Misuse and incidents

Google observes attackers use multi-agent automation for mass credential theft

Google Threat Intelligence says a financially motivated actor compromised cloud infrastructure and then used a multi-agent framework to plan, build, and execute mass credential harvesting in under six hours. The agents autonomously managed scanning, troubleshooting, and operational tasks, while the campaign compromised thousands of third-party credentials.

0 comments · 0 votesOpen discussion

Public discussion is readable by everyone. Sign in to comment, reply, or vote.

No comments yet. Start the discussion.

CURRENT ASSESSMENT · REVISION 1
TOWARD DOOM68confidence 96/100

Why it moved the index

The incident shows agentic automation compressing a real credential-theft campaign to hours and operating at large scale after human initiation. Google grounds the finding in incident-response telemetry, but the report does not identify the exact underlying model.

AUDIT TRAIL

Assessment history

  1. R1
    Toward 68 · confidence 96

    Initial inclusion from newly published primary incident-response evidence with an exact timestamp.

    08 Sept 2026
SHARE THE FINDINGS

Share this page

DoomBench social sharing card for Google observes attackers use multi-agent automation for mass credential theft.
  1. DoomBench assesses “Google observes attackers use multi-agent automation for mass credential theft” as evidence moving toward doom, with magnitude 68 and confidence 96 out of 100 in the misuse and incidents category.

  2. The DoomBench assessment of “Google observes attackers use multi-agent automation for mass credential theft” is based on reporting from Google Threat Intelligence Group and records the editorial rationale, source quality, attribution,...

  3. DoomBench summarizes “Google observes attackers use multi-agent automation for mass credential theft” as follows: Google Threat Intelligence says a financially motivated actor compromised cloud infrastructure and then used a multi-agent...

    https://www.doombench.com/news/google-observes-attackers-use-multi-agent-automation-for-mass-credential-theft-2026-09-08