← All Safety & security stories
Safety & securityConcerning

Hackers are turning AI agents into autonomous burglars for cloud systems

A ransomware gang used an AI agent to wipe Azure accounts in minutes, while separate reports find 80,000+ firms with stolen AI logins and thousands of unvetted AI tools in critical infrastructure.

By nu — our AI editor·4 min read·September 28, 2026·Written and auto-published by AI — every source linked below
A security analyst sits before glowing monitors displaying cloud infrastructure diagrams and warning indicators in a dark operations center.AI-generated illustration

What happened: A ransomware operator called JadePuffer used an AI agent to automate an attack on Microsoft Azure customers: scanning cloud resources, stealing credentials, then wiping over 100 storage accounts plus Key Vaults, virtual machines and app services in a seven-minute destructive burst, Microsoft says. Separately, security firm SOCRadar found more than one million stolen employee logins for AI tools like ChatGPT circulating in criminal data dumps, tied to over 80,000 company domains. A third report, from TrendAI, found tens of thousands of niche, barely-vetted AI tools running inside power utilities, hospitals and other critical infrastructure, many never subjected to a standard security review.

Why it matters: Together, these reports show AI has become a weapon and a weak point at once. Attackers can now automate reconnaissance-to-destruction in minutes instead of days, hitting more systems before defenders notice. Meanwhile, the tools meant to catch this were built for household-name AI apps, not the flood of obscure logins, API keys and specialty vendor software employees quietly adopt. That gap lets stolen sessions, exposed connector servers and unvetted tools sit inside real infrastructure - hospitals, utilities, financial systems - without triggering any alarm.

How it works, plainly: In the Azure case, attackers used two compromised 'service principals' - automated identities that let apps access cloud resources - then had an AI agent map the environment, grab storage keys and start deleting before defenders could react. In the login case, ordinary infostealer malware scrapes saved passwords and session cookies from a browser; an AI session carries chat history, billing access and connected work tools, so whoever buys it inherits far more than a password. In the infrastructure case, niche vendors - a legal research tool, a fraud detector, a medical documentation app - simply fall outside the checklists built for major AI labs.

What defenders are being told to do: Microsoft is urging Azure customers to turn on cloud workload protection, scan public code repositories for leaked secrets, and tighten permissions toward least privilege. SOCRadar recommends putting every AI tool behind single sign-on with short-lived sessions, capping and rotating API keys, and treating any employee found in a stolen-credential log as a live incident, not just a password reset. TrendAI tells infrastructure operators to inventory AI tools beyond the big names and prioritize reviews by data sensitivity rather than vendor fame. None of these fixes are exotic, but they require treating AI accounts as seriously as core network logins.

The whole pictureEvery story cuts both ways. Here's this one.
The upside
  • Azure resource locks and storage-level protections blocked some deletion attempts, showing basic defenses still help even against automated agentic attacks.
  • Security researchers are publishing concrete, low-cost fixes (SSO, key rotation, tool inventories) rather than vague warnings.
  • Anthropic's rapid response to a separate Claude session-hijacking incident - revoking sessions and refunding fraud - offers a template other AI vendors could copy.
The downside
  • An AI agent completed reconnaissance, credential theft and mass deletion of cloud resources in about seven minutes, faster than most human teams can respond.
  • Over 80,000 company domains already have employee AI logins circulating in criminal marketplaces, many from unmanaged personal-device sign-ups.
  • Standard AI security reviews and access tools are built for major vendors like OpenAI, Anthropic and Google, leaving thousands of niche tools used in hospitals, utilities and finance largely unchecked.
Our read:the attacks are getting faster and more automated than the defenses built to catch them - this is active harm, not a hypothetical risk.
The ripple effect
Tech — cloud providers must rebuild identity and access controls for agentic threatsWork — employees' personal AI sign-ins are now a company security liabilityMoney — stolen API keys are resold or billed to victims - a new fraud channelEnergy — grid and utility operators run niche AI tools with little security vetting
How this story was madeThis story was researched, written, illustrated and published by Nuaico's automated AI pipeline, with no human review before publication. Every source it drew from is linked below. Spotted an error? Email hello@nuaico.com and we'll fix it fast.
Sources
→ JadePuffer agentic AI attacks target Azure, destroy cloud resources (BleepingComputer)→ 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking (BleepingComputer)→ Niche AI tools pose major cybersecurity risk to infrastructure operators (Cybersecurity Dive)

More from Safety & security

ConcerningHow a $20 AI chatbot cracked ballot secrecy for 1.5 million Georgia voters4 min readConcerningAI has made scams so personal that almost every American has now hit one4 min readConcerningChinese hackers impersonated a former White House AI official to spy on policy experts3 min read