“It’s become a really valuable target where organizations are spending a lot of money and investment, and they don't necessarily want their IP exposed to the open world, so they're willing to pay in an extortion scheme,” John Hultquist, chief analyst at Google Threat Intelligence Group, said in an interview with The Register.
Two detailed breaches: healthcare research and AI media generation
Google’s Mandiant incident response team described two intrusions in its most recent AI Threat Tracker, published Tuesday. In one investigation Mandiant found attackers had broken into a healthcare company and exfiltrated corporate data and drug research, including AI research and a proprietary AI model; the intruders then threatened to publish the stolen material unless the victim paid a ransom. In a separate case at a company that specializes in AI media generation, attackers stole sensitive AI assets — specifically source code, prompts, skills, model scripts, and secrets — before issuing a payment demand and threatening to dump the assets publicly if the ransom wasn’t met.
TeamPCP (UNC6780) and open-source supply-chain compromises since March
Google named a prolific extortion actor, TeamPCP — tracked as UNC6780 — as “extremely successful.” Since March, UNC6780 executed very large-scale open-source supply-chain attacks against ecosystems including PyPI, npm, and Docker Hub. After compromising those packages and registries, the actor typically deployed stealers to harvest cloud and AI system credentials. Mandiant’s evidence showed UNC6780 created a malicious GitHub Actions workflow for a company’s proprietary AI repository and exfiltrated a copy of that repository. Google’s report says the group “has also implemented more than half a dozen different methods to target or exploit AI tools and open source software development practices.”

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAgentic capabilities and autonomous, multi-agent intrusions
Google’s researchers reported that attackers have moved beyond experimenting with agentic AI and are integrating agentic capabilities into multiple stages of the attack lifecycle. In one observed intrusion, miscreants compromised a cloud environment in an autonomous, multi-agent credential-harvesting campaign that finished in less than six hours. During the operation the agents autonomously scanned for vulnerabilities, performed real-time troubleshooting, and executed IP-rotation logic without manual intervention — a pattern John Hultquist summarized as “Like scanning – but with a brain.”
The report also details a case in which a China-linked espionage group used Gemini to design a dynamic, automated penetration-testing framework that could reason through actions, execute tasks, and change course as needed in unpredictable environments. Google disabled the assets associated with that crew.
Sectors, geography, and Mandiant’s Q2 2026 response
Mandiant responded to several data-theft-and-extortion operations during the second quarter of 2026, the Google report says. The intrusions affected organizations in technology, healthcare, pharmaceutical, and media and entertainment sectors, and occurred across North America and Europe. The common denominator in the documented cases was theft of AI-specific assets — models, research, scripts, prompts, and secrets — which attackers used as leverage in extortion demands.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: Expect attackers to weaponize agentic tools across reconnaissance, credential harvesting, and exfiltration. The report’s examples — malicious GitHub Actions workflows and autonomous multi-agent campaigns that completed in under six hours — point to specific vectors defenders should prioritize.
- Policymakers and regulators: The report highlights that open-source ecosystems including PyPI, npm, and Docker Hub were targeted by a single actor since March; that pattern may inform oversight, guidance, and protective measures for software supply chains and package registries.
- Affected enterprises and procurement leaders: Organizations investing heavily in AI and proprietary models face a clear extortion risk because attackers value those assets as bargaining chips. The cases described show that source code, prompts, model scripts, and proprietary models are now explicit targets for theft-and-extortion schemes.
Google’s account draws a straight line from supply-chain compromises to credential theft to rapid, agent-enabled intrusions and finally to extortion of high-value AI assets. As John Hultquist put it, criminals attacking AI systems are “ahead of others” in some respects, and defenders are “right on the precipice” of a shift to even more autonomous operations. The concrete question left by the report is this: can defenders harden the open-source and cloud development pathways that UNC6780 and others have exploited before agentic tooling removes the last human brakes on large-scale exfiltration and extortion?




