Google warns cybercriminals are moving toward agentic attacks
Google Threat Intelligence Group’s Q2 2026 AI Threat Tracker describes a move from isolated prompting to agentic AI systems that can coordinate parts of cyber operations. Attackers are using AI for reconnaissance, vulnerability research, credential harvesting, malware development and post-exploitation, reducing the delay between human direction and operational execution.
Mandiant observed a cloud compromise in which a threat actor used an AI coding chatbot and autonomous agents to plan, build and execute a mass credential harvesting campaign in less than six hours. Another multi-agent framework conducted vulnerability scanning, handled errors, rotated IP addresses and managed credential harvesting from compromised cloud infrastructure. A separate framework called Recon organized and validated more than 23,800 secrets, including API keys tied to cloud and AI services.
GTIG also documented activity involving financially motivated criminals and state-sponsored groups linked to China, Russia, Iran and North Korea. Targets included proprietary AI assets such as models, prompts, source code and research, with one healthcare compromise involving stolen corporate data, drug research and a proprietary AI model. Underground demand for Claude and Gemini accounts is rising, and average marketplace prices for these accounts more than doubled in 2026.
Google said it has not observed fully autonomous exploitation pipelines in the wild, but AI is accelerating the conversion of public vulnerability disclosures and delayed patching into functional exploit code. GTIG recommends continuous monitoring, threat intelligence and stronger safeguards around both AI tools and the infrastructure that supports them.