Spies and Criminals Are Stealing AI Systems, Not Just Data
Google's threat research team says nation-state hackers and extortion gangs are now going after the AI models, cloud accounts, and secret access keys that companies use to run artificial intelligence, turning those stolen assets into weapons for their own attacks.

Key points
- Google's Threat Intelligence Group (GTIG) published a quarterly AI Threat Tracker in late June 2026 documenting a sharp rise in attacks aimed at stealing artificial intelligence assets from enterprises.
- A China-linked espionage cluster tracked as UNC6508 broke into academic and defence organisations and hijacked cloud computing resources to run its own AI workloads.
- Mandiant, Google's incident-response division, investigated at least two breaches in Q2 2026 where extortion groups stole proprietary AI models, including one theft from a healthcare company that included drug research.
- Google recorded campaigns using more than 100 million automated prompts designed to drain the knowledge out of its own AI models without paying for them.
- Known groups including SANDWORM RELIC, CALANQUE ION, and UNC6240 (also known as ShinyHunters) all used Google's Gemini AI assistant to sharpen their attacks.
Artificial intelligence has become a product companies pour millions into building. Hackers have noticed.
Google's Threat Intelligence Group, a team that tracks criminal and government-backed hacking operations worldwide, released its latest quarterly AI Threat Tracker last week. The picture it paints is straightforward: the same people who once broke into systems to steal customer records are now breaking in specifically to steal AI models, the secret credentials that grant access to them, and the cloud computing power that runs them.
What did the hackers actually take?
They stole the AI itself, not just the data around it. During Q2 2026, Mandiant investigated a breach of a healthcare organisation where criminals walked off with drug research and a proprietary AI model the company had built internally. A separate attack hit an AI media-generation company, stripping out source code, prompts (the instruction sets that tell an AI how to behave), and what researchers call "skills" (reusable AI capabilities packaged for repeated use).
Beyond straight theft, GTIG documented a technique called model distillation: interrogating an AI so thoroughly that you can teach a cheaper copy to think like the original, without ever paying for a licence. Google says campaigns targeting its own audio and image generation tools involved more than 100 million automated prompts, all fired through networks of thousands of hijacked accounts to hide who was behind them.
Who is behind this?
Both governments and criminals, often for different reasons but with overlapping methods.
On the government side, GTIG flagged UNC6508, a China-linked espionage cluster we first covered on 16 June 2026, for targeting healthcare and defence-sector organisations. Researchers at medium confidence assess the group collected AI research and then used stolen cloud credentials to quietly run its own AI infrastructure inside victim environments, a tactic sometimes called "LLMJacking" (hijacking a victim's cloud account to run large language models, which are the AI systems that power chatbots, at the victim's expense).
Separately, the US National Security Agency and the FBI, alongside CISA, published an advisory accusing China-based AI labs of running industrial-scale distillation attacks against leading US AI models.
A Chinese group also built an automated attack pipeline that handled everything from initial reconnaissance (scanning the internet for weak points) to stealing credentials for deeper access, with minimal human involvement.
On the criminal side, a financially motivated group used stolen cloud credentials to deploy an autonomous multi-agent attack framework, where AI agents (software programs that can plan and act independently) ran a mass credential-harvesting campaign in under six hours. We reported on that agent-based attack pattern on 8 September. Researchers also found a tool called Recon sitting on an active command-and-control server, the kind of remote computer criminals use to direct attacks, managing more than 23,000 stolen credentials including API keys for cloud and AI services. An API key is a digital password that lets one piece of software talk to another; stealing it grants access without needing a username or a separate breach.
Groups identified in the GTIG report include SANDWORM RELIC (also known as APT44, linked to Russian military intelligence), CALANQUE ION (also known as APT42, an Iranian state-sponsored group), RAVINE CASTLE (also known as APT24, Chinese), MIDNIGHT NEPTUNE (also known as UNC1069, a North Korean group with a history of cryptocurrency theft), and UNC6240. ShinyHunters, operating as UNC6240, dumped 12.9 million Carhartt customer records in late August after the company refused a ransom demand, and it's worth watching how that same crew now pivots toward AI credential theft.
Should ordinary employees or customers be worried?
Yes, practically. If your employer uses AI tools and the access keys for those tools are stolen, criminals can impersonate your company's legitimate systems. That makes phishing emails, the fake messages designed to trick staff into handing over passwords, far more convincing because they may appear to come from tools your colleagues already trust.
Any organisation that holds AI-related credentials, even as a customer rather than a developer, should treat those keys the way it treats banking passwords: rotate them regularly, set alerts for unusual usage, and tell staff what to watch for.



