Detect Deepfakesby Resemble AI
Agentic AI attack

AI agents breach an enterprise network

Unit 42 reports coordinated AI agents stealing enterprise secrets and commandeering cloud services.

Reported date
Sep 2, 2026
Target
Unnamed enterprise
Agent type
Multiple AI agents
Agent role
Used by the attacker

The exact incident date was not established. This entry is dated by its source report.

Updated Sep 23, 2026 · 1 min read

Unit 42 disclosed an intrusion against an unnamed enterprise on September 2, 2026. The investigation describes a human attacker delegating work to AI agents, which advanced through the victim's environment in less than ten hours. The incident date was not disclosed; September 2 is the publication date.

After initial access, agents mapped internal services, searched software repositories for secrets, and obtained administrative credentials. They also acquired cloud access keys and commandeered the company's AI infrastructure. An attempt to insert infrastructure backdoors was stopped by repository protections, limiting one part of the attack.

Investigators observed parallel model calls and information exchanged between agents. The attacker also described its AI use during negotiations, so that statement forms part of the evidence alongside the observations.

Unit 42 characterized the event as a ransom-related intrusion and subsequently corrected references to ransomware. The account does not identify the model providers or establish that files were encrypted.

Evidence in the reporting

Incident evidence
harvesting master administrative credentials
Agent involvement
LLM calls to multiple frontier AI agents in parallel

Sources