Unit 42 reports that it responded to an incident in which a human attacker used advanced artificial intelligence to autonomously compromise a company’s network. During negotiations, the threat actor told Unit 42 that it had used advanced AI models and agentic AI frameworks designed for attacks. The report attributes the operation to a human attacker using AI to carry out the intrusion.

The operation’s tempo stands out. Unit 42 says the attacker compressed into less than 10 hours a sequence that would normally have taken human operators about two weeks. The intrusion used more than 50 MITRE ATT&CK techniques, according to the investigation. The report therefore describes both an accelerated workflow and a wide set of techniques deployed during the same compromise.

After initial access, agents mapped the company’s internal architecture. Sub-agents searched enterprise code repositories for hard-coded tokens and service passwords. Using exposed tokens, the attacker entered the secrets manager and recovered primary administrator credentials that provided root access. This part of the account follows the path from code repositories to secret storage and then to privileged access.

The attacker also hijacked an enterprise code application through custom workflows to exfiltrate cloud access keys. Branch protections blocked an attempt to insert backdoors into Terraform configurations. That detail shows one point at which an existing control stopped a specific persistence attempt during the reported intrusion.

The stolen cloud keys were used to transform the victim’s AI access points into post-compromise infrastructure. Unit 42 says the agent also left an 80-page technical audit of the organization’s security posture, detailing dozens of exploited points. The report documents not only movement through the company’s systems, but also a detailed record left by the agent after the compromise.

The Unit 42 page records a September 3, 2026 update clarifying that the event was an intrusion rather than a ransomware attack. It records a further update on September 4, 2026 for minor editorial corrections. Those notes define how Unit 42 currently characterizes the incident.

Taken together, the verified account describes a human-led cyber operation in which AI agents handled reconnaissance, repository searches, credential discovery, workflow abuse and technical documentation at unusual speed. The central finding is the combination of autonomous activity inside the network, more than 50 observed MITRE ATT&CK techniques and a compromise completed in a fraction of the time Unit 42 says human operators would normally require.

Official sources

Sources and methodology

  1. Official source: unit42.paloaltonetworks.com Opens an external source