Executive summary
Google’s September 8 threat report describes a human-directed attack using multiple AI agents. After compromising cloud infrastructure, the attacker built and ran a campaign that stole thousands of third-party credentials in under six hours.
<6 hTo plan, build and execute the campaign
1,000sThird-party credentials compromised
Q2 2026Observed activity; disclosed September 8
What happened
Mandiant investigators found agents handling scanning and troubleshooting without manual intervention. The attacker supplied the objective and instructions.
This is a newly published account of activity from Q2 2026, not an attack that happened this week.
The 2050 museum label
The criminal enterprise finally solved its staffing problem.
What this does—and doesn’t—show
Human-directed crime, not spontaneous AI rebellion. Google has not observed fully autonomous zero-day discovery and intrusion pipelines used by threat actors against real targets. Its report describes particular investigations, not how common this is across all cybercrime.