Threat actors target enterprise AI assets at scale
🔐 Google’s GTIG reports that state-affiliated groups and cybercriminals are increasingly targeting AI-related assets — from model weights and proprietary source code to API keys and cloud compute — to support espionage, extortion, and resource theft. The quarter’s incidents included exfiltration of proprietary models, distillation campaigns using hundreds of millions of prompts, and cloud compromises that enabled attackers to run unauthorized AI workloads. Attackers also deploy automated, agent-driven frameworks to scale reconnaissance, credential harvesting, and exploitation.
