Leadership2 publishers3 min readPublished
Attackers went from stolen cloud credentials to mass credential harvest in under six hours
Google's threat intelligence group logged that case in the second quarter of 2026, in the same report that counts distillation runs of more than 100 million prompts against its own generation models. Both started with compromised accounts.
The Board Room · Leadership desk

What happened
- Google also counted distillation campaigns of more than 100 million prompts against its audio, video and image generation models, run through proxy networks on thousands of compromised accounts.
- The NSA, FBI and CISA published an advisory accusing China-based AI labs of industrial-scale distillation against US frontier AI models.
- GTIG tracked a group it calls UNC6780 using several tactics to trick AI coding assistants and large language model security scanners as part of open source supply chain compromises.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint A containment process whose first human approval arrives at the start of the next business day cannot act inside a window that closes in under six hours, so the authority to revoke cloud roles has to sit with the on-call engineer or with automation.
- cost When adversaries hijack enterprise cloud infrastructure to run unauthorized high-performance compute, the victim's account carries the bill for the attacker's inference.
- precedent With three US agencies naming industrial-scale distillation, who holds downstream API access and how partner resale is controlled is now a policy question for enterprises as well as a live issue for the abuse teams at model vendors.
The six-hour case turned on stolen credentials and a set of markdown files. Mandiant's investigators found a financially motivated actor using compromised cloud infrastructure credentials to stand up an autonomous multi-agent attack framework [3]. "Using preconfigured markdown instruction sets as operational playbooks, the threat actor conducted automated scanning and credential harvesting, compromising thousands of third-party credentials," the GTIG researchers said [4]. The agent instructions, they said, "enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute Internet Protocol (IP) rotation logic without manual intervention" [5].
The window from cloud compromise to mass harvest ran under six hours [2]. Approval timing is the constraint: an escalation path whose first human decision to revoke a cloud role lands the next morning finishes after the campaign does.
GTIG says adversaries have moved from basic prompting to agentic workflows and automation, cutting human-in-the-loop latency on the attacker's side and compressing the traditional window for response [1].
The other number in the report is larger and slower. Google counted distillation campaigns involving more than 100 million prompts against its audio, video and image generation models, launched through proxy networks using thousands of compromised account credentials [9]. Divide one by the other: a thousand accounts would mean at least 100,000 prompts each, ten thousand accounts at least 10,000 each [10].
Ismael Valenzuela, VP of labs, threat research, and intelligence at Arctic Wolf, told CSO Online that these campaigns reach companies outside frontier AI: "Businesses not directly associated with frontier AI models may be tempted to disregard these campaigns as irrelevant due to them being a national security issue, but the exposure of model access to customers or partners makes API keys and service accounts valuable targets, with abuse of access to those models appearing as legitimate" [12].
Mandiant's second-quarter extortion work gives the inventory question a shape. Investigators saw data extortion groups steal AI models, skills, prompts, source code and related research [13]. In one breach at a healthcare organization, the attacker took drug research and other corporate data, including a proprietary AI model [14]. In another, attackers compromised an AI media generation company and took proprietary source code, prompts, skills, model scripts and secrets [15].
On direction, the record holds. On frequency, it is one case. Google's own summary and CSO Online's account describe the same intrusion [2][3], and the quarterly report draws on Mandiant incident response engagements, global threat actor tracking and live platform defenses [17]. One case at that speed is a demonstration. The choice it puts in front of a security owner this quarter is narrow: whether model weights, prompt libraries, service accounts and API keys sit on the asset register with a named owner, the way a production database does. GTIG says the activity reached AI labs along with government, military, healthcare and media organizations [18].
What to watch
- Whether GTIG's next quarterly tracker reports the six-hour agentic pattern more than once, which would turn a single case into a rate.
- Whether model providers publish account-level abuse thresholds or restrict resale of API access to customers and partners.
- Follow-through on the NSA, FBI and CISA distillation advisory, including whether specific labs or specific access channels are named.