Hackers Now Hand Off Stolen Access in 22 Seconds. Google Just Built AI Agents That Fight Back at Machine Speed

Mandiant's M-Trends 2026 report found hackers can pass stolen access between groups in 22 seconds. Google's answer is an AI-powered SOC that never sleeps.

Cybersecurity analyst at dual monitors working on threat detection and AI-powered security operations

In 2022, when a hacker broke into a network and wanted to hand that access off to another criminal group, the process took more than eight hours. By 2025, that window had collapsed to 22 seconds.

That’s the headline finding from Mandiant’s M-Trends 2026 report, published this week at RSAC and built on more than 500,000 hours of frontline incident investigations conducted globally last year. The implication is straightforward: the human security analyst checking an alert queue has already lost before they get their coffee.

Google’s answer, announced alongside the report, is an agentic security operations center built on the latest Gemini models — AI agents that investigate alerts, synthesize threat intelligence, and assist with remediation in real time, without waiting for a human to pull up a dashboard.

The 22-second figure isn’t just a dramatic stat. Mandiant researchers believe it reflects something structural about how criminal operations have matured. Initial access brokers — specialists who break in and sell that foothold to others — are increasingly automating the handoff rather than advertising access on forums. The buyer gets in almost simultaneously with the breach. By the time a SOC team gets an alert, a second group may already be executing their payload.

The broader picture from M-Trends is one of bifurcation. Cybercriminal groups are optimizing for speed and maximum disruption. Nation-state actors and espionage groups are doing the opposite — moving slowly and quietly through edge devices and native network features, sometimes persisting undetected for years. Both trends, at opposite ends of the velocity spectrum, are getting harder to stop with traditional playbooks.

Exploits remained the most common initial access vector for the sixth year running, appearing in 32% of Mandiant investigations where a vector could be identified. Voice phishing climbed to second place at 11% — a reminder that social engineering is scaling alongside the technical attacks. Federal agencies have already faced the consequences of slow patch cycles, with CISA issuing emergency directives to close critical vulnerabilities being actively exploited in the wild.

The patch problem got measurably worse. The mean time to exploit known vulnerabilities dropped to negative seven days in 2025 — meaning attackers are routinely exploiting flaws before a patch even exists. Defenders are no longer racing to apply fixes. They’re racing against an invisible clock they can’t see.

Google’s new Alert Triage and Investigation Agent is designed specifically for this environment. It autonomously gathers evidence, decodes obfuscated scripts, and correlates signals across tools — delivering a verdict and explanation without requiring an analyst to trace each step manually. The system is now in public preview for Google Security Operations customers.

On the threat intelligence side, Google’s platform is adding Gemini-powered agents that scan millions of external signals daily and elevate only the threats that matter, with 98% accuracy in internal testing. The dark web monitoring module automatically builds an organizational profile and tracks criminal activity relevant to that specific company — rather than dumping a raw feed of underground chatter at an analyst.

AI being used to both probe and defend critical systems is increasingly the norm across industries, not just enterprise security. At RSAC, Google also announced MCP server support for Security Operations customers — letting enterprises build their own security agents without managing the underlying infrastructure, with general availability set for early April.

The Wiz acquisition, which closed last year, is now producing results at the product layer. Wiz is launching an AI Application Protection Platform with security agents covering red-team, blue-team, and green-team functions, feeding into Google’s broader push to unify cloud infrastructure security with the SOC layer.

Mandiant’s Phil Venables, Google Cloud’s CISO, noted at RSAC that the challenge isn’t awareness of the threat — it’s the sheer volume of signals that make acting on any single one nearly impossible without automation. The 22-second handoff window is a forcing function. At that speed, the only realistic response is a system that doesn’t have to decide whether to look.

Leave your vote