AI agents breach an enterprise network
Unit 42 reports coordinated AI agents stealing enterprise secrets and commandeering cloud services.
- Reported date
- Sep 2, 2026
- Target
- Unnamed enterprise
- Agent type
- Multiple AI agents
- Agent role
- Used by the attacker
The exact incident date was not established. This entry is dated by its source report.
Unit 42 disclosed an intrusion against an unnamed enterprise on September 2, 2026. The investigation describes a human attacker delegating work to AI agents, which advanced through the victim's environment in less than ten hours. The incident date was not disclosed; September 2 is the publication date.
After initial access, agents mapped internal services, searched software repositories for secrets, and obtained administrative credentials. They also acquired cloud access keys and commandeered the company's AI infrastructure. An attempt to insert infrastructure backdoors was stopped by repository protections, limiting one part of the attack.
Investigators observed parallel model calls and information exchanged between agents. The attacker also described its AI use during negotiations, so that statement forms part of the evidence alongside the observations.
Unit 42 characterized the event as a ransom-related intrusion and subsequently corrected references to ransomware. The account does not identify the model providers or establish that files were encrypted.
Evidence in the reporting
- Incident evidence
- harvesting master administrative credentials
- Agent involvement
- LLM calls to multiple frontier AI agents in parallel