Extortion crews have their eyes on high-value AI data, Google warns

← Back to the feed

Extortion crews have their eyes on high-value AI data, Google warns

The Register · 1 hour ago

Google's threat intelligence team has warned that extortion gangs are increasingly targeting companies' proprietary artificial intelligence data, stealing sensitive materials such as AI models, source code and research before threatening to leak them unless a ransom is paid. Mandiant, Google's incident response arm, detailed cases including a healthcare firm whose drug research and proprietary AI model were exfiltrated, and an AI media generation company that had source code, prompts and secrets stolen, highlighting AI systems as a lucrative and under-protected target as firms pour investment into them.

Mandiant responded to several such data-theft-and-extortion incidents in the second quarter of 2026, affecting technology, healthcare, pharmaceutical, and media firms across North America and Europe. The report also flags a group known as TeamPCP (tracked by Google as UNC6780), which has run large-scale supply chain attacks on PyPI, npm and Docker Hub since March to harvest cloud and AI credentials, and notes a broader shift towards attackers embedding agentic AI into multiple stages of attacks—including a six-hour autonomous multi-agent credential-harvesting operation and a China-linked espionage group using Gemini to build an automated penetration-testing framework, whose associated assets Google has since disabled.

  • Extortion gangs are stealing and ransoming firms' proprietary AI data
  • Healthcare and AI media firms hit; ransom demanded to prevent leaks
  • Attackers increasingly use agentic AI across multiple attack stages

New here? Start with this

Extortion gangs typically operate by breaking into a company's systems, copying sensitive files, and then demanding payment to stop that data being published or sold. Historically this has focused on things like customer records or financial information, but Google's Mandiant security division says it is now seeing criminals go after artificial intelligence assets specifically: the trained models, source code and research that companies have invested heavily in building. Because so much money and effort is going into AI development, these assets can be highly valuable, and often are not as well protected as more traditional data.

Mandiant is the part of Google that helps organisations investigate and respond to cyberattacks, giving it visibility into real-world incidents across many industries. Its findings point to a wider pattern of criminal and state-linked groups adapting their tactics as AI becomes more central to business, including hackers targeting the software supply chains developers rely on, and even using AI tools themselves to automate parts of their attacks.

This matters because it signals a shift in what hackers consider worth stealing, and suggests that companies building or using AI systems may face new risks that existing security practices were not designed to cover.

AI Technology

Read the full article at the source →