Google's Threat Intelligence Group (GTIG) successfully blocked a large-scale cyberattack powered by an artificial intelligence model. The unidentified hacking group used AI to discover a previously unknown zero-day software flaw. This exploit was specifically designed to bypass two-factor authentication protocols.

This incident marks the first time Google has observed AI used for both zero-day identification and exploit creation. Security teams intercepted the operation before the hackers could execute the planned mass exploitation event.

Google confirmed that neither its Gemini model nor Anthropic’s Mythos model were utilized in the attempt. The company did not disclose the specific AI model used or the identity of the cybercrime group responsible.