Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Cyber Threats » Hackers Use AI Agents to Steal Thousands of Credentials in Under Six Hours, Google Says

Hackers Use AI Agents to Steal Thousands of Credentials in Under Six Hours, Google Says

Last updated:September 12, 2026
Human Written
  • Hackers used an AI system to steal thousands of passwords in under six hours, Google says.

  • Criminals now let AI tools scan for weak spots, fix errors, and steal logins on their own.

  • Google has not yet seen hackers use AI to fully run an attack from start to finish, without any help from a person.

Hackers Use AI Agents to Steal Thousands of Passwords in Under Six Hours, Google Says

Cybercriminals no longer just ask AI chatbots for tips. They now let AI agents run whole parts of an attack by themselves. Google Threat Intelligence Group (GTIG) shared this warning in a new report. The team published its findings on September 8.

GTIG says hackers are moving past simple AI prompts. They now build AI systems that can plan and carry out several attack steps on their own. This shift could shrink the time security teams have to catch an attack in progress.

Hackers Build AI Systems that Steal Passwords Fast

One case stood out the most. A hacking group broke into a company’s cloud system first. The group then launched an AI system built from several linked AI agents. According to BleepingComputer, the hackers used an AI coding chatbot along with a written plan.

This setup let the AI scan for weak spots, harvest passwords, fix problems as they come up, and swap IP addresses. The whole operation ran in less than six hours.

The attack stole thousands of passwords that belonged to outside companies. BleepingComputer reports that this shows a new pattern. Hackers now blend basic automation with AI that can adjust itself when something goes wrong. Older attack tools just follow a fixed list of steps.

The use of AI in criminal operations is not without risks for the attackers themselves. In a separate case, researchers found that a criminal carding platform built on AI-generated code was left exposed due to critical vulnerabilities in its implementation. The platform’s AI-generated code contained flaws that allowed researchers to access sensitive internal systems, proving that while AI can accelerate criminal operations, it can also introduce new weaknesses that undermine them

GTIG also found a separate AI hacking system. This one had already gathered more than 23,800 stolen secrets. Those secrets include cloud logins and API keys tied to AI services, according to SiliconANGLE. Both cases point to the same trend. Hackers now trust AI to run tasks that once needed a full team of people.

AI Coding Tools Become a New Hacking Target

Google also tracked a group called UNC6780, also known as TeamPCP. This group goes after software developers, open-source code, and AI coding tools. The Cloud Security Alliance notes that this group has hit package sites like PyPI, npm, and Docker Hub. The group has also tried to steal special login tokens from GitHub Actions.

Google spotted bad files hidden inside folders used by AI coding helpers. These folders include .claude, .cursor, and .vscode. Hackers hide files there to trick AI coding assistants. According to The Register, attackers have also tried a trick called prompt injection. This trick can fool an AI coding tool into doing something it should not do. It can also stop AI security scanners from spotting bad code.

This pattern shows something important. AI now works as both a hacking tool and a hacking target. Developers who use AI coding tools face new risks they did not have before.

Full Robot Hackers have Not Arrived, but they are Close

Google made one thing clear in its report. No group has yet built a fully automatic AI system that finds and uses brand-new software flaws on its own, with zero human help. That kind of attack has not shown up in the real world so far, according to Help Net Security.

Still, the path forward looks clear. Hackers started with simple AI prompts. They moved to AI-assisted tools. Now they use automatic attack chains and linked AI agents that make their own choices. Each step needs less human input than the last.

This does not mean AI has replaced human hackers. It means hackers can now hand off single tasks to AI systems. This cuts down the work a hacker must do by hand. It could also let small hacking groups act like much bigger, more skilled ones, warns TheHackerNews.

Security teams now face a harder problem: speed. AI can scan, fix errors, steal data, and adjust its plan much faster than a person can. This shrinks the window security teams have to spot an attack.

Teams must catch these threats before real damage happens. Companies that rely on AI tools for daily work should watch their systems closely. They should also update any AI coding tools they use right away. Fast detection now matters more than ever, since AI-powered attacks do not wait around.

Share this article

About the Author

Memchick E

Memchick E

Digital Privacy Journalist

Memchick is a digital privacy journalist who investigates how technology and policy impact personal freedom. Her work explores surveillance capitalism, encryption laws, and the real-world consequences of data leaks. She is driven by a mission to demystify digital rights and empower readers with the knowledge to protect their anonymity online.

View all posts by Memchick E >
Comments (0)

No comments.