Google Threat Intelligence Group's report, published 2026-09-08, describes a financially motivated group running a multi-agent artificial-intelligence framework that compromised thousands of credentials in under six hours. The framework did not phish one target at a time. It assigned agents to reconnaissance, credential validation and lateral movement concurrently, the division of labor a human crew would need a shift roster to match. Google's parallel report the same week tracked the same shift across state-linked operators in China, Iran and Russia, moving off single-turn chatbot prompts toward autonomous systems that chain actions without an operator approving each step.
For a bank running MAS Notice 655 or HKMA's TM-G-1 technology risk framework, the six-hour figure is the number that matters, because it sits inside most institutions' detection-to-containment window, not outside it. Credential-stuffing runbooks built around human-paced attack curves assume hours of dwell time before lateral movement; an agent framework compresses that curve and leaves the same alert volume for a SOC team to triage at the same headcount. HKMA's cyber resilience assessment framework asks institutions to test response time against a threat scenario. The scenario on file at most banks still assumes a human on the other end.
The vendor stream this week ran the other direction: Zscaler's Jay Chaudhry called AI a demand tailwind for the industry, and Neo raised $100 million on the premise that AI agents are the next attack surface for enterprises to secure internally. Neither claim addresses Google's finding, which is that agents are already the offense, not a future attack surface to defend. The control that would have changed Google's six-hour timeline is agent-speed detection tuned to machine-paced credential validation, not another dashboard tile counting logins per hour.