AuraTracer智迹闻
中文

EVENT DOSSIER

Extortion crews have their eyes on high-value AI data, Google warns

2026-09-08 20:00 Cybersecurity 🔥 42.2 heat score
1sources
1days unfolding
42.2heat score
4mentions
SummaryAI generated

Google Threat Intelligence team warned that ransomware gangs are attacking high-value artificial intelligence data. In two cases investigated by Mandiant, attackers infiltrated medical companies and an AI media generation company, stealing sensitive data including AI models, source code, and prompts, and threatening to reveal the information without payment of a ransom. These incidents have affected the technology, medical, and media industries in North America and Europe. Additionally, the gang named TeamPCP (UNC6780) has carried out multiple large-scale open-source supply chain attacks since March, using malicious GitHub Actions workflows to steal AI repositories. Analysts noted that companies are often forced to pay ransoms due to their reluctance to expose intellectual property. At the same time, attackers are integrating proxy AI capabilities throughout the entire attack process, such as autonomously completing vulnerability scanning and credential collection within six hours, and even using Gemini to design automated penetration testing frameworks.

Related eventsRELATED EVENTS
Key entitiesKEY ENTITIES
GoogleMandiantTeamPCPUNC6780

Event frameEVENT FRAME

Regulation

Google → AI data extortion 发布 AI 威胁追踪报告

Coverage · reports per dayLANGUAGE SPLIT

Entity relations
Google × Mandiant1Google × TeamPCP1Google × UNC67801Mandiant × TeamPCP1Mandiant × UNC67801TeamPCP × UNC67801

SignalsSIGNALS

Keyword heat
  • Google1
  • Mandiant1
  • TeamPCP1
  • UNC67801

All reports (1)SOURCES

T The Register en 2026-09-08 20:00

Extortion crews have their eyes on high-value AI data, Google warns

谷歌威胁情报团队警告,勒索团伙正窃取高价值 AI 数据并以此要挟企业。在 Mandiant 调查的两起案例中,攻击者入侵了医疗公司和一家 AI 媒体生成公司,窃取包括 AI 模型、源代码及提示词在内的敏感数据,并在未获赎金前威胁公开泄露。谷歌最新发布的《AI 威胁追踪器》首次披露了这两起事件,指出此类攻击已波及北美和欧洲的科技、医疗及媒体行业。分析师约翰·霍尔奎斯特表示,由于企业不愿暴露知识产权,往往被迫支付勒索费。此外,名为 TeamPCP(UNC6780)的团伙自三月以来多次发动大规模开源供应链攻击,利用恶意 GitHub Actions 工作流窃取 AI 仓库;同时,攻击者正将代理 AI 能力整合至攻击全生命周期,例如在六小时内自主完成漏洞扫描与凭证收集,甚至使用 Gemini 设计自动化渗透测试框架。