Extortion Crews Target Companies' AI Data with Ransom Demands
Data theft and extortion crews are targeting companies' proprietary AI data, threatening to leak it unless they pay a ransom, according to Google's threat hunters. The crooks break into companies, exfiltrate corporate data, including AI research and models, and demand payment.
Google investigated two cases: one at a healthcare company where the attackers stole drug research and AI data, and another at an AI media generation company where they stole sensitive AI data, including source code and model scripts.
The intrusions affected companies in various sectors, including technology, healthcare, pharmaceuticals, and media and entertainment, in North America and Europe. Google's threat intelligence group notes that the attackers are 'extremely successful' in this area, particularly TeamPCP (UNC6780), which has pulled off several large-scale open-source supply chain attacks.
The researchers observed that UNC6780 created a malicious GitHub Actions workflow for a company's proprietary AI repository and exfiltrated a copy of it. They also used agentic AI to support certain parts of the attack lifecycle, including autonomous credential-harvesting attacks.