AI at all levels: the new face of cybercrime

Partager
AI at all levels: the new face of cybercrime
A new generation of cybercriminals is directly targeting AI in the enterprise to accelerate the entire attack cycle.

Extortion, siphoning, chain scams... A new generation of attackers emerges and directly targets the AI infrastructure of companies. The latest Google Threat Intelligence Group report takes a concrete top of the rapidly changing threat landscape. Analysis with John Hultquist, Chief Analyst, Google Threat Intelligence Group. Hot in front!

A new report confirms what cybersecurity experts have known for a long time: cybercriminals are industrializing the use of AI agents to accelerate the entire cycle of attacks. His merit is to drive the nail on companies that would still doubt the matter. But above all, it reveals a new generation of attackers who now directly target the AI infrastructures of companies.

Specifically, the AI Threat Tracker Q3 2026 report, published by Google TIG, gathers information from investigations conducted by Mandiant, abuse analysis carried out by Gemini and information from the clandestine criminal community. And the least we can say is that the face of online crime is changing at an amazing speed.

And for good reason, hackers are no longer content to test agent AI - as some still think - but already use it industrially to conduct ultra-fast and autonomous attacks. In other words, criminals use AI to accelerate the entire cycle of attacks: from the detection of vulnerabilities to automated intrusion into networks.

 John Hultquist, Chief Analyst, Google Threat Intelligence Group, summarizes: "we can now assume that AI is used in virtually all forms of threats and that criminals benefit directly from it".

 Autonomous attacks via Gemini and chain extortion

Let us note a few salient observations made in the report:

-Self-contained attacks: A spy group tried to use Gemini to develop software capable of entering networks completely autonomously. Another attack consisted of running a sophisticated AI network on hacked servers, which made it possible to steal thousands of identifiers in less than six hours.

-IA supply chain compromise: Hacker collectives such as TeamPCP have sabotaged the metadata of open source software packages. As a result, AI-based programming tools have automatically attributed malicious code to some developers.

To get the computing power necessary for AI, they steal it!

-Extortion via data and computing power theft: Hackers are increasingly stealing corporate-owned AI models and then blackmailing them. They also hijacked their victims' cloud systems to exploit heavy GPU computing power for free, running their own AI models protected from security tools.

For John Hultquist, Chief Analyst at the Google Threat Intelligence Group: "the biggest challenge for organizations lies in agent AI, those systems that act autonomously. This allows attackers to act faster and on a larger scale than ever before. Criminals deliberately opt for attacks that simply take place faster than organizations can react.”

And to get the computing power necessary for AI, they steal it! "This shows that hackers use both pirated systems and local models to bypass commercial detection systems," says John Hultquist.

At the same time, "a new generation of attackers is emerging, which directly target the AI infrastructure of companies. The software supply chain is now their main target, but their horizon is soon expanding. "

CTA Image

SAVE THE DATE - October 15, 2026 Hi Site, Grimbergen (Brussels)

Register! - Register Here!

Lire la suite

Interview Jamie Collier, Google Threat Intelligence Group : Comment les cybercriminels s’emparent de l’IA pour défoncer nos protections

Interview Jamie Collier, Google Threat Intelligence Group : Comment les cybercriminels s’emparent de l’IA pour défoncer nos protections

Face à l'automatisation fulgurante des cyberattaques, Jamie Collier, Lead Advisor au sein du Google Threat Intelligence Group (GTIG), analyse les nouvelles menaces qui pèsent sur les entreprises en Belgique et en Europe. Si les acteurs malveillants exploitent désormais des frameworks multi-agents et ciblent l'écosystème IA,

Par Boris Jancen