Google GTIG: threat actors steal model weights, API keys and hijack cloud AI workloads

ChuckDBrooks · x · 2026-09-15

A CSO Online analysis of Google Threat Intelligence Group's latest quarterly AI Threat Tracker: state-affiliated espionage groups and cybercrime gangs are stealing AI documents, configs and proprietary models, exfiltrating API credentials, and co-opting victim cloud environments to run unauthorized AI workloads. Distillation attacks — extracting LLM knowledge and reasoning via targeted prompts — are rising. Targets extend beyond AI labs to government, military, healthcare and media organizations that train or fine-tune their own models; enterprise AI assets are now high-value targets for espionage, extortion and resource theft.

Original post →

More from Safety

Safety channel →