Google Warns of Rising Extortion Attacks Targeting Proprietary AI Data
Cybercriminals are shifting from ransomware to the theft of AI models and research to coerce high-value payments from tech and biotech firms.
Cyber-extortion crews are increasingly targeting proprietary artificial intelligence data—including model weights, source code, and research—to coerce payments from victims. Google's Mandiant team identified this trend in Q2 2026, noting that attackers are exfiltrating intellectual property and threatening public leaks rather than relying on traditional encryption.
According to Mandiant, these operations have hit sectors including media, pharmaceuticals, and healthcare across Europe and North America. In one instance, a healthcare company lost both a proprietary AI model and critical drug research. Another target, an AI media generation firm, saw the theft of its source code, model scripts, secrets, prompts, and specialized skills.
One specific threat actor, TeamPCP (tracked as UNC6780), has utilized supply chain attacks via Docker Hub, npm, and PyPI to harvest credentials for AI systems and cloud environments. Mandiant further documented UNC6780 creating a malicious GitHub Actions workflow specifically designed to exfiltrate a company's proprietary AI repository.
The Shift to IP Extortion
This trend reflects a broader shift in the cyber-extortion landscape from encryption-based ransomware to exfiltration-based intellectual property theft. As corporations invest heavily in proprietary AI to secure competitive advantages, the value of training data and specialized prompts has skyrocketed.
Organizations are spending significant capital on these investments and are often more willing to pay an extortion scheme to prevent their IP from being exposed to the open world than they are to recover encrypted files. This shift effectively turns AI infrastructure from a secondary target into a primary objective for financially motivated crews.
The Rise of Agentic Attacks
Beyond the theft of data, attack methods are becoming more sophisticated through the integration of "agentic AI." Mandiant observed an autonomous, multi-agent credential-harvesting attack that was completed in under six hours, demonstrating a level of speed and automation that reduces the need for human intervention during a breach.
Furthermore, a China-linked espionage group reportedly used Gemini to design a dynamic, automated penetration-testing framework, signaling that attackers are using the same AI tools they target to refine their offensive capabilities.
Future Risks
As AI systems become more deeply integrated into corporate operations, the attack surface continues to expand. The continued incorporation of these systems will introduce brand-new risks to the global enterprise, particularly as criminals target AI systems—an area that has not yet received sufficient attention.
Security teams are now tasked with protecting not just the data these models produce, but the underlying weights and scripts that constitute the core value of modern tech and biotech firms. The speed of agentic attacks suggests that traditional response times may soon be insufficient to prevent total data exfiltration.