Google says PRC-linked hackers are combining cyberespionage with AI agents, automating intrusion tasks and completing some campaigns in under six hours. One group has targeted North American academic, medical, and military organizations conducting proprietary AI research. Attackers allegedly install open-source models on compromised cloud systems, avoiding commercial monitoring and safety guardrails.
Hackers working for Chinese intelligence are increasingly targeting American AI research and using AI in their operations, Google said Tuesday.
In its latest quarterly report, Google’s Threat Intelligence Group said that several hacker groups, including both intelligence agencies and cybercrime gangs, have moved from basic AI prompting to using AI agents that automate wide swaths of their intrusion.
The switch means hackers spend drastically less time actively hacking, and in some cases can conduct an entire campaign in less than six hours, the report says.
Google said that one Chinese group in particular, which it has tracked since 2023, has relentlessly focused on academic, medical and military research organizations in North America and has specifically gone after proprietary AI research. Google did not name any of the victims.
FOR SUBSCRIBERS

00:0000:00
03:16
While American intelligence agencies also have powerful cyberespionage capabilities, the U.S. has long accused China of hacking its companies for economic advantage, a tactic Western countries generally say is unacceptable.
Liu Chang, spokesperson for the Chinese Embassy in Washington, broadly denied the claims.
“China opposes hacking activities and fights such activities in accordance with the law. That said, we firmly reject vilification and smears under the pretext of cybersecurity,” he said.
Google said it had observed the hacker group compromising unrelated victims’ cloud networks and installing open-source AI models — a way to query models without leaving a trail via commercial AI products.
John Hultquist, the chief analyst at Google’s Threat Intelligence Group, said that running those models on a hacked third-party system allows hackers to avoid monitoring and bypass guardrails that might stop a more popular commercial chatbot from helping with a hacking campaign.
“They compromise a third party and they put models on that third party. They do that instead of using, say, a commercial option where their activities are observed,” Hultquist told NBC News.
The White House has repeatedly cast the U.S. and China as being in a race to develop the most cutting-edge AI. Both American and Chinese AI companies have announced this year that they have developed AI agents that are adept at hacking and cybersecurity operations.
In the last several months, both OpenAI and Anthropic have reported that their own AI agents have slipped out of evaluation sandboxes to reach third-party organizations — incidents that were disclosed after the fact. Google says it has not seen threat actors wage fully automated hacking campaigns but that instead, hacking groups are continuing to layer on more AI into their operations.
To date, there have been no publicly identified government hacking operations conducted entirely by AI agents. But China’s increasing reliance on agentic AI that it has installed on hacked computer networks means the country’s hackers — like any with sufficient resources and who aren’t legally constrained from such activity — can automate more of their work, Hultquist said.
“There were a couple cases where we could see them essentially trying to build out autonomous capabilities, so they can remove themselves, remove humans from the loop on some of their most important tasks,” Hultquist said.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | AI agents conspired to hack into networks and steal data during an experiment: study | 0 | 8.75 | 10-08-2026 |
| 2 | Хакеры использовали ИИ-агентов для успешного автономного взлома госсистем Тайваня | 0 | 10.75 | 13-08-2026 |
| 3 | Gemini AI Hacked Three Companies in a Testing Breakout, Google Says | 0 | 11.1 | 19-09-2026 |
| 4 | Chinese AI firms that rip off US models could face sanctions, Treasury Secretary Scott Bessent warns | -3 | 6 | 21-07-2026 |
| 5 | Hackers target PE firms with old-school vishing attacks - Google researchers | 0 | 12.12 | 10-08-2026 |
| 6 | 'GhostJacking' Exposes Identity Governance Gaps in AI Agents | 0 | 7.83 | 10-08-2026 |
| 7 | Google’s Gemini joins rogue AI cases after real-world hacks – WSJ | 0 | 12.78 | 19-09-2026 |
| 8 | A Sneaky Hacking Tool Targeting AI Infrastructure Is Lurking in Victims’ Blind Spots | 0 | 7.4 | 21-07-2026 |
| 9 | OpenAI AI agent hacked Hugging Face, went undetected for days: Report | 0 | 5.17 | 26-07-2026 |
| 10 | RatHat Android Malware Uses AI To Hijack Phones, Steal Banking Credentials | 0 | 6.65 | 18-09-2026 |