Google reports a credential-harvesting campaign built in under six hours
An agent-assisted campaign moved from planning to credential theft in hours. Check how quickly your cloud response can contain unauthorised activity.
The cover image is an AI-generated editorial illustration. Screens and documents are illustrative concepts.
Google Threat Intelligence Group’s September report describes an attacker using compromised cloud infrastructure to plan, build and run a credential-harvesting campaign in under six hours. Agent instructions supported scanning, troubleshooting and IP rotation.
That is a concrete example of reduced human involvement, not proof that an entire attack happened without an operator. Nor is it a universal response deadline. It is a reason to examine whether your own procedures can deal with a rapidly developing incident.
Where does your response lose time?
Start with the first signal your team could reasonably detect: an unexpected workload, an unusual identity change or activity inconsistent with an account’s purpose. Follow what happens next.
Who receives the alert outside office hours? What evidence do they need? Can they restrict the affected identity or resource, or must they find someone else with permission?
A technically accurate alert can still arrive too late to be useful if each decision sits in a queue. We recommend measuring the complete response sequence, including handovers and approval, rather than just the time taken to generate a detection.
Containment needs a defined scope
Choose automatic actions with the business impact in mind. Suspending an unexpected workload and disabling a critical production identity are different decisions. Establish the conditions, exceptions and recovery process before relying on automation.
Credential theft also requires more than deleting the attacker’s process. Identify which secrets were accessible, revoke affected credentials and sessions where appropriate, and examine their subsequent use. A successful cleanup of the original resource does not establish that every stolen credential is harmless.
Google’s report is a useful prompt for a cloud-response exercise. Pick a credible scenario, identify the first observable event and trace it through containment. The result should tell you what can happen promptly today and which decisions still need an owner.