The Attackers Preserved Context Better Than the Enterprise Preserved Authority.
AI can exploit organizational discontinuity at machine speed.
Palo Alto Networks Unit 42 reported in September 2026 that a human attacker used multiple frontier AI agents during an enterprise intrusion completed in less than ten hours. According to the incident-response account, the agents mapped architecture, searched code repositories for credentials, entered secret-management systems, obtained administrative credentials, triggered unauthorized CI/CD activity, stole cloud access keys, and reused the victim’s own AI endpoints as post-compromise infrastructure.
Unit 42 also observed structured Markdown used to carry operational state among agents and sessions. The attacker’s automation preserved working context while moving rapidly across enterprise systems.
Identity survived. Purpose did not.
Credentials and tokens proved that a technical identity could access a resource. But they did not preserve the institutional purpose or authorization context under which that access should have been legitimate.
GovKM maps the defensive failure as Evidence / credential → Authority / permitted use → Context / target system → Decision → Action. The credential remained valid evidence of identity while the authority relationship governing its acceptable use had become detached.
The attacker maintained continuity
The offensive workflow demonstrates the inverse. Structured state passed among agents helped preserve objectives, discoveries, credentials, and next actions across sessions. The attacker's system maintained enough working continuity to coordinate specialized activity even as the victim's authority boundaries fragmented across repositories and services.
That contrast is important: continuity is not inherently protective. It is an operational property. Organizations that fail to preserve legitimate authority and context can be exploited by adversaries that preserve their own.
Hard enforcement still mattered
Unit 42 reported that a branch-protection control stopped an attempted Terraform backdoor. That result illustrates the distinction between contextual policy and execution-time enforcement. The attacker possessed credentials and context, but the deterministic control still prevented the prohibited action.
GovKM interprets the incident as evidence that a credential proves identity, not purpose. Consequential enterprise actions need authority relationships that remain enforceable across system boundaries.
Source
Palo Alto Networks Unit 42, “An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation,” September 2, 2026, updated September 4, 2026. https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/



