A ransomware attacker breached a company network in under 10 hours using AI agents. Unit 42, the incident response arm of Palo Alto Networks, says such intrusions normally take about two weeks. The attacker later told negotiators that AI agents carried out each step. Agents did reconnaissance, then entry came through a public API endpoint. Subagents mapped internal services and scraped code repositories for hard-coded tokens and passwords. Those tokens opened the secret-management system and yielded master administrative credentials. The attacker hijacked build pipelines to steal cloud keys and ran orchestration on the victim's own cloud AI services. An agent then left an 80-page report on the company's security failings. Unit 42 says no zero-day or elite tradecraft was involved. It advises automated playbooks that revoke credentials, kill OAuth sessions, freeze pipelines and isolate cloud accounts.
What changed
Comparable intrusions took human operators around two weeks.
- under 10 hours to breach
- normally about two weeks
- 80-page report left for victim
Sources