AI-Powered Attackers Are Now Stealing Credentials in Hours, Not Days
Google's Threat Intelligence Group has revealed that cybercriminals are increasingly using AI, including autonomous, multi-agent systems, to speed up and scale their attacks. In one case, a financially motivated hacking group used an AI-driven framework to harvest thousands of credentials in less than six hours, a task that would traditionally take much longer to achieve manually.
Attackers are also targeting proprietary AI models used in healthcare, government, and media organisations, stealing API credentials and hijacking victims' cloud environments to run unauthorised AI workloads. Google says a threat actor known as TeamPCP (also called Altered Spider or UNC6780) has been behind a series of large-scale supply chain compromises affecting popular software repositories including PyPI, npm, and Docker Hub. Once inside, the group deploys credential-stealing malware to target AI coding assistants, then sells or uses the stolen data through partnerships with ransomware and extortion groups.
Google's chief analyst warns that as AI is applied 'agentically', meaning attackers can automate entire attack chains, criminals will increasingly outpace the speed at which defenders can respond. The rise of AI-assisted coding tools has also expanded the attack surface, making developers and open-source software supply chains more attractive targets.