Google Says AI Attackers Stole Thousands of Credentials in Under 6 Hours
Updated
Updated · Fox News · Sep 22
Google Says AI Attackers Stole Thousands of Credentials in Under 6 Hours
3 articles · Updated · Fox News · Sep 22
Summary
Google’s Threat Intelligence Group said attackers are shifting from simple AI prompts to agentic workflows, including one financially motivated intruder that planned, built and ran a mass credential-harvesting campaign in under six hours.
Thousands of third-party credentials were compromised after the attacker breached a company’s cloud environment and used an AI coding chatbot to scan for weaknesses, troubleshoot issues and automate parts of the operation.
Google said it has also seen malware use AI directly: PROMPTFLUX rewrote its own code to evade signatures, PROMPTSTEAL queried a language model during live attacks in Ukraine, and PROMPTSPY used AI to interpret Android screens.
The company has not yet seen fully autonomous exploit pipelines in the wild, but said AI is steadily reducing the human effort needed to run attacks.
That trend lands on top of a huge cybercrime base: AV-TEST logs more than 450,000 new malicious programs or unwanted apps daily, while the FBI said Americans reported nearly $21 billion in cyber-enabled losses in 2025.