🕒 Created · Updated

Unit 42 Reports Human Ransomware Attacker Used AI Agents to Breach Enterprise Network in Under 10 Hours

Unit 42 incident responders reported that a human ransomware attacker successfully breached an enterprise network in less than 10 hours using frontier AI models and agentic attack frameworks. This intrusion, which would typically take human operators approximately two weeks to complete, was achieved by using AI agents to perform reconnaissance, map internal microservices, and scrape code repositories for hard-coded tokens and service passwords. Specialist pivot agents then validated access to various environments, including cloud, identity, CI/CD, and SaaS systems. The attacker also hijacked CI/CD workflows to steal cloud access keys and utilize the victim's cloud AI services as post-compromise infrastructure. Upon completing the goals, the attacker provided the victim company with an 80-page security audit report detailing dozens of exploited findings. To defend against these machine-speed attacks, security experts suggest deploying automated playbooks to revoke credentials, terminate sessions, and isolate accounts. They also recommend treating AI as core infrastructure by taking inventory of model endpoints and applying rate limits and least-privilege policies.

Sources


Paywall and unreadable sources