Google Warns AI Agent Attacks Put MSPs, Cloud Customers at Risk

Google says autonomous AI agents stole thousands of credentials in hours, raising new cloud, supply chain, and customer security risks for MSPs.

Written By
Michelle Lojo
Michelle Lojo
Sep 10, 2026
3 minute read
Channel Insider content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Hackers are no longer just asking chatbots for malicious scripts; they are putting artificial intelligence in the driver’s seat.

In a threat report released Tuesday, the Google Threat Intelligence Group (GTIG) warned that cybercriminals are moving beyond basic prompting to autonomous, multi-agent frameworks capable of conducting attacks at greater speed and scale.

In one incident tracked during the second quarter of 2026, a financially motivated attacker breached an enterprise cloud environment and deployed an agent-driven operation that planned, constructed, and executed a mass credential-harvesting campaign in under six hours.

The automated system managed its own vulnerability scans, resolved runtime bugs, and rotated IP addresses without manual oversight, harvesting thousands of credentials.

“At this point, we can assume that all threat actors are using AI in some capacity and their operations have benefited,” John Hultquist, chief analyst at GTIG, said in a statement shared with The Hacker News. “[…] Criminals, like the ones who conducted a mass exploitation campaign in just six hours, will gravitate to attacks that are faster than we can respond to.”

For MSPs, MSSPs, cloud consultancies, and other channel partners, that acceleration raises the risk that a compromised privileged account or shared automation tool could expose multiple customer environments before conventional response processes catch up.

AI attacks spread into software supply chains

Threat actors are also targeting the software supply chains supporting enterprise development, particularly as AI coding agents increase reliance on open-source packages. The financially motivated group tracked as UNC6780, or TeamPCP, compromised open-source ecosystems including PyPI, npm, and Docker Hub to deploy its DUSTMAKER malware.

DUSTMAKER extracts OpenID Connect tokens from GitHub Actions runner memory and uses them to publish compromised packages with valid, cryptographically signed SLSA Build Level 3 attestations. Google said packages published with those tokens can pass automated trust checks used by AI coding agents. The malware also hides files in project directories used by coding assistants and development tools, including .cursor, .vscode, and .claude, and plants configurations that direct those tools to run malicious setup commands.

Advertisement

In an adversarial twist, DUSTMAKER incorporates comments referencing nuclear weapons designs and biological toxins at the top of its loader scripts. Google said the offensive text was likely intended to trigger safety refusals in LLM-based security scanners, potentially causing them to skip the malicious code beneath it.

For channel partners supporting software development environments, the technique expands the security review beyond conventional malware scanning. MSPs and security providers may also need to inspect package attestations, CI/CD credentials, and project-level instructions consumed by AI coding tools.

Attackers target AI assets and cloud capacity

Enterprise AI intellectual property has become prime extortion collateral. GTIG observed attackers targeting proprietary AI models, code, prompts, and research in sectors including healthcare, government, and media, while Mandiant investigated several related data-theft extortion cases.

Simultaneously, attackers are pursuing raw processing power. Through “LLMJacking,” adversaries hijack corporate cloud environments to run unauthorized workloads on the victim’s tab. In an April intrusion detailed by GTIG, an intruder used a leaked personal access token to access a victim’s cloud, deploy containers running agent frameworks, and request quota increases for high-performance hardware.

That activity creates another monitoring responsibility for cloud partners, which may be positioned to detect unusual container deployments, quota requests, and computing costs before customers recognize that their infrastructure has been hijacked.

The speed trap of post-compromise security

Security operations centers built to monitor human adversaries face a severe operational mismatch against agent-driven workflows. When threat actors compress reconnaissance, exploitation tooling, and credential harvesting into a sub-six-hour sprint, traditional escalation paths, where an alert sits in a queue waiting for human triage, collapse.

The primary risk for enterprise defenders is not necessarily that autonomous agents will discover entirely new vulnerabilities. Instead, compromised credentials can allow automated systems to scan infrastructure, exploit known weaknesses, and move through cloud environments faster than conventional escalation processes can respond.

For MSPs, MSSPs, and cloud partners, the immediate priority is to isolate customer credentials and tighten privileged-access controls, monitor unusual API activity and computing consumption, review automated quota-increase requests, and inspect AI-tool configuration files within development projects. Partners that manage privileged access across several customers will need faster response procedures and stronger separation between client environments to keep one compromised identity from becoming a route into multiple organizations.

Advertisement

Read more: AI security risks are pushing MSPs to strengthen customer access controls and incident preparation without adding unmanageable complexity to their technology stacks.

Channel Insider Logo

Channel Insider combines news and technology recommendations to keep channel partners, value-added resellers, IT solution providers, MSPs, and SaaS providers informed on the changing IT landscape. These resources provide product comparisons, in-depth analysis of vendors, and interviews with subject matter experts to provide vendors with critical information for their operations.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.