In a disturbing trend, recent attacks have demonstrated how easily artificial intelligence (AI) can be leveraged by cybercriminals to compromise user credentials at scale. What’s more, these AI-powered assaults are not only more efficient but also more convincing than traditional phishing campaigns. For security teams, this raises serious concerns about the trustworthiness of their authentication processes and the potential for compromised credentials to grant attackers access to internal networks.
One notable example of an AI-powered attack was detailed by Google Threat Intelligence Group (GTIG) on September 8. In a credential-harvesting campaign, a threat actor used an AI-driven multi-agent framework to compromise thousands of third-party credentials in less than six hours. This operation involved the AI managing parts of the vulnerability-scanning pipeline, troubleshooting problems as they arose, and rotating IP addresses with minimal human intervention. What’s striking is how quickly and effectively this attack was carried out, underscoring the potential for AI to accelerate cybercrime.
The use of AI in these attacks isn’t about introducing new techniques; rather, it’s about making established ones more efficient. By automating parts of the phishing playbook, attackers can generate targeted messages more quickly, adapt them for different languages or industries, and create variations without writing each one from scratch. This improvement in success rates allows attackers to acquire a larger number of credentials, increasing their chances of finding valuable accounts.
AI-assisted phishing campaigns have been shown to achieve click-through rates as high as 54%, compared with around 12% for traditional campaigns. Microsoft reported this phenomenon in April, highlighting the changing economics of phishing. When attackers can make the same campaign more convincing without spending proportionally more time creating it, they gain a significant advantage.
The impact of compromised credentials cannot be overstated. According to Verizon’s Data Breach Investigation Report, stolen credentials are involved in 44.7% of breaches. This suggests that even if organizations have robust authentication processes in place, the vulnerabilities introduced by weak and reused passwords can still compromise security.
Given these risks, it’s crucial for security teams to prioritize visibility when it comes to credential exposure. Before they can reduce this risk, they need to know where the weaknesses are in their own environment. Specops Password Auditor is a tool that performs a read-only scan of Active Directory to identify password-related vulnerabilities and highlight issues with users and password policies.
While successful authentication isn’t necessarily trustworthy, these attacks demonstrate how easily valid identities can be abused by attackers. The resulting access can lead to malicious activity that may not trigger any alarms for defenders. It’s essential for security teams to differentiate between authentication and trust, recognizing that a correct password doesn’t guarantee the intent behind it is legitimate.
Ultimately, AI-powered attacks are a wake-up call for organizations to review their current authentication processes and ensure they’re robust enough to withstand these new challenges. By understanding how AI can be used to compromise user credentials and prioritizing credential visibility, security teams can better protect against these threats and maintain the trustworthiness of their internal networks.
Source: Bleeping Computer — 2026-09-17