A ransomware group called LunaLock has introduced a new form of cyber extortion that goes beyond traditional data leaks and encryption. The group threatens to submit stolen data directly to AI companies as training material, making the damage permanent and irreversible for victims.

How LunaLock Operates
LunaLock first appeared in September 2025 when it targeted Artists&Clients, a platform where digital artists manage client commissions. The group breached the website, encrypted all data, and demanded $50,000 from the platform. Their demand included a twist that set them apart from every other ransomware gang: they threatened to release all stolen artwork to AI companies so it could be added to training datasets for large language models.
The group’s announcement on their Tor leak site was blunt: if the ransom was not paid, they would release all data publicly, including source code and personal user data. On top of that, they would submit all artwork to AI companies to be incorporated into training sets.
Why This Matters
Traditional ransomware operates on a double extortion model: encrypt the data and threaten to leak it publicly. The threat works because leaked data fades from relevance over time and is harder for attackers to monetize once it circulates. LunaLock’s AI training threat changes the equation entirely.
Once stolen data is included in an AI model’s training set, it becomes effectively permanent. AI models do not “forget” training data the way a dark web leak eventually gets buried. The data becomes part of the model’s learned representations, accessible to anyone who queries the system. For artists, this means their original work could be reproduced by an AI system trained on their stolen creations.
The Broader AI-Driven Ransomware Landscape
LunaLock is part of a larger trend where AI tools are being weaponized by cybercriminals. In 2026, ransomware groups are using local large language models to scan internal documentation and craft perfectly targeted phishing emails. The average dwell time for AI-driven breaches has dropped from 20 days to just 4 hours, according to Cyber Correlate, a cybersecurity firm.
Traditional endpoint detection and response (EDR) tools struggle against this new class of malware. AI-driven ransomware changes its code structure on every execution (polymorphism), making signature-based detection useless. Security teams are shifting to behavioral analysis: monitoring what files do rather than what they look like.
How Artists Can Protect Themselves
Ben Zhao, a computer science professor at the University of Chicago, created Glaze and Nightshade, tools that subtly alter images so they appear normal to humans but corrupt AI training pipelines. Both tools have over 3 million downloads and are widely used by digital artists to protect their work.
Glaze applies invisible perturbations to artwork that prevent AI models from learning the artist’s style. Nightshade goes further, poisoning training data so that models trained on it produce corrupted outputs. Together, they form a defense against exactly the kind of threat LunaLock is making.
The fact that ransomware groups are now weaponizing AI training pipelines shows how the AI copyright debate has real-world consequences beyond courtrooms and policy papers. Anthropic recently settled a copyright lawsuit for at least $1.5 billion, the first major US AI-copyright case, but that has not deterred criminals from threatening to exploit the same scraping practices.
FAQ
What is LunaLock ransomware?
LunaLock is a ransomware group that emerged in September 2025. It distinguishes itself by threatening to submit stolen data to AI companies for model training, in addition to traditional encryption and data leak threats.
How is LunaLock different from other ransomware groups?
Most ransomware groups use double extortion (encryption + data leak). LunaLock adds a third layer: threatening to feed stolen data into AI training pipelines, making the damage permanent and irreversible.
What was the Artists&Clients attack?
LunaLock breached the Artists&Clients platform, stealing and encrypting artwork and user data. They demanded $50,000 and threatened to release all stolen art to AI companies if payment was not made.
Can stolen data really be used for AI training?
Yes. AI companies scrape publicly available data for training. Once stolen data is uploaded to accessible databases or submitted directly, it can be incorporated into model training sets, where it becomes effectively permanent.
What tools protect against AI data scraping?
Glaze and Nightshade, created by University of Chicago professor Ben Zhao, are widely used tools that protect artwork from AI training. They have over 3 million downloads combined.
