Extortionists Are Coming for Your AI Models, Google's Threat Hunters Warn
Corporate AI assets have become a lucrative extortion target, according to Google's Mandiant incident response team, which investigated multiple data theft and ransom operations during the second quarter of 2026 alone.
In one case, attackers broke into a healthcare company and walked out with drug research and a proprietary AI model. Their demand was simple: pay up, or watch the data go public. In another intrusion, a company specialising in AI-generated media had its source code, model scripts, prompts, and credentials stripped out before receiving a similar ultimatum.
Google published details of both cases in its latest AI Threat Tracker this week.
"It's become a really valuable target," said John Hultquist, chief analyst at Google Threat Intelligence Group. "Organizations are spending enormous amounts on this IP and they don't want it exposed, so they're willing to pay."
The affected sectors include technology, healthcare, pharmaceuticals, and media and entertainment, with victims spread across North America and Europe. The pattern is consistent: find a company sitting on valuable AI assets, steal everything, and threaten to dump it unless a ransom lands.
One group Google is tracking closely is TeamPCP, internally designated UNC6780. Since March, this crew has run large-scale supply chain attacks across PyPI, npm, and Docker Hub, compromising open source packages to harvest cloud and AI system credentials. In at least one confirmed case, they created a malicious GitHub Actions workflow inside a victim's proprietary AI repository and exfiltrated its contents. Google notes the group has now developed over half a dozen distinct methods specifically targeting AI tools and open source development pipelines.
"Criminals attacking AI systems is an area that hasn't received the attention it probably should," Hultquist said. "TeamPCP has been extremely successful."
Beyond theft and extortion, Google's researchers are watching threat actors get considerably more sophisticated in how they use AI offensively. In one incident, Mandiant observed an autonomous, multi-agent attack on a compromised cloud environment that completed credential harvesting in under six hours. No human hand-holding required. The agents scanned for vulnerabilities, rotated IP addresses, and troubleshot their own problems in real time. "Like scanning, but with a brain," as Hultquist put it.
A separate case involved a China-linked espionage group using Gemini to build an automated penetration-testing framework capable of reasoning through obstacles and adjusting its approach on the fly. Google disabled the associated assets, but the direction of travel is clear.
Earlier this year, Google's researchers documented attackers experimenting with agentic AI for isolated parts of attacks. By Q2 2026, those same techniques were being threaded through multiple stages of a single operation.
"We're in this interim phase where threat actors are inserting agentic AI into parts of their operations, but haven't yet removed themselves from the process entirely," Hultquist said. "We're right on the precipice of that."
When that precipice gets crossed, the question won't be whether your AI is safe to deploy. It'll be whether you even still own it.