Extortion Gangs Target High-Value AI Data, Google Warns
Google's Mandiant reports that extortion gangs are increasingly targeting proprietary AI data, including models and research, with threats of public leaks for ransom.

Extortion gangs are increasingly targeting companies' proprietary artificial intelligence data, including sensitive models and research, threatening public leaks if ransoms are not paid, according to Google's threat intelligence unit, Mandiant. These attacks represent a significant escalation in cybercriminal focus, moving beyond traditional corporate data to the highly valuable intellectual property that underpins AI development.
Mandiant investigated multiple incidents in the second quarter of 2026 where attackers successfully exfiltrated sensitive AI assets from organizations across the technology, healthcare, pharmaceutical, and media sectors in North America and Europe. In one notable case, threat actors breached a healthcare company, stealing not only corporate data but also crucial drug research and a proprietary AI model. The criminals then leveraged this theft to demand a ransom, threatening public disclosure of the stolen intellectual property.
Another incident involved a company specializing in AI media generation, where attackers made off with a trove of sensitive AI data. This included source code, prompts, skills, model scripts, and secrets. Following the exfiltration, a ransom demand was issued, with the threat of publicly releasing the stolen AI assets if the payment was not made.
"It’s become a really valuable target where organizations are spending a lot of money and investment, and they don't necessarily want their IP exposed to the open world, so they're willing to pay in an extortion scheme," explained John Hultquist, chief analyst at Google Threat Intelligence Group. This highlights the unique value proposition of AI data, making it a prime target for financially motivated cybercriminals.
The threat actor UNC6780, also tracked as TeamPCP, has been particularly active and successful in this domain. This group has been observed employing sophisticated tactics, including the creation of malicious GitHub Actions workflows targeting proprietary AI repositories. By compromising these workflows, UNC6780 has been able to exfiltrate entire AI repositories, demonstrating a deep understanding of modern development practices.
Beyond direct repository theft, UNC6780 has developed over half a dozen methods to target or exploit AI tools and open-source software development practices. This multifaceted approach allows them to adapt and exploit various vulnerabilities within the AI development ecosystem, making them a persistent and evolving threat.
Google's research also points to the growing integration of agentic AI capabilities into attack chains. While previous reports noted experimentation, the latest findings reveal attackers are now embedding these autonomous capabilities into multiple stages of their operations. This includes autonomous credential harvesting attacks that can scan for vulnerabilities, perform troubleshooting, and rotate IP addresses without human intervention, significantly accelerating the speed and efficiency of attacks.
This trend signifies a broader shift in the threat landscape, where AI is not only the target but also a tool for sophisticated cyberattacks. As organizations continue to invest heavily in AI development, the protection of this data becomes paramount, requiring new strategies and defenses against these evolving threats.