it as part of their attack kits. 

Google said attackers can compromise legitimate cloud infrastructure and use it to route malicious traffic. This can help conceal malicious activity among normal cloud traffic while sparing attackers from building their own infrastructure.

Advertisement

But that’s not all. Threat actors have expanded what counts as a target by moving beyond infrastructure. Google says ithas investigated extortion cases involving stolen proprietary AI models, source code, prompts, model scripts, research, and other AI assets, showing that AI systems are becoming valuable breach targets in their own right.

The real problem for victims may be speed

The biggest change may not be that AI can perform more hacking tasks, but that it can compress the time between one successful step and the next. That acceleration could give defenders less time to contain an intrusion before attackers steal credentials, expand their access, or compromise additional systems.

For internet users, that can make stolen credentials more dangerous. Stolen data may spend less time sitting unused before automated systems test credentials, sort records, and identify opportunities for follow-on attacks.

For businesses, the risk runs in both directions: Attackers can use AI to accelerate intrusions while also targeting enterprise models, prompts, source code, credentials, and cloud environments as valuable assets.

Organizations cannot prevent every AI-assisted attack, but they can limit how far one compromised identity or cloud account can take an intruder. Identity and access management controls, phishing-resistant multifactor authentication, credential rotation, least-privilege access, and centralized logging can help security teams detect and contain attacks before automated workflows expand the damage.

Read more: A simulated AI-agent attack breached an enterprise network in 10 hours, demonstrating how automated attack chains can shrink defenders’ response windows.

Joseph Ofonagoro

Joseph is a technical writer with about three years of experience creating clear, practical content across consumer technology, startups, tutorials, and cybersecurity. He is also advancing a career in cyber threat intelligence, driven by a strong interest in the responsible use of technology and its role in protecting people, organizations, and digital systems. His passion for cybersecurity grew out of a broader commitment to helping others understand technology safely and effectively. As an undergraduate at the National Open University of Nigeria, he leads a community of technology enthusiasts, guiding beginners, sharing learning resources, and helping students build confidence as they explore careers in tech. Joseph’s writing combines technical curiosity with an accessible, beginner-friendly style. In addition to his editorial work, he periodically shares cybersecurity case studies and research reports on social media, covering threat trends, security lessons, and practical insights for readers interested in cyber awareness and digital safety.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.