Autonomous AI Agents Are Changing the Speed of Cyberattacks: Thousands of Credentials Compromised in Hours

Artificial intelligence is transforming how organizations develop software, analyze information, automate business processes, and operate cloud environments.

But the same capabilities that make AI valuable to businesses are also being adopted by cybercriminals.

Recent threat intelligence has highlighted a significant shift in the way attackers are using AI. Instead of using AI only to generate malicious code or assist with research, threat actors are increasingly giving AI systems operational responsibilities across multiple stages of an attack.

One reported campaign demonstrated how an autonomous multi agent framework was used to harvest thousands of third party credentials in less than six hours after attackers gained access to a cloud environment. The system was able to automate activities such as vulnerability scanning, credential harvesting, troubleshooting, and other attack related tasks with limited human intervention.

This development creates a new challenge for cybersecurity teams.

The question is no longer simply whether attackers are using AI.

The more important question is how organizations can defend against attacks that operate at machine speed.

From AI Assistance to Autonomous Attack Operations

Early discussions around AI enabled cybercrime primarily focused on attackers using generative AI to write phishing emails, generate scripts, analyze vulnerabilities, or improve malware.

That threat is already significant.

Autonomous AI introduces another layer.

An AI agent can potentially coordinate multiple activities, evaluate results, identify failures, adjust its approach, and continue working without requiring an operator to manually direct every step.

In the reported campaign, the attackers provided an AI coding system with instructions and an operational framework. The resulting system was capable of managing parts of the credential harvesting process, including scanning, troubleshooting, and operational adjustments.

This means the advantage for attackers is not necessarily a completely new hacking technique.

The advantage is speed, scale, adaptability, and automation.

Why Six Hours Matters

Traditional cyberattacks often require attackers to spend significant time performing reconnaissance, identifying vulnerable systems, testing credentials, troubleshooting failures, and moving between targets.

Automation has already reduced that time.

AI can reduce it further.

A campaign capable of compromising thousands of credentials within a few hours creates a very different defensive environment.

Security teams may have limited time to:

• Detect the initial compromise
• Identify affected cloud resources
• Disable compromised credentials
• Investigate suspicious activity
• Determine which accounts were accessed
• Contain the attacker
• Rotate secrets
• Protect downstream systems
• Notify affected stakeholders

If attackers can automate their workflow while defenders continue relying primarily on manual investigation, the imbalance becomes increasingly dangerous.

Credentials Are Becoming a Strategic Target

Credentials remain one of the most valuable assets for attackers.

A stolen credential can provide access to:

• Cloud platforms
• Developer environments
• Source code repositories
• CI/CD pipelines
• SaaS applications
• Databases
• APIs
• Internal communication systems
• Security platforms
• AI services

The value of a credential is therefore determined not only by the system it directly accesses, but also by what that identity can reach.

A compromised developer account, for example, could potentially provide access to source code, package repositories, cloud environments, deployment systems, and development secrets.

This is why identity security must be treated as a central component of modern cybersecurity.

AI Is Also Targeting the Developer Ecosystem

The threat does not stop at traditional cloud accounts.

Threat intelligence has identified increasing activity around software repositories, CI/CD systems, developer environments, and AI coding assistants. Related campaigns have targeted ecosystems such as PyPI, npm, and Docker Hub, demonstrating the growing connection between AI enabled attacks and software supply chain security.

Developer environments are particularly attractive because they frequently contain valuable credentials and access tokens.

These may include:

• Cloud credentials
• Repository tokens
• API keys
• Package registry credentials
• CI/CD secrets
• Deployment credentials
• AI service tokens
• Infrastructure configuration

If attackers compromise these environments, they may be able to move from a developer workstation into much larger enterprise systems.

The AI Coding Assistant Security Problem

AI coding assistants are becoming standard productivity tools for developers.

They can generate code, analyze repositories, troubleshoot errors, and interact with development workflows.

However, they also operate within environments containing sensitive information.

This creates a new security question:

What happens when an AI assistant is influenced by an attacker?

Threat actors have increasingly experimented with techniques designed to manipulate AI assisted development environments, including malicious instructions and compromised workspace configurations. Related reporting has identified malicious activity targeting directories and configuration areas used by AI coding assistants and development tools.

Organizations therefore need to treat AI development environments as part of their security boundary.

Non Human Identities Need Stronger Protection

Traditional identity security programs primarily focus on employees and service accounts.

Agentic AI introduces another category of identity.

AI agents may interact with:

• APIs
• Databases
• Cloud services
• Code repositories
• SaaS platforms
• Security systems
• Internal applications

Each agent may require credentials or tokens to perform its assigned tasks.

Organizations need visibility into these non human identities.

