What Google observed
Google Threat Intelligence Group published its latest AI threat tracker on Tuesday under the title From Prompting to Autonomy. Its central case is a single intrusion: a financially motivated attacker who had already compromised an organisation’s cloud infrastructure used an AI coding chatbot, one prompt and a set of agent instructions to plan, build and run a mass credential-harvesting campaign in under six hours. Thousands of third-party credentials were taken.
The detail that matters is what the agent did without being told again. Google says it managed the vulnerability-scanning pipeline, troubleshot its own failures in real time, and rotated IP addresses on its own — and that because it ran inside the victim’s cloud environment, its traffic came from legitimate addresses. The operator’s instructions were preconfigured markdown playbooks, not live commands.
From assistant to operator
Google’s earlier trackers described threat actors using models the way anyone else does: writing phishing text, translating, explaining unfamiliar code. This report describes something different — multi-agent frameworks that coordinate several stages of an intrusion with a human checking in rather than driving.

The group it tracks as UNC6780, also called TeamPCP, went at the tooling rather than the targets: trojanised MCP servers, extraction of OIDC tokens from CI/CD runners, and prompt injection aimed at getting large language model security scanners to pass malicious code. State-linked clusters in China, Iran, Russia and North Korea appear in the report for reconnaissance, lure writing, reverse engineering and infrastructure work.
The market for AI accounts
Google also tracks what stolen model access is worth. It says advertised prices per account more than doubled over 2026, with demand concentrated on Claude and Gemini credentials and on autonomous coding tools such as Cursor Pro and Devin. The Hacker News reported the same shift among the infostealer families feeding that market.
Those families have followed the money. Google names LUMMAC.V2, STEALC.V2, VIDAR and ACRSTEALER as adding file-grabber rules aimed at AI developer configuration — in May 2026 ACRSTEALER was pulling secrets.json from Cline and config.yaml from Continue, files that hold plaintext API keys and custom model endpoints.

What Google says it did
The company says it disabled the accounts and projects tied to the activity it identified, updated Gemini’s classifiers and the model itself to refuse the attack patterns it saw, and in June 2026 brought its first legal action over Gemini misuse, against an operation it calls Outsider Enterprise. It also says it disrupted a China-linked attempt to build an automated penetration-testing framework on Gemini before it was used.
What to watch
Two figures here are worth tracking into the next quarterly edition: whether the six-hour build time falls, and whether the price of a stolen Claude or Gemini account keeps climbing. The first measures how much of an intrusion the tooling can carry. The second measures how many people want to buy it.