Google says extortion crews are stealing proprietary AI models, prompts, source code, and research data from companies

Google says extortion groups are breaking into companies and stealing valuable AI data, then threatening to leak it unless the victim pays. In newly disclosed Mandiant cases, one healthcare company lost corporate data, drug research, AI research, and a proprietary AI model, while an AI media generation company lost source code, prompts, skills, model scripts, and secrets. Google says the activity hit technology, healthcare, pharmaceutical, and media organizations in North America and Europe during Q2 2026.
Why it matters: This shows that attackers are treating AI models, prompts, code, and related research as ransom-worthy intellectual property, not just ordinary files. Organizations building or using AI should tighten cloud and repository access, protect secrets, review GitHub Actions and other automation, and prepare for data-extortion even when no systems are encrypted.

Sources

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns
Kevin Townsend 2026.09.09 33% relevant
The piece connects to Google's broader reporting on AI-enabled threat activity, but this article is more focused on AI as an operational multiplier for attackers rather than theft of AI assets from victim organizations.
Extortion crews have their eyes on high-value AI data, Google warns
2026.09.08 100% relevant
This article establishes a distinct trend story: data-theft extortion crews are specifically targeting high-value AI assets across multiple sectors, with newly disclosed victim case details rather than a single previously tracked breach.
← Back to all stories