Extortion crews have their eyes on high-value AI data, Google warns
Companies 'don't want their IP exposed, so they're willing to pay'
Google has issued a warning to companies about the growing threat of extortion crews targeting high-value AI data. These criminal groups are stealing proprietary AI data and threatening to leak it unless the victim organization pays a ransom. In one incident, a healthcare company had corporate data and drug research, including AI research, stolen and threatened to be published unless the company met the extortion demand.
Another case involved an AI media generation company whose sensitive AI data, including source code, prompts, skills, model scripts, and secrets, were stolen before a demand for payment and a threat of public AI data dump was made. Google’s Mandiant incident response team responded to several of these data-theft-and-extortion operations during the second quarter of 2026.
These breaches affected companies in the technology, healthcare, pharmaceutical, and media and entertainment sectors in North America and Europe. Mandiant’s Chief Analyst, John Hultquist, highlighted that AI systems are becoming a valuable target for these extortion schemes as companies invest heavily in them and are willing to pay to avoid their IP exposure.
Hultquist pointed out that threat actors like TeamPCP are notably advanced in this area, having successfully executed multiple large-scale open-source supply chain attacks targeting ecosystems such as PyPI, npm, and Docker Hub. These attacks often involved compromising open-source packages and registries to obtain AI system credentials.
Google has noted that the threat actors have implemented numerous methods to target or exploit AI tools and open-source software development practices. Recent updates to Google’s AI Threat Tracker show that attackers are increasingly integrating agentic AI capabilities into multiple stages of an attack lifecycle. This includes autonomous multi-agent credential-harvesting attacks that can scan for vulnerabilities, perform real-time troubleshooting, and execute IP rotation logic without manual intervention.
Google has also observed a China-linked espionage group utilizing Gemini to create a dynamic, automated penetration-testing framework capable of reasoning and adapting to unpredictable environments. Google has disabled the assets associated with this particular threat actor. Hultquist emphasized that while some threat actors have integrated agentic AI into certain parts of their operations, they have not yet fully removed themselves from the attack chain, and they are close to achieving that milestone.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.