Extortion crews have their eyes on high-value AI data, Google warns
- ID
- 22315
- Status
- summarized
- Published
- 08 Sep 2026, 8:00 PM
- Fetched
- 08 Sep 2026, 8:05 PM
- Provider
- The Register
- Category
- technology
- Original URL
- https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640
- Source URL
- https://www.theregister.com/headlines.atom
Summary
- Score
- 7.5
- Created
- 08 Sep 2026, 8:08 PM
- Tags
- Audience
- developersai_ml_learnerssaas_startup_founders
What happened
Google's Mandiant team reports extortion crews are stealing proprietary AI assets—models, source code, prompts, skills, model scripts, and secrets—and threatening to leak them unless ransoms are paid. In two disclosed breaches, a healthcare company lost drug research and an AI model, while an AI media generation firm lost source code, prompts, and secrets. Google also flags TeamPCP (UNC6780) as running large-scale open source supply chain attacks on PyPI, npm, and Docker Hub since March 2026.
Why it matters
If you ship AI products, your prompts, model scripts, and proprietary models are now extortion targets—not just PII or credentials. Audit what secrets and AI assets sit in your repos and CI pipelines, and scrutinize dependencies pulled from PyPI, npm, and Docker Hub given TeamPCP's active supply chain campaigns in those exact ecosystems.
Discussion angle
What's your current process for vetting packages from PyPI, npm, and Docker Hub—and would you even notice if a dependency you've used for months was silently compromised?