AI Agents Enable Rapid Credential Theft and Data Extortion in Cyberattacks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Google's Threat Intelligence Group reports that threat actors are increasingly using autonomous AI agents to automate cyberattacks, including credential theft, software supply chain compromises, and extortion. These AI-driven attacks, observed globally in 2025-2026, have enabled rapid breaches, theft of proprietary AI data, and large-scale harm to organizations with minimal human involvement.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions AI agents automating parts of cyberattacks, including credential theft, which is a direct harm to individuals and organizations. The AI systems are used maliciously, leading to realized harm such as theft and security breaches. This fits the definition of an AI Incident because the AI system's use has directly led to harm (violation of rights and harm to property).[AI generated]
AI principles
AccountabilityRobustness & digital security

Industries
Digital security

Affected stakeholders
Business

Harm types
Economic/Property

Business function:
ICT management and information security

AI system task:
Goal-driven organisation


Articles about this incident or hazard