Google Details AI-Driven Attack That Stole Thousands of Credentials in Under Six Hours
Google's Threat Intelligence Group disclosed a credential-harvesting operation where attackers compromised cloud infrastructure and deployed a multi-agent AI framework that scanned for vulnerabilities, fixed its own errors, and rotated IP addresses largely without human input. The entire campaign, which compromised thousands of third-party credentials, took less than six hours to execute. Separately, Microsoft found AI-assisted phishing messages reaching click-through rates of 54%, compared to roughly 12% for conventional campaigns.