Google warns extortion crews targeting AI data as new attack surface emerges

Mandiant investigates breaches at healthcare, media firms as criminals steal proprietary models and source code

edit
By LineZotpaper
Published
Read Time3 min
Data theft and extortion crews are actively stealing companies' proprietary AI data and threatening to leak it unless ransoms are paid, according to Google's threat intelligence team. In two newly detailed intrusions — one at a healthcare company and another at an AI media generation firm — attackers exfiltrated AI models, research, source code, and secrets before demanding payment. Google warns the trend is likely to expand as AI assets become increasingly valuable targets.

Google's Mandiant incident response team has documented a growing wave of cyber extortion specifically targeting organizations' artificial intelligence assets. In the latest edition of its AI Threat Tracker, published Tuesday, Google detailed two cases for the first time.

In one incident, intruders broke into a healthcare company and stole corporate data and drug research, including AI research and a proprietary AI model. The criminals then threatened to publish the data unless the company paid a ransom. In a second breach, this time at a firm specializing in AI media generation, attackers stole sensitive AI data — source code, prompts, skills, model scripts, and secrets — before making a similar extortion demand.

John Hultquist, chief analyst at Google Threat Intelligence Group, said Mandiant responded to several such data-theft-and-extortion operations during the second quarter of 2026. The intrusions affected companies in the technology, healthcare, pharmaceutical, and media and entertainment sectors across North America and Europe.

“It’s become a really valuable target where organizations are spending a lot of money and investment, and they don’t necessarily want their IP exposed to the open world, so they’re willing to pay in an extortion scheme,” Hultquist said in an interview.

Google also highlighted the activity of a threat actor tracked as TeamPCP (UNC6780), which since March has conducted large-scale open source supply chain attacks against PyPI, npm, and Docker Hub. After compromising packages, TeamPCP typically deploys stealers to scoop up cloud and AI system credentials. The group created a malicious GitHub Actions workflow for a company's proprietary AI repository and exfiltrated a copy of the repository, according to the report. TeamPCP has implemented more than half a dozen different methods to target or exploit AI tools and open source development practices.

Beyond data theft, Google observed attackers integrating agentic AI capabilities into multiple stages of the attack lifecycle. In one case, miscreants compromised an organization's cloud infrastructure in an autonomous, multi-agent credential-harvesting attack that took less than six hours. The agents autonomously scanned for vulnerabilities, performed real-time troubleshooting, and executed IP rotation logic without manual intervention — what Hultquist described as "scanning — but with a brain."

Additionally, Google Threat Intelligence saw a China-linked espionage group using Gemini to design a dynamic, automated penetration-testing framework that could reason through actions and adapt in unpredictable environments. Google has disabled the assets associated with this group.

“Criminals attacking AI systems is an area that’s not received as much attention as it probably should, and as we incorporate these systems, it’s going to come with brand-new risks,” Hultquist added.

§

Analysis

Why This Matters

  • Organizations that have invested heavily in AI development face a serious new extortion threat; proprietary models and training data are irreplaceable and attackers know companies will pay to keep them secret.
  • The integration of agentic AI into attack chains makes intrusions faster, more adaptive, and harder to stop, lowering the barrier for sophisticated cybercrime.
  • As AI becomes embedded in critical sectors like healthcare and pharmaceuticals, supply chain attacks targeting open source ecosystems could have cascading effects.

Background

Cyber extortion has evolved from encrypting data to threatening to leak it, a tactic known as double extortion. High-value intellectual property — especially in AI — is an increasingly attractive target because companies cannot easily remove their AI models from the internet once stolen. Google's Mandiant team has tracked criminal groups and state-backed espionage actors exploring AI environments for months, and the recent surge in supply chain attacks suggests threat actors are methodically building tools to compromise AI pipelines.

Key Perspectives

Victim organizations: Must balance rapid AI deployment with robust security for model repositories, credentials, and cloud infrastructure. Extortion demands create a costly dilemma between paying and risking IP exposure. Google/Mandiant: As threat hunters, they are drawing attention to a nascent but dangerous trend, warning that the problem will grow as more criminals realize the value of AI data. Attackers (including TeamPCP): Have demonstrated that open source package registries are a viable vector for stealing AI credentials, and that extorting AI firms can be highly profitable. State actors benefit from acquiring models and techniques for their own purposes.

What to Watch

  • Whether other major criminal groups adopt TeamPCP's tactics for targeting AI repositories and cloud credentials.
  • Further integration of agentic AI into attack lifecycles — especially autonomous credential-harvesting and penetration-testing frameworks.
  • Policy responses, such as guidance from cybersecurity agencies or increased pressure on open source registries to improve supply chain security.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.