Executive summary
Palo Alto Networks' Unit 42 investigated a real ransomware intrusion in which a human attacker used multiple frontier AI agents to perform specialized tasks across an enterprise network. The agents helped compress more than 50 attack techniques into under 10 hours—work the researchers estimate would normally take human operators roughly two weeks.
What happened
The attacker first breached a public-facing API endpoint, then deployed an automated reconnaissance agent to map internal microservices. Specialized sub-agents searched code repositories for exposed tokens and passwords, reached the organization's secrets-management system and obtained administrative credentials.
Other agents validated access across cloud, identity, CI/CD, container and software-as-a-service environments. They hijacked development workflows to exfiltrate cloud keys and used the victim's own AI services as post-compromise infrastructure. A protected branch blocked an attempted Terraform backdoor.
After the intrusion, an agent produced an 80-page technical audit of the weaknesses used in the attack.
What this does—and doesn’t—show
A human selected the objective and made consequential decisions; Unit 42 describes the agents as executing delegated tactical work, not independently choosing a victim or ransom campaign. The attack used familiar techniques rather than zero-days and depended on serious security weaknesses such as exposed credentials. The specific models, frameworks and victim remain undisclosed, and the attacker's claim of using frontier models was corroborated by technical indicators rather than independently reproduced.