Google’s threat intelligence team says data theft and extortion crews are increasingly stealing companies’ proprietary AI assets and threatening to leak them unless they are paid. The finding appears in Google’s latest AI Threat Tracker, published Tuesday, which details two intrusions for the first time.
In one case handled by Mandiant’s incident response team, attackers broke into a healthcare company and exfiltrated corporate data and drug research, including AI research and a proprietary AI model, then demanded payment. In another, at a company that builds AI media generation tools, the intruders stole source code, prompts, skills, model scripts, and secrets before threatening to dump the material publicly.
Mandiant responded to several such operations during the second quarter of 2026, hitting technology, healthcare, pharmaceutical, and media and entertainment companies in North America and Europe. John Hultquist, chief analyst at Google Threat Intelligence Group, said organizations spending heavily on AI do not want their intellectual property exposed and are often willing to pay to keep it private. He singled out the actor known as TeamPCP as unusually successful in this space.
The warning frames AI systems as an emerging extortion surface: models, prompts, and training data now rank alongside source code as assets worth stealing. Hultquist said criminals attacking AI systems have drawn less attention than the risk deserves, and that incorporating these systems into business will bring brand-new exposure as defenders learn to treat them that way.
