-
Hackers used an AI system to steal thousands of passwords in under six hours, Google says.
-
Criminals now let AI tools scan for weak spots, fix errors, and steal logins on their own.
-
Google has not yet seen hackers use AI to fully run an attack from start to finish, without any help from a person.

Cybercriminals no longer just ask AI chatbots for tips. They now let AI agents run whole parts of an attack by themselves. Google Threat Intelligence Group (GTIG) shared this warning in a new report. The team published its findings on September 8.
GTIG says hackers are moving past simple AI prompts. They now build AI systems that can plan and carry out several attack steps on their own. This shift could shrink the time security teams have to catch an attack in progress.
Hackers Build AI Systems that Steal Passwords Fast
One case stood out the most. A hacking group broke into a company’s cloud system first. The group then launched an AI system built from several linked AI agents. According to BleepingComputer, the hackers used an AI coding chatbot along with a written plan.
This setup let the AI scan for weak spots, harvest passwords, fix problems as they come up, and swap IP addresses. The whole operation ran in less than six hours.
The attack stole thousands of passwords that belonged to outside companies. BleepingComputer reports that this shows a new pattern. Hackers now blend basic automation with AI that can adjust itself when something goes wrong. Older attack tools just follow a fixed list of steps.
The use of AI in criminal operations is not without risks for the attackers themselves. In a separate case, researchers found that a criminal carding platform built on AI-generated code was left exposed due to critical vulnerabilities in its implementation. The platform’s AI-generated code contained flaws that allowed researchers to access sensitive internal systems, proving that while AI can accelerate criminal operations, it can also introduce new weaknesses that undermine them
GTIG also found a separate AI hacking system. This one had already gathered more than 23,800 stolen secrets. Those secrets include cloud logins and API keys tied to AI services, according to SiliconANGLE. Both cases point to the same trend. Hackers now trust AI to run tasks that once needed a full team of people.
AI Coding Tools Become a New Hacking Target
Google also tracked a group called UNC6780, also known as TeamPCP. This group goes after software developers, open-source code, and AI coding tools. The Cloud Security Alliance notes that this group has hit package sites like PyPI, npm, and Docker Hub. The group has also tried to steal special login tokens from GitHub Actions.
Google spotted bad files hidden inside folders used by AI coding helpers. These folders include .claude, .cursor, and .vscode. Hackers hide files there to trick AI coding assistants. According to The Register, attackers have also tried a trick called prompt injection. This trick can fool an AI coding tool into doing something it should not do. It can also stop AI security scanners from spotting bad code.
This pattern shows something important. AI now works as both a hacking tool and a hacking target. Developers who use AI coding tools face new risks they did not have before.
Full Robot Hackers have Not Arrived, but they are Close
Google made one thing clear in its report. No group has yet built a fully automatic AI system that finds and uses brand-new software flaws on its own, with zero human help. That kind of attack has not shown up in the real world so far, according to Help Net Security.
Still, the path forward looks clear. Hackers started with simple AI prompts. They moved to AI-assisted tools. Now they use automatic attack chains and linked AI agents that make their own choices. Each step needs less human input than the last.
This does not mean AI has replaced human hackers. It means hackers can now hand off single tasks to AI systems. This cuts down the work a hacker must do by hand. It could also let small hacking groups act like much bigger, more skilled ones, warns TheHackerNews.
Security teams now face a harder problem: speed. AI can scan, fix errors, steal data, and adjust its plan much faster than a person can. This shrinks the window security teams have to spot an attack.
Teams must catch these threats before real damage happens. Companies that rely on AI tools for daily work should watch their systems closely. They should also update any AI coding tools they use right away. Fast detection now matters more than ever, since AI-powered attacks do not wait around.