GTIG disrupts planned mass attack using an AI-assisted zero-day
Google Threat Intelligence observed criminals preparing a 2FA bypass for mass exploitation and assesses with high confidence that AI assisted discovery and weaponization.
- First observed
- May 11, 2026, 2:00:00 AM
- Disclosed
- May 11, 2026, 2:00:00 AM
- Status
- Resolved
- Confidence
- 90%
- Organization
- Google Threat Intelligence Group, Undisclosed open-source vendor
- Last reviewed
- Sep 1, 2026
Observed
Facts supported by sources
- The exact observation date was not disclosed; the report date is used as a fallback.
- The exploit targeted a logic flaw that bypassed two-factor authentication and required already valid credentials.
- GTIG worked with the vendor on responsible disclosure and disrupted the planned activity.
- GTIG does not believe Gemini was used and does not name the specific model.
Assessment
Interpretation, not observation
- The AI attribution is GTIG's high-confidence assessment based on the exploit's structure and content, not directly published model-log evidence.
Impact
Impact
A prepared mass attack that GTIG says was probably prevented; no confirmed victim count.
Response
Response
GTIG coordinated vulnerability disclosure with the vendor and disrupted the campaign.