Security / WORLD

Google reports new ways threat actors are using artificial intelligence

Google Threat Intelligence Group said attackers are targeting AI workflows and cloud resources, including a second-quarter 2026 campaign that moved from cloud access to mass credential harvesting in under six hours.

The source does not state the event date; the period shown is the source review period.

Reading sizeSources ↓Share story ↗

Google Threat Intelligence Group published its assessment of adversarial AI activity on 8 September 2026. It said that in the second quarter of 2026 it observed an actor compromise a cloud resource, then plan and execute an agent-enabled mass credential-harvesting campaign in under six hours.

The report also described theft of AI accounts and API credentials, use of enterprise cloud environments for unauthorised computing, and supply-chain attacks involving AI-enabled software tools. Google said the findings draw on its threat intelligence and incident-response visibility; they are not a census of incidents across all sectors.

Data

Timeline

Security development

Security event or institutional action reported by the source.

  1. · Occurred

    Google published a report on AI-enabled threats observed in the second quarter of 2026

    Google Threat Intelligence Group described cloud-resource hijacking for unauthorised AI workloads, account theft and software supply-chain attacks.

Methodology

The event date and description summarise the action reported by the source; no additional measurement or forecast is made.

Updated:

Key figures

Measure reported by the source

Key quantitative figure stated by the source.

Time from cloud compromise to mass campaign
≤6 hours
2026 · Observed
Methodology

Value is reproduced as stated by the source; a qualifier marks an approximate or bounded figure.

Updated:

Structured coverage

Subjects and places

Subject proposals

Taxonomy version: IPTC Media Topics 2026-Q2

Continue reading