AI assets become prime targets for attackers
Google's threat intelligence unit reports that espionage and criminal groups are stealing models, prompts, and API keys to power their own AI operations.
The lure of artificial intelligence has spread well beyond corporate boardrooms. According to Google's Threat Intelligence Group, it now extends into the operational toolkits of state-sponsored spies and financially motivated cybercriminals who are systematically hunting for the data, code, and credentials that make enterprise AI systems run.
The finding comes from GTIG's latest quarterly AI Threat Tracker report, which describes adversaries with an array of motivations targeting proprietary models, source code, and cloud environments. The goal, according to the researchers, is not simply intellectual property theft but the acquisition of the computational power and access needed to run AI workloads of their own.
"GTIG observed adversaries with wide-ranging motivations target proprietary AI models and source code, exfiltrate application programming interface (API) credentials, and co-opt victim cloud environments to sustain unauthorized AI workloads," the Google Threat Intelligence Group said in the report. "This shift underscores that enterprise AI assets — from model weights to cloud compute quotas — are high-value targets for espionage, extortion, and resource theft."
Credentials ranked above models
While the theft of a proprietary model draws the most attention, the report makes clear that the credentials surrounding it may be just as valuable to an intruder. API keys, service accounts, and cloud access tokens allow an attacker to run workloads at someone else's expense or to feed data into a model without ever touching the model's weights.
The National Security Agency, the Federal Bureau of Investigation, and the Cybersecurity and Infrastructure Security Agency published an advisory accusing China-based AI labs of engaging in industrial-scale distillation against US frontier AI models. That advisory also came last week, according to the source material.
Ismael Valenzuela, vice president of labs, threat research, and intelligence at Arctic Wolf, tells CSO that companies often underestimate their own exposure because they do not consider themselves AI developers.
"Businesses not directly associated with frontier AI models may be tempted to disregard these campaigns as irrelevant due to them being a national security issue, but the exposure of model access to customers or partners makes API keys and service accounts valuable targets, with abuse of access to those models appearing as legitimate," Valenzuela says.
— Ismael Valenzuela, VP of labs, threat research, and intelligence at Arctic Wolf
Distillation campaigns surge against Google models
One of the more striking data points in the report concerns model distillation, a technique in which an attacker extracts the outputs of a target model through crafted prompts and uses that data to train a competing system. GTIG reports an increase in distillation attack campaigns against Google's own AI models.
The scale is substantial. Google observed campaigns involving more than 100 million prompts targeting audio, video, and image generation capabilities, according to the report. Those campaigns were launched through proxy networks using thousands of compromised account credentials.
Distillation is not a new concept in machine learning research, but the report describes it being weaponized at a volume that suggests a coordinated, resource-intensive effort rather than isolated experimentation. The use of proxy networks and stolen credentials is intended to obscure the origin of the traffic and to evade rate limits or account restrictions that would otherwise slow the extraction process.
Espionage groups and criminal gangs converge
The report draws a direct line between state-aligned espionage actors and cybercrime groups that are pursuing similar AI-related assets for different reasons. For intelligence services, the value lies in research data and the ability to run models without attribution. For criminal gangs, the appeal is extortion leverage and the raw compute needed to automate attacks.
GTIG points to a China-based cyberespionage group tracked as UNC6508 that previously targeted organizations involved in academic, healthcare, and defense research. According to the report, the information collected by this group included AI research. UNC6508 was also observed compromising cloud environments to deploy large language model infrastructure for its own use, researching how to run LLMs locally, and investigating vulnerabilities in AI models.
The threat activity reached beyond AI labs alone. Government, military, healthcare, and media organizations that train or fine-tune their own models were also affected, the report states. Even organizations that do no model development may hold significant AI-related proprietary data, from retrieval-augmented generation pipelines and custom workflows to agents and credentials.
Healthcare and media breaches show the pattern
During the second quarter of 2026, Google's Mandiant incident response arm investigated breaches by data extortion groups that involved the theft of AI models, skills, prompts, source code, and related research, according to the report.
In one case, a threat actor breached a healthcare organization and stole drug research and other corporate data, including a proprietary AI model. In a separate incident, attackers compromised an AI media generation company and stole proprietary source code, prompts, skills, model scripts, and secrets.
Those two incidents illustrate how broadly the targeting has spread. The healthcare victim's stolen model and research data have direct competitive and scientific value. The media company's loss includes the prompt libraries and scripts that represent years of tuning work, assets that are difficult to recreate and potentially valuable on underground markets.
Agentic AI turns stolen compute into attacks
Beyond distillation, the report describes attackers using stolen AI-related credentials to automate offensive operations, including what the researchers call a high level of automation via AI agents.
Mandiant observed a financially motivated threat actor use compromised cloud infrastructure credentials to deploy an autonomous multi-agent attack framework. The resources enabled the attacker to plan, build, and execute a mass credential harvesting campaign in less than 6 hours.
