Google's Mandiant incident response team has documented a growing wave of cyber extortion specifically targeting organizations' artificial intelligence assets. In the latest edition of its AI Threat Tracker, published Tuesday, Google detailed two cases for the first time.
In one incident, intruders broke into a healthcare company and stole corporate data and drug research, including AI research and a proprietary AI model. The criminals then threatened to publish the data unless the company paid a ransom. In a second breach, this time at a firm specializing in AI media generation, attackers stole sensitive AI data — source code, prompts, skills, model scripts, and secrets — before making a similar extortion demand.
John Hultquist, chief analyst at Google Threat Intelligence Group, said Mandiant responded to several such data-theft-and-extortion operations during the second quarter of 2026. The intrusions affected companies in the technology, healthcare, pharmaceutical, and media and entertainment sectors across North America and Europe.
“It’s become a really valuable target where organizations are spending a lot of money and investment, and they don’t necessarily want their IP exposed to the open world, so they’re willing to pay in an extortion scheme,” Hultquist said in an interview.
Google also highlighted the activity of a threat actor tracked as TeamPCP (UNC6780), which since March has conducted large-scale open source supply chain attacks against PyPI, npm, and Docker Hub. After compromising packages, TeamPCP typically deploys stealers to scoop up cloud and AI system credentials. The group created a malicious GitHub Actions workflow for a company's proprietary AI repository and exfiltrated a copy of the repository, according to the report. TeamPCP has implemented more than half a dozen different methods to target or exploit AI tools and open source development practices.
Beyond data theft, Google observed attackers integrating agentic AI capabilities into multiple stages of the attack lifecycle. In one case, miscreants compromised an organization's cloud infrastructure in an autonomous, multi-agent credential-harvesting attack that took less than six hours. The agents autonomously scanned for vulnerabilities, performed real-time troubleshooting, and executed IP rotation logic without manual intervention — what Hultquist described as "scanning — but with a brain."
Additionally, Google Threat Intelligence saw a China-linked espionage group using Gemini to design a dynamic, automated penetration-testing framework that could reason through actions and adapt in unpredictable environments. Google has disabled the assets associated with this group.
“Criminals attacking AI systems is an area that’s not received as much attention as it probably should, and as we incorporate these systems, it’s going to come with brand-new risks,” Hultquist added.