Google Threat Intelligence Group (GTIG) said a financially motivated hacking group used an autonomous, multi‑agent AI framework to harvest thousands of cloud and developer credentials across healthcare, government and media organisations in under six hours.
The attack and its scope
The operation was carried out by the threat actor known as TeamPCP – also referenced as Altered Spider and UNC6780. GTIG’s analysis describes the campaign as a large‑scale credential‑harvesting effort that spanned multiple sectors and resulted in the exfiltration of API keys and other developer credentials. The group targeted organisations in three verticals – healthcare, government and media – and used credential stealers named SANDCLOCK and DUSTMAKER to obtain the data.
How the autonomous AI framework worked
According to the source, the attackers leveraged an AI coding chatbot, a prompt and a set of agent instructions to plan, build and execute the mass‑credential harvest. Pre‑configured markdown instruction sets acted as operational playbooks, allowing the AI agents to automate scanning, exploitation and data extraction without human intervention once the campaign launched.
The framework is described as “autonomous” and “multi‑agent”, meaning several AI‑driven bots coordinated their activities – one scanning for vulnerable endpoints, another attempting exploitation, and a third extracting credentials. The entire sequence, from initial reconnaissance to data exfiltration, completed in less than six hours.
Google’s analysis and disclosure timeline
The first public mention of the attack appeared on 8 September 2026 in The Hacker News, which quoted GTIG’s findings. On 14 September 2026 GTIG issued a formal disclosure, reiterating that the campaign was financially motivated and that the attackers had leveraged AI to accelerate their operations.
“Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi‑agent attack framework to carry out a large‑scale credential harvesting campaign within six hours.” – Google Threat Intelligence Group, as reported by The Hacker News
GTIG also noted that the attackers targeted proprietary AI models in the victim environments, co‑opting cloud resources to run unauthorized AI workloads after gaining access.
Implications for defenders
The incident underscores a shift in attacker tactics: AI is no longer a peripheral tool but a core component that can orchestrate complex, time‑critical operations. Organizations that rely on cloud APIs and developer credentials are now exposed to threats that can sweep through multiple accounts in a matter of hours.
Security teams are urged to review credential‑management practices, enforce strict API‑key rotation policies and monitor for anomalous AI‑related workloads in cloud environments. The use of AI‑generated playbooks also raises the bar for detection, as traditional signatures may miss the rapid, automated steps taken by autonomous agents.
What remains unknown
- The exact number of credentials stolen was not disclosed; GTIG only confirmed that the figure reached the “thousands” range.
- Details on the specific victims within each sector have not been made public.
- Whether the group plans to replicate this AI‑driven approach in future campaigns is unclear.
As the threat landscape evolves, the line between human‑directed attacks and fully autonomous AI operations continues to blur. Google’s disclosure provides the first concrete evidence of a large‑scale, fully autonomous credential‑theft campaign, offering a benchmark for future threat‑intel assessments.