/Submit incident
Documented

AI Agents Enable Rapid Credential Theft and Data Extortion in Cyberattacks

September 8, 2026
oecd:2026-09-08-d25eView source ↗

What happened

Google's Threat Intelligence Group reports that threat actors are increasingly using autonomous AI agents to automate cyberattacks, including credential theft, software supply chain compromises, and extortion. These AI-driven attacks, observed globally in 2025-2026, have enabled rapid breaches, theft of proprietary AI data, and large-scale harm to organizations with minimal human involvement.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

OECD AI Incidents Monitor
Primary source
AI Agents Enable Rapid Credential Theft and Data Extortion in Cyberattacks
2026-09-08