Threat Intelligence

AI-Powered Attackers Are Now Stealing Credentials in Hours, Not Days

The Hacker News · 8 Sept 2026
Key Takeaway Australian small businesses using AI coding tools or cloud-based AI services should tighten credential management and monitor for unusual account activity, since AI-driven attacks can compromise systems far faster than traditional methods.

Google's Threat Intelligence Group has revealed that cybercriminals are increasingly using AI, including autonomous, multi-agent systems, to speed up and scale their attacks. In one case, a financially motivated hacking group used an AI-driven framework to harvest thousands of credentials in less than six hours, a task that would traditionally take much longer to achieve manually.

Attackers are also targeting proprietary AI models used in healthcare, government, and media organisations, stealing API credentials and hijacking victims' cloud environments to run unauthorised AI workloads. Google says a threat actor known as TeamPCP (also called Altered Spider or UNC6780) has been behind a series of large-scale supply chain compromises affecting popular software repositories including PyPI, npm, and Docker Hub. Once inside, the group deploys credential-stealing malware to target AI coding assistants, then sells or uses the stolen data through partnerships with ransomware and extortion groups.

Google's chief analyst warns that as AI is applied 'agentically', meaning attackers can automate entire attack chains, criminals will increasingly outpace the speed at which defenders can respond. The rise of AI-assisted coding tools has also expanded the attack surface, making developers and open-source software supply chains more attractive targets.

Carrying this risk through a supplier? Assessing third-party and supply chain security ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.