Security teams should know:

• Which AI agents exist?
• Who owns them?
• What business purpose do they serve?
• Which systems can they access?
• Which credentials do they use?
• How long should their access remain active?
• What actions have they performed?
• What happens when the agent is compromised?

Without this visibility, organizations can accumulate large numbers of unmanaged machine identities.

Least Privilege Becomes Even More Important

The principle of least privilege becomes critical when defending against autonomous attacks.

If a compromised credential provides broad access, an automated attacker can potentially exploit that access much faster than a human attacker.

Organizations should therefore limit permissions wherever possible.

Important controls include:

• Role based access control
• Attribute based access control
• Just in time access
• Short lived credentials
• Privileged access management
• Strong authentication
• Network segmentation
• API authorization
• Service account governance
• Automated credential rotation

The objective is to reduce the potential impact of a compromised identity.

Multi Factor Authentication Is Necessary but Not Sufficient

Strong authentication remains one of the most important defenses against credential theft.

However, organizations should not assume that MFA alone solves the problem.

Attackers may target sessions, tokens, API credentials, application integrations, service accounts, recovery processes, and other authentication mechanisms.

Security teams should therefore monitor identity behavior after authentication.

Suspicious activity can include:

• New geographic locations
• Unusual login patterns
• Unexpected API usage
• Sudden privilege changes
• New application registrations
• Unusual cloud resource creation
• Abnormal data downloads
• Large numbers of authentication attempts
• Unusual developer activity

Identity security needs to move from authentication only toward continuous verification.

Detection Must Operate at Machine Speed

One of the biggest lessons from autonomous AI attacks is that human speed may not be enough.

Security operations teams should increasingly automate detection and response for high confidence events.

For example, automated controls can:

• Disable compromised credentials
• Revoke suspicious sessions
• Rotate exposed API keys
• Quarantine affected workloads
• Restrict unusual network connections
• Block suspicious automation
• Alert security teams about abnormal AI activity

Automation should not replace human security expertise.

It should give security teams the ability to respond at the same speed as automated threats.

Cloud Security Becomes More Important

The reported campaign also reinforces the importance of protecting cloud environments.

Attackers increasingly view cloud infrastructure as both a target and an operational platform.

Compromised cloud resources may provide access to:

• Compute infrastructure
• Storage
• Databases
• APIs
• Identity systems
• Developer environments
• AI workloads

Organizations should therefore monitor cloud environments for unexpected changes and unusual behavior.

Important signals include:

• New service accounts
• Unexpected workloads
• Unusual API calls
• Sudden resource consumption
• New geographic activity
• Unexpected outbound traffic
• Unauthorized credential creation
• Changes to security policies

Cloud security monitoring should be closely integrated with identity and threat detection programs.

Protecting the Software Supply Chain

The growing use of AI in cyberattacks also increases the importance of software supply chain security.

Organizations depend on thousands of external packages, containers, repositories, APIs, and development services.

A compromised dependency or development environment can provide attackers with access to much larger populations of systems.

Organizations should implement:

• Software Composition Analysis
• Dependency monitoring
• Software Bill of Materials management
• Secure CI/CD pipelines
• Repository security
• Secrets scanning
• Code signing protection
• Artifact integrity controls
• Third party risk assessments
• Continuous vulnerability management

AI security and software supply chain security are increasingly connected.

Proprietary AI Assets Are Also at Risk

Threat actors are not only interested in traditional credentials.

Organizations are investing heavily in proprietary AI models, datasets, prompts, research, source code, and AI infrastructure.

These assets can represent significant intellectual property.

Compromised credentials can potentially provide attackers with access to these resources.

Organizations should therefore protect:

• AI models
• Training datasets
• Model repositories
• AI APIs
• Prompt libraries
• AI development environments
• Research environments
• Model serving infrastructure
• AI cloud workloads

AI security should cover the entire lifecycle rather than focusing only on the model itself.

Industry Impact

Autonomous AI enabled attacks can affect virtually every industry, but some sectors face particularly significant exposure because of their reliance on cloud infrastructure, sensitive data, software development, and digital identities.

Financial Services

Banks, insurance companies, fintech organizations, and payment providers manage highly valuable financial data and operate large cloud and application environments.

COE Security can help financial organizations strengthen identity security, cloud security, API protection, vulnerability management, threat detection, penetration testing, and compliance programs.

Healthcare

Healthcare organizations manage sensitive patient information while increasingly adopting cloud platforms and AI technologies.

Compromised credentials could expose patient information, applications, research data, or operational systems.

COE Security can help healthcare organizations strengthen data protection, AI security, access controls, application security, threat monitoring, and HIPAA aligned security programs.

