Autonomous AI agents used by hackers to harvest cloud credentials and API keys

Cybercriminals are using autonomous AI agents to automate cyberattacks and harvest thousands of credentials in just a few hours. Google Cloud researchers identified a campaign in which attackers used compromised cloud infrastructure to scan for vulnerabilities, collect secrets, troubleshoot errors, and rotate IP addresses with minimal human involvement.

Autonomous AI agents used by hackers to harvest cloud credentials and API keysAutonomous AI agents used by hackers to harvest cloud credentials and API keys

The operation reportedly exposed more than 23,800 secrets, including cloud credentials and AI-service API keys. Stolen credentials can provide access to cloud accounts, code repositories, development systems, and paid AI platforms, increasing the risk of data breaches and supply-chain attacks.

Organizations should protect cloud environments by enforcing least-privilege access, rotating exposed credentials, monitoring unusual activity, securing CI/CD pipelines, and separating development and production systems.

NPAV Endpoint Security help organizations detect suspicious activity, protect endpoints, monitor threats, and respond to evolving AI-powered cyberattacks.