What happened
Google Threat Intelligence Group (GTIG) reports that adversaries have evolved from basic AI prompting to using agentic AI workflows and automation, reducing human-in-the-loop latency and shrinking defender response windows.
In Q2 2026, GTIG observed a cloud compromise where attackers planned, built, and executed an agent-enabled mass credential harvesting campaign in under six hours.
GTIG tracked UNC6780 using tactics to trick AI coding assistants and LLM security scanners into open source software supply chain compromises.
Adversaries are increasingly targeting AI assets, including proprietary models, source code, API credentials, and cloud environments for unauthorized AI workloads.
Why it matters
The shift to agentic AI means attacks can unfold faster than human defenders can react, compressing the time available for incident response.
Enterprise AI assets—from model weights to compute quotas—are now high-value targets for espionage, extortion, and resource theft, requiring new defense strategies.
AI-assisted coding pipelines expand the attack surface in open source ecosystems, affecting developers and security tools.
Key facts
GTIG observed a cloud compromise leading to a mass credential harvesting campaign in under six hours in Q2 2026.
UNC6780 used tactics to trick AI coding assistants and LLM security scanners.
Threat actors are targeting proprietary AI models, code, prompts, and research across healthcare, government, and media.
Adversaries are stealing developer credentials, purchasing compromised AI platform accounts, and hijacking cloud infrastructure for unauthorized compute.
What to watch next
Further adoption of multi-agent frameworks that autonomously manage scanning, error resolution, and credential harvesting at scale.
Increased targeting of AI-specific infrastructure like MCP servers and model repositories in open source ecosystems.
Potential scaling of information operations campaigns using AI as a force multiplier.
