An attacker used artificial intelligence (AI) agents to blast through an enterprise network in less than 10 hours, significantly reducing the typical two-week time span an attack of similar magnitude would have taken.
Researchers from Palo Alto Networks’ Unit 42 responded to the incident, in which a human attacker used frontier AI to breach an enterprise network autonomously as part of a “machine-speed” ransomware attack, according to a report published Sept. 2. During the attack, which took mere hours, the attacker harvested credentials, seized root access, hijacked CI/CD pipelines, and even turned the victim’s own AI infrastructure against it.
“The agents breached the company’s security layers in a methodical manner, each targeting a different layer of defense to achieve a shared goal,” Unit 42 researchers wrote in the report. “The impact was at the scale of a coordinated effort from multiple red teams, which would normally take human operators around two weeks.”
The incident is a stark warning for organizations about the speed at which attackers can orchestrate a team of agents to compromise their networks and assets.
AI-Driven Coordination Makes the Difference
Indeed, AI-assisted attacks are becoming more common, but what made this attack stand out was the operational efficiency the attacker achieved using AI “without the need for a novel zero-day or super elite tradecraft,” the researchers wrote.
“The attacker left tactical execution to AI agents that monitored, evaluated, acted and re-planned in real time, increasing speed throughout the attack chain,” they wrote. The attacker also directed the agent to leave behind a “report” on the organization’s security posture, which came in the form of an 80-page technical audit.
The attack demonstrates an evolution in AI assistance from using it to automate individual tasks such as writing phishing emails, analyzing binaries, and generating scripts, to a group of agents working in a coordinated way alongside a human attacker to achieve a set of malicious goals, observes Rickard Carlsson, CEO of AI security firm Detectify.
“The shift here is orchestration,” he says. “What Unit 42 is describing is a set of specialized agents working in parallel, sharing findings and adapting, while a human sets the objectives and makes the consequential calls.”
In this way, “the attack process has become a workflow,” Carlsson adds.
AI Agents as Special Ops Team
Indeed, the operation appears to have been structured less like a conventional hacker working through a checklist and more like an automated team of specialized operators, with the adversary running the attack using current AI-enabled software development processes, the researchers said.
Some of the processes used by the attacker included LLM calls to multiple frontier AI agents; structured markdown files passed between agents and sessions; and custom scripts that were AI-generated to manage dynamic operations. The agents worked together to process the results of their actions, decide what to do next, and re-plan in real time, the researchers noted.
Malicious activity covered in the 10-hour operational timeline was varied and began with the threat actor breaching a public API endpoint to tunnel into the network and deploy an automated reconnaissance agent to map internal microservices. The adversary also harvested secrets using sub-agents that combed enterprise code repositories, extracting hard-coded tokens and service passwords.
The attacker then used these exposed tokens to infiltrate the secrets management system and obtain master administrative credentials to gain root system access. They also took control of an enterprise code application and exfiltrated cloud access keys. These keys were then used to turn the victim’s AI endpoints into post-compromise infrastructure for future malicious activity, the researchers wrote.
“What’s striking is how ordinary the underlying weaknesses were: an exposed API, hardcoded credentials, tokens opening paths into sensitive systems,” Carlsson observes about the security gaps exploited in the attack. “The agents didn’t discover a new class of vulnerability; they moved through existing exposures faster and more systematically. The intelligence was in the coordination, not the exploitation.”
Match AI’s Pace, Adaptability to Defend
Overall, the attack “exposes how an attacker who understands how to deploy frontier AI agents effectively can dramatically speed up the pace of their attack,” the researchers wrote, and they expect that attackers will increasingly add AI agents to their tool sets. This means that defending against automated agent loops will require “matching the speed and adaptability of AI-driven attacks,” they added.
This will require enterprises “to make security continuous rather than periodic,” Carlsson observes. “Repositories, pipelines, infrastructure-as-code and secrets management all need to be treated as part of the attack surface.”
They also should make credentials short-lived, and inventory AI endpoints and integrations, as well as automate containment “so compromised access can be shut down quickly,” Carlsson adds.
Organizations also should make their security savvy regarding the automation that AI-assisted attacks provide by detecting behavioral loops, according to Unit 42. “Hunt for operational loops including bursty API requests, rapid 401/200 HTTP state shifts, parallel authentications and sudden model usage from unexpected identities,” the researchers advised defenders.

No responses yet