Google Threat Intelligence Group (GTIG), the threat analysis division of Google, published a report on September 9 regarding the misuse of AI, reporting that AI-powered attacks are becoming faster and larger in scale. The report identifies instances where thousands of credentials were compromised in less than six hours.
John Haltquist, Chief Analyst at GTIG, mentioned that all threat actors are utilizing AI in some form. He pointed out that advanced attackers are shifting from basic prompt usage to agentic AI workflows and AI-driven automation. This reduction in human intervention time has accelerated attacks and shortened the response window for defenders.
Furthermore, GTIG warned of increasing operational risks accompanying the acceleration of software development, noting a rise in attacks targeting software supply chains—including AI coding assistants and open-source software—as well as organizations' proprietary AI models, code, prompts, and research. In response, Google stated that it has adopted a multi-faceted defense strategy, including model safety measures, threat intelligence collection, and red-teaming exercises.
Source:
- 「全ての攻撃者は何らかの形でAIを使用」 6時間で数千件の侵害事例も Google傘下組織が報告 (ITmedia AI+, 2026-09-09)