The notice arrived after dark. Andrew Kopcienski, a principal threat intelligence analyst at Google, wrote on LinkedIn that he had been laid off “alongside a lot of other great folks at Google Threat Intelligence Group.” Within hours, other affected employees were posting their own farewells, turning a reduction Google had handled quietly into a public accounting of job cuts inside its cloud business.
The layoffs have been unfolding for roughly two weeks, according to two people familiar with the matter. They have touched the Threat Intelligence Group, one of Google’s marquee security units, which regularly publishes research on hackers and the campaigns they run. The reductions also reached Mandiant, the cybersecurity firm Google acquired in 2022, and other parts of Google Cloud, the people said. The Threat Intelligence Group was affected the day before the cuts became public.
Google did not announce the move, and it has not said how many employees lost their jobs. In at least one instance, workers were told the reduction was meant to free up resources for growth areas such as artificial intelligence, one of the people said. “We regularly evaluate our internal structures to ensure we are best positioned to meet the evolving demands of our customers and the industry,” a Google spokesperson said.
The timing is difficult to read as conventional cost-cutting. Days before the cuts surfaced, Alphabet detailed an equity raise of roughly $85 billion to fund AI infrastructure, with 2026 capital spending guided at between $180 billion and $190 billion. That is the posture of a company spending aggressively, not retrenching. The layoffs suggest a