"Using preconfigured markdown instruction sets as operational playbooks, the threat actor conducted automated scanning and credential harvesting, compromising thousands of third-party credentials," the researchers said. "The agent instructions enabled the AI to autonomously manage the vulnerability scanning pipeline, perform real-time troubleshooting, and execute Internet Protocol (IP) rotation logic without manual intervention — significantly reducing the human-in-the-loop latency."
GTIG also uncovered an automated reconnaissance and credential management framework called Recon that was being used on a live command-and-control server to manage more than 23,000 stolen credentials, including API keys for cloud infrastructure and AI services. A Chinese threat actor known for targeting government organizations was additionally observed building an AI-powered exploitation and post-exploitation pipeline, automating the entire attack chain from reconnaissance to credential scraping for lateral movement.
A roster of actors adopting AI
The report names a range of groups that GTIG says are incorporating AI into their operations. "GTIG continues to observe the widespread adoption and incorporation of AI technologies by threat actors with wide-ranging motivations across multiple geographic portfolios," the researchers said. "Threat actors continue to misuse Gemini to enhance all stages of their operations, from reconnaissance and phishing lure creation to C2 development and data exfiltration. Key examples from the last quarter include PRC- and Russia-nexus espionage groups; financially-motivated and espionage-related activity attributed to the Democratic People's Republic of Korea (DPRK); financially-motivated cyber crime groups; and state-sponsored IO [influence operations] groups."
Among the groups cited in the report are:
- BASIN CASTLE, a China-based group also known as BASIN or TEMP.Hex
- CALANQUE ION, an Iranian state-sponsored actor also tracked as APT42
- RAVINE CASTLE, a Chinese cyber espionage group also known as COULEE or APT24
- SANDWORM RELIC, a Russian state-linked cyber espionage actor also known as SANDWORM and APT44
- UNC6240, a data theft extortion group also known as ShinyHunters
- MIDNIGHT NEPTUNE aka UNC1069, a North Korean threat group known for stealing cryptocurrency
The breadth of that list, spanning China, Iran, Russia, North Korea, and criminal extortion crews, indicates that interest in AI assets is not confined to a single geopolitical adversary or a single type of criminal operation.
The economics of stolen AI access
Underlying much of this activity is a practical problem for attackers: AI tools cost money. Premium model access and high-performance compute are expensive, and that cost acts as a barrier for groups seeking to operationalize AI in their operations.
"In order to experiment with generative AI tools, threat actors must obtain and maintain access to those tools," the researchers explain. "The cost of premium model access and high-performance compute is one of the primary barriers for threat actors seeking to operationalize AI. This has resulted in increased targeting, exfiltration, and sale of AI accounts across cyber crime communities coupled with a growing number of intrusions involving the compromise of enterprise cloud environments to hijack compute resources (aka 'LLMJacking')."
The term LLMJacking describes the hijacking of cloud compute resources specifically to run large language model workloads. It turns a victim's cloud bill into an attacker's subsidy, and it can be difficult to distinguish from ordinary, legitimate usage patterns.
What the findings mean for defenders
The picture that emerges from the report is one in which AI assets — models, prompts, pipelines, and the credentials that connect them — have taken a place alongside more traditional targets such as email accounts and administrative cloud keys. If the findings hold, organizations that use AI services, even indirectly through partners or customers, could face a class of credential theft and resource hijacking that is designed to look legitimate on the surface.
That could make conventional detection harder. Abuse of model access through legitimate API keys may not trigger the same alarms as a brute-force login or a known malware signature, which suggests security teams may need to extend monitoring to AI API usage, cloud compute quotas, and the service accounts that tie them together.
For companies without frontier models of their own, the immediate risk may be less about protecting model weights and more about securing the credentials and pipelines connected to third-party AI services. Those assets can be used to launch distillation campaigns or automated attacks, and the victim may not notice until usage bills spike or a partner raises a complaint.
The advisory from the NSA, FBI, and CISA indicates that governments are already treating parts of this activity as a national security matter. For businesses, the practical takeaway is that the boundaries between AI security, cloud security, and credential security are blurring — and that the credentials tied to AI services may deserve the same scrutiny as any other high-value account.
Sources
- CSO Online Original source
- an advisory Also reporting
Continue Reading
AI & MLNewChina's security chief turns AI critic
China's state security minister warns AI poses risks to social order, as Beijing rolls out a new governance framework.
Microsoft Drafts AI Rules for Cyber Defense
A new draft code of conduct would block its MAI models from generating working exploit code while opening a review track for defensive security work.
Huang's Foldable Moment Ties AI to Device Politics
Jensen Huang's stage call with Trump at All-In mixed AI safety talk with a foldable-phone correction, raising questions about attention and accuracy.