Hackers are turning AI agents into autonomous burglars for cloud systems
A ransomware gang used an AI agent to wipe Azure accounts in minutes, while separate reports find 80,000+ firms with stolen AI logins and thousands of unvetted AI tools in critical infrastructure.
What happened: A ransomware operator called JadePuffer used an AI agent to automate an attack on Microsoft Azure customers: scanning cloud resources, stealing credentials, then wiping over 100 storage accounts plus Key Vaults, virtual machines and app services in a seven-minute destructive burst, Microsoft says. Separately, security firm SOCRadar found more than one million stolen employee logins for AI tools like ChatGPT circulating in criminal data dumps, tied to over 80,000 company domains. A third report, from TrendAI, found tens of thousands of niche, barely-vetted AI tools running inside power utilities, hospitals and other critical infrastructure, many never subjected to a standard security review.
Why it matters: Together, these reports show AI has become a weapon and a weak point at once. Attackers can now automate reconnaissance-to-destruction in minutes instead of days, hitting more systems before defenders notice. Meanwhile, the tools meant to catch this were built for household-name AI apps, not the flood of obscure logins, API keys and specialty vendor software employees quietly adopt. That gap lets stolen sessions, exposed connector servers and unvetted tools sit inside real infrastructure - hospitals, utilities, financial systems - without triggering any alarm.
How it works, plainly: In the Azure case, attackers used two compromised 'service principals' - automated identities that let apps access cloud resources - then had an AI agent map the environment, grab storage keys and start deleting before defenders could react. In the login case, ordinary infostealer malware scrapes saved passwords and session cookies from a browser; an AI session carries chat history, billing access and connected work tools, so whoever buys it inherits far more than a password. In the infrastructure case, niche vendors - a legal research tool, a fraud detector, a medical documentation app - simply fall outside the checklists built for major AI labs.
What defenders are being told to do: Microsoft is urging Azure customers to turn on cloud workload protection, scan public code repositories for leaked secrets, and tighten permissions toward least privilege. SOCRadar recommends putting every AI tool behind single sign-on with short-lived sessions, capping and rotating API keys, and treating any employee found in a stolen-credential log as a live incident, not just a password reset. TrendAI tells infrastructure operators to inventory AI tools beyond the big names and prioritize reviews by data sensitivity rather than vendor fame. None of these fixes are exotic, but they require treating AI accounts as seriously as core network logins.
