Unit 42 responded to an intrusion where a human attacker delegated the entire operation to AI agents.
They breached the enterprise in under 10 hours.
The same work would have taken human operators approximately two weeks.
The attacker told Unit 42 during negotiations that they used frontier AI models and attack-specific agentic frameworks.
Here is what the agents did in sequence:
Breach a public-facing API endpoint and tunnel into the network.
Deploy an automated recon agent to map internal microservices.
Scour code repositories for hard-coded tokens and service passwords.
Infiltrate the secrets management system and harvest root administrative credentials.
Hijack the CI/CD pipeline and exfiltrate cloud access keys.
Turn the victim's own AI endpoints into post-compromise infrastructure.
The attacker used the company's compute power to run further operations.
Fifty-plus MITRE ATT&CK techniques were executed across the full kill chain.
The agents monitored, evaluated, acted, and re-planned in real time.
After achieving the human operator's goals, an agent left the victim an 80-page technical audit detailing dozens of exploited findings.
This was not a zero-day exploit. The techniques were largely familiar.
What changed was the speed at which they were executed and adapted.
Enterprise complexity became the attacker's advantage.
Credentials in code repos became the foothold. CI/CD pipelines became the lateral movement path. AI infrastructure became the command-and-control channel.
The 10-hour timeline breaks the foundational assumption behind most breach detection programs: that human-speed attacker operations give defenders adequate time to detect and contain.
Organizations running 72-hour breach notification frameworks now face compounded regulatory exposure.
Audit your API key management, CI/CD pipeline access controls, and AI tool inventory today.
If your security team cannot detect and contain an attack in under 10 hours, your detection architecture is structurally exposed.
An attacker just used AI agents to breach an enterprise in 10 hours. The work would have taken humans two weeks. Then the agents left behind an 80-page security audit.
AI-Assisted Content — Produced with AI assistance and human editorial review.
Learn more
0 Comments