Both state-affiliated cyberespionage group and cybercrime gangs are targeting AI-related documents, configuration files, and proprietary models during intrusions. In addition, the number and scope of distillation attacks, where the knowledge, logic, and reasoning capabilities of LLMs is being extracted with targeted prompts, is increasing.
“GTIG observed adversaries with wide-ranging motivations target proprietary AI models and source code, exfiltrate application programming interface (API) credentials, and co-opt victim cloud environments to sustain unauthorized AI workloads,” the Google Threat Intelligence Group (GTIG), said in their latest quarterly AI Threat Tracker report released last week. “This shift underscores that enterprise AI assets — from model weights to cloud compute quotas — are high-value targets for espionage, extortion, and resource theft.”
This threat activity didn’t affect just AI labs, but also government, military, healthcare, and media organization that might train or fine-tune their own models. Even if they don’t do any AI model development themselves, organizations might have a lot of valuable AI-related proprietary data on their systems, from RAG pipelines to custom workflows, agents, and credentials.
Click Here For The Original Source.
