Illustration for: Google Mandiant: Hackers Now Ransom Your AI Models, Not Data

Google Mandiant: Hackers Now Ransom Your AI Models, Not Data

Google's Mandiant threat unit says extortion crews are now stealing proprietary AI models, training data and prompts before demanding ransom, treating a company's AI assets as more valuable leverage than customer records.

By the Numbers

TeamPCP / UNC6780
Tracked actor
March 2026
Active since
PyPI, npm, Docker Hub
Targets hit
Tech, health, pharma, media
Sectors affected
Google Threat Intelligence
Report source
TC
By the AI Desk
Edited by Trace Cohen · Early-stage VC & angel · Founder, New York Venture Partners
2 min read
ShareXLinkedInEmail
TC

The VC Read · Trace's Take

Trace Cohen

Model weights and fine-tuning data are now crown-jewel assets and most portfolio companies still guard them like internal documentation, not like source code or customer PII. The diligence question I'd add to every AI security review from here: who has egress access to the model artifacts and prompt library, and is it monitored separately from general cloud access? TeamPCP's supply-chain playbook through PyPI and npm means your dependency list is now part of your AI security surface, not just your infra.

Analysis

Google's Mandiant threat intelligence team says extortion crews are now specifically targeting proprietary AI models, training data and prompt libraries -- stealing the assets first, then threatening to leak them unless a ransom is paid, The Register reported Tuesday, citing Mandiant's AI Threat Tracker for the second quarter.

Who is doing it and how

Mandiant tracks the most successful group as TeamPCP, designated UNC6780, which since March has run large-scale supply-chain attacks against PyPI, npm and Docker Hub -- the package registries millions of developers pull dependencies from -- deploying credential stealers aimed specifically at cloud and AI service tokens rather than generic system access. Separately, Mandiant observed a China-linked espionage group using Google's own Gemini to help design an automated penetration-testing framework with autonomous reasoning capabilities, a use of a frontier model to accelerate the tooling used against other AI companies.

At a healthcare company, attackers exfiltrated proprietary drug-research data and AI models before demanding payment.

Two named incidents illustrate the pattern. At a healthcare company, attackers exfiltrated proprietary drug-research data and AI models before demanding payment. At an AI media generation company, criminals stole source code, prompts and model scripts -- the specific instructions and fine-tuning artifacts that represent a company's actual competitive edge, as distinct from the underlying open-weight model anyone can download. Mandiant's assessment of the motive is blunt: "Companies don't want their IP exposed, so they're willing to pay."

Why this differs from a normal ransomware playbook

Traditional ransomware extortion threatens to leak customer data or shut down operations by encrypting files -- both create disclosure obligations and downtime costs, but the underlying data usually has a known, roughly bounded value. A stolen AI model, training dataset or prompt library is different: it may represent years of RLHF tuning, proprietary data licensing, or a genuine architectural edge that a competitor would pay far more to acquire quietly than a victim would to ransom back. That asymmetry is exactly why Mandiant frames this as an emerging, distinct threat category rather than ransomware with a new target list, and it maps onto Pulse's prior coverage of OpenAI's own agent-security incidents -- the industry's security posture keeps lagging the value of what it is now protecting.

The counterweight and the practical exposure

Mandiant's report is threat intelligence built from observed incidents, not a comprehensive census -- the true scale of AI-asset extortion is unknowable from outside the victim companies, most of which have strong incentives never to disclose a quiet payment. Still, the specificity of the two named incidents, plus a threat actor already responsible for multiple confirmed supply-chain compromises, is a stronger evidence base than most emerging-threat reports carry.

For any startup building a defensible AI product, model weights, fine-tuning data and prompt engineering now belong in the same security tier as source code and customer PII -- most companies still treat them as internal artifacts rather than crown-jewel assets requiring separate access controls, encryption at rest and monitored egress. That gap is precisely what this generation of extortion crews is now built to exploit, and it is a materially harder gap to close than a normal ransomware playbook, because most security teams were built to protect data at rest, not a model's behavior and the pipeline that produced it.

ShareXLinkedInEmail

More on

Google

Key Sources

2 sources

THE WIRE in your inbox— Tech, startup & VC news with Trace's take. Free, no spam.