Google Threat Intelligence Group reported that AI is rapidly lowering the cost and time needed for credential theft, including a campaign that compromised thousands of third-party credentials in under six hours. The article warns that strong password hygiene is not enough on its own and emphasizes device trust as a critical defense against AI-enabled abuse of stolen credentials. #GoogleThreatIntelligenceGroup #SpecopsPasswordAuditor #SpecopsDeviceTrust #Unit42 #Microsoft
Keypoints
- GTIG described an AI-driven credential-harvesting campaign that finished in less than six hours.
- The operation compromised thousands of third-party credentials with minimal human effort.
- AI is improving phishing and other credential theft tactics by making them faster and easier to scale.
- Stolen credentials remain a major breach vector, even when authentication succeeds.
- Specops recommends adding device trust to password hygiene and authentication checks.