Cybersecurity Research

AI-Powered Attacks Are Speeding Up: Google Warns of Autonomous Hacking Campaigns

Key Takeaway Small businesses should treat AI coding tools, cloud credentials, and API keys as high-value assets requiring the same protection as financial data, since attackers are now automating breaches faster than manual defences can respond.

Google Threat Intelligence Group (GTIG) has released new findings showing that cyber criminals and state-linked hackers are moving beyond simply using AI chatbots for basic tasks. They are now building AI-driven systems that can plan, execute, and adapt attacks with minimal human involvement. In one case observed in Q2 2026, attackers compromised a cloud resource and used an AI-enabled system to launch a mass credential harvesting campaign in under six hours, far faster than traditional attacks.

GTIG also identified a group known as UNC6780 using tricks to fool AI coding assistants and automated security scanners, allowing malicious code to slip into open source software supply chains undetected. Separately, attackers are increasingly targeting AI assets directly, including proprietary AI models, source code, and API credentials, as well as hijacking cloud computing resources to run unauthorised AI workloads. This shows that AI systems themselves, not just the data they process, have become valuable targets for theft and extortion.

The report highlights a broader shift toward 'agentic AI', where multi-agent systems can independently manage scanning, fix their own errors, and scale up attacks such as credential theft without constant human direction. GTIG notes that state-sponsored and criminal groups are using AI across the entire attack process, from reconnaissance and crafting phishing lures to disguising malware and troubleshooting after a breach.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Google Threat Intelligence. We link back to every original so you can read it yourself.