{
  "id": 6902077,
  "title": "An Attacker's Multi-Agent Framework Stole Thousands of Credentials in Under Six Hours",
  "url": "https://urgent.news/2026/09/12/an-attackers-multi-agent-framework-stole-thousands-of-credentials-in",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-12T09:21:16.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/aditya_soni_e5b9d5213e544/an-attackers-multi-agent-framework-stole-thousands-of-credentials-in-under-six-hours-4kgh"
  },
  "original_language": "en",
  "account": "A financially motivated attacker deployed a multi-agent framework to steal thousands of credentials in less than six hours, according to Google's Threat Intelligence Group (GTIG). The attack utilized an AI coding chatbot and preconfigured Markdown files as operational playbooks, similar to how legitimate teams use agents with reusable, structured procedures. The attacker gained access to the organization's cloud infrastructure and ran the autonomous system without human intervention, handling vulnerability scanning, credential collection, issue resolution, and IP address rotation. This marks a shift from traditional threat concerns to a more mundane risk where resilience engineering features of agents can be exploited for autonomous attacks. Organizations using agent-accessible credentials should treat these as high-value targets and shift detection focus from IP-based alerts to behavioral signals that don't rely on the request's origin looking suspicious. Specific details about the AI coding chatbot used in the attack remain undisclosed, leaving room for further investigation by other vendors and incident responders.",
  "summary": "A financially motivated attacker ran reconnaissance, exploitation, and cleanup with almost no human in the loop — using the same design patterns you'd use to build a helpful agent. That symmetry is the actual story. What Google's threat researchers found Google's Threat Intelligence Group (GTIG) published its Q3 2026 AI Threat Tracker documenting a mass credential-harvesting campaign carried out…",
  "key_points": [
    "Multi-agent framework stole credentials in under six hours",
    "Attack used AI coding chatbot and preconfigured Markdown files",
    "Organizations must shift detection focus to behavioral signals"
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}