← Incident database

unit42-ai-assisted-2026 · Disclosed 2026-09-02

Unit 42: AI-assisted intrusion abusing repository secrets

Unit 42 reported an intrusion that expanded from an exposed service to cloud systems through repository secrets, with LLM calls observed during the attack.

CredentialsConfiguration / exposure

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    Repository tokens, vault credentials, and cloud keys in CI enabled expansion.

    [s1]Repository / vault / CI stages
  • Reported fact

    Branch protection blocked a backdoor attempt; the intrusion was not established as ransomware.

    [s1]Branch protection / September corrections
  • Reported fact

    Investigators reported LLM calls and operations involving multiple agents during the attack.

    [s1]AI-assisted orchestration

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    Investigators reported that branch protection prevented the attacker’s change from reaching production.

    [s1]Branch protection

Evidence relevant to prevention

Operational controls to inspect

Inspect repository secrets and CI, vault, and AI-endpoint privileges; separate change approval from production credentials.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementReported fact

Unit 42 reports LLM calls during the intrusion; this does not establish autonomous execution of every stage.

Victim identity and initial vulnerability are undisclosed; the full human-versus-agent autonomy split is unverified.

Sources

  1. [s1] Palo Alto Networks Unit 42 · Primary source

    An AI-assisted cyber attack: inside a Unit 42 investigation ↗

    Published 2026-09-02 · Reviewed 2026-10-02