Evidence over alarm
← Back to the incident library
Malicious useCASE STUDY / Reported by Google / Mandiant

An intruder put AI to work stealing digital keys

Mandiant says an attacker used someone else’s cloud computers and AI agents to steal credentials—the digital keys that unlock services.

Source: Google Threat Intelligence Group / Mandiant
ACTIVITYApril–June 2026; exact dates undisclosed
PUBLICLY DISCLOSEDSep 8, 2026
THE AI’S ROLEPeople set tasks; AI runs steps
THE 10-SECOND TAKEAWAY

Defending cloud access also protects people outside your organization.

HOW IT WORKED

Follow the chain.

An explanation, not a technical reproduction.
Attacker
Compromised cloud
Outside targets
SIMPLIFIED VIEW · 1 / 3
STEP 01

Someone else’s computers

The attacker first took over another organization’s cloud computers, Mandiant reports.

Google Threat Intelligence Group / Mandiant
Move through the story at your own pace.
1 / 3
THINK OF IT THIS WAY

Think of an intruder using someone else's workshop to collect digital keys. This is an illustration, not an additional account of what happened.

An analogy for the mechanism; not an additional claim about the incident.
KEEP THE EVIDENCE IN VIEW

What we know.
What we don’t.

Reported outcomes

Thousands of third-party credentials were compromised. Planning, building and executing the harvesting campaign took under six hours, the investigators report. Google Threat Intelligence Group / Mandiant

Important limits

Credentials are not a count of breached organizations. Subsequent account use and financial losses are unspecified.

The six-hour figure concerns this workflow, not time to compromise any organization.

People still gave the AI its task and instructions; this is not evidence of an entirely human-free attack.

No public actor or victim identity links this case to an existing entry. Its grouping may change if later evidence establishes overlap.

WHY IT MATTERS

The lesson beyond
this one case.

An organization needs to notice when its computing resources are being used against others, as well as protect the permissions attached to its own credentials.

What happened in response? +

Google reports disruption across these agent-related activities; this case's complete outcome remains unspecified. Google Threat Intelligence Group / Mandiant

FROM THE INCIDENT TO THE DEFENSE

What could help
an organization?

Editorial defense mapping: control what runs in your cloud and what an exposed credential can reach.

Cloud

Notice unauthorized cloud activity

Connect workload, sign-in and network events; investigate unfamiliar running programs and unexpected outbound activity. Revoke compromised identities and isolate affected systems.

What this does—and does not—establish

Traffic volume alone is not proof of an attack. Useful detection depends on coverage and the context of legitimate work.

Software

Reduce exposed entry points

Inventory internet-facing applications, investigate suspected flaws, and verify deployed repairs. Review which applications can read sensitive credentials.

What this does—and does not—establish

This is general defensive relevance; the publication does not establish the initial cloud-compromise method or a specific missing patch.

Security operations

Turn an alert into containment

Rehearse how responders connect suspicious events, preserve evidence, and stop unauthorized activity under a clear approval policy.

What this does—and does not—establish

The victim cannot set policies for an attacker's AI. Fast triage still requires validated evidence and authority to act.

Editorial connections to relevant controls, not evidence that a particular technology would have prevented this case. Each guide links to the security guidance behind its recommendations.

Explore the full AI security framework
TRACE IT TO THE SOURCE

Read the evidence.

Explore more original accounts in the source report library ↗.

These are source-reported findings. An independent assessment, when available, is labeled explicitly.

01
GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AIGoogle Threat Intelligence Group / Mandiant · Sep 8, 2026 · provider investigation

Read this case’s update history →

Reviewed Sep 11, 2026 · Editorial methodology · Structured data