Retail and E-commerce

Retail organizations operate large customer facing applications, payment environments, APIs, cloud services, and digital supply chains.

COE Security can help secure customer applications, APIs, cloud infrastructure, identities, development environments, and software supply chains.

Manufacturing

Manufacturing organizations increasingly depend on connected applications, cloud platforms, engineering systems, and operational technology.

Compromised developer or cloud credentials could create risks across both enterprise and operational environments.

COE Security can help manufacturers strengthen application security, cloud security, identity protection, penetration testing, and IT and OT security programs.

Government

Government organizations manage sensitive citizen information, critical applications, and public services.

AI enabled attacks against cloud infrastructure and privileged identities could create significant operational and national security risks.

COE Security can help government organizations strengthen identity security, application security, cloud security, continuous monitoring, vulnerability management, and compliance programs.

What Organizations Should Do Now

Organizations should not wait until autonomous AI attacks become more widespread before adapting their defenses.

Security teams should begin with several practical steps.

1. Inventory Machine Identities

Identify AI agents, service accounts, API credentials, automation accounts, and other non human identities.

2. Reduce Credential Lifetime

Use short lived credentials wherever possible and automatically rotate sensitive secrets.

3. Enforce Least Privilege

Limit the systems and data accessible to each identity based on its actual business requirement.

4. Protect Developer Environments

Monitor repositories, CI/CD systems, AI coding assistants, package managers, and developer workstations.

5. Strengthen Cloud Monitoring

Detect unexpected workloads, authentication patterns, API calls, resource creation, and outbound activity.

6. Monitor AI Activity

Establish visibility into AI agents, AI coding assistants, model APIs, and automated workflows.

7. Automate High Confidence Response

Use security automation to revoke credentials, isolate workloads, and contain suspicious activity quickly.

8. Test the Entire Attack Surface

Security assessments should include cloud infrastructure, identities, APIs, AI applications, development environments, software supply chains, and connected enterprise systems.

The New Cybersecurity Race

The cybersecurity industry is entering a period where attackers and defenders will both use AI for automation.

Attackers can use AI to increase speed.

Defenders must use AI to increase visibility and response capability.

This does not mean replacing security professionals with autonomous systems.

It means giving security teams the tools necessary to identify and contain threats before automated attacks can move through the environment.

Organizations that continue relying exclusively on manual investigation and slow remediation processes may find it increasingly difficult to keep pace.

Conclusion

The use of autonomous AI agents to harvest thousands of credentials in a matter of hours represents an important development in the evolution of cyber threats.

The most concerning element is not simply the use of artificial intelligence.

It is the combination of AI, cloud infrastructure, automation, stolen credentials, developer environments, and software supply chains.

When these elements are combined, attackers can potentially compress complex attack workflows into a fraction of the time previously required.

Organizations therefore need to rethink identity security, cloud monitoring, AI governance, software supply chain protection, and incident response.

Strong authentication, least privilege, continuous monitoring, automated response, secure development practices, and proactive security testing will become increasingly important as attackers adopt more autonomous techniques.

The organizations best prepared for this new environment will be those that treat AI security and traditional cybersecurity as connected disciplines rather than separate programs.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services
• Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption.

In addition, COE Security helps organizations prepare for emerging AI enabled cyber threats through AI security assessments, agentic AI security reviews, identity and access management assessments, cloud security assessments, API security testing, secure AI development consulting, software supply chain security assessments, vulnerability management, threat detection, continuous security monitoring, and penetration testing.

For financial services organizations, we help protect cloud identities, financial applications, APIs, developer environments, sensitive credentials, and AI workloads while supporting security and compliance requirements.

For healthcare organizations, we help secure sensitive patient data, healthcare applications, cloud environments, AI systems, and development platforms through security assessments, data governance, monitoring, and compliance focused cybersecurity programs.

For retail and e-commerce organizations, we help protect customer applications, payment environments, APIs, cloud platforms, developer credentials, and software supply chains against rapidly evolving cyber threats.

For manufacturing organizations, we help secure enterprise applications, cloud infrastructure, development environments, connected systems, and IT and OT ecosystems while strengthening identity and access controls.

For government organizations, we help protect sensitive digital services, cloud environments, privileged identities, AI systems, and critical applications through continuous monitoring, security assessments, vulnerability management, and compliance programs.

As AI agents become increasingly capable of performing complex tasks, COE Security helps organizations establish the security controls, monitoring capabilities, governance practices, and testing programs required to adopt AI responsibly while reducing cybersecurity risk.

Follow COE Security on LinkedIn for ongoing insights into AI security, cybersecurity, compliance, emerging threats, secure software development, and responsible AI adoption. Stay updated and cyber safe.

Click to read our LinkedIn feature article