Google observes attackers use multi-agent automation for mass credential theft
Google Threat Intelligence says a financially motivated actor compromised cloud infrastructure and then used a multi-agent framework to plan, build, and execute mass credential harvesting in under six hours. The agents autonomously managed scanning, troubleshooting, and operational tasks, while the campaign compromised thousands of third-party credentials.
0 comments · 0 votes
Sign in to join the discussion →
No comments yet. Start the discussion.
Why it moved the index
The incident shows agentic automation compressing a real credential-theft campaign to hours and operating at large scale after human initiation. Google grounds the finding in incident-response telemetry, but the report does not identify the exact underlying model.
Assessment history
-
R1
Toward 68 · confidence 96
Initial inclusion from newly published primary incident-response evidence with an exact timestamp.
08 Sept 2026
Share this page
-
DoomBench assesses “Google observes attackers use multi-agent automation for mass credential theft” as evidence moving toward doom, with magnitude 68 and confidence 96 out of 100 in the misuse and incidents category.
-
The DoomBench assessment of “Google observes attackers use multi-agent automation for mass credential theft” is based on reporting from Google Threat Intelligence Group and records the editorial rationale, source quality, attribution,...
-
DoomBench summarizes “Google observes attackers use multi-agent automation for mass credential theft” as follows: Google Threat Intelligence says a financially motivated actor compromised cloud infrastructure and then used a multi-agent...
https://www.doombench.com/news/google-observes-attackers-use-multi-agent-automation-for-mass-credential-theft-2026-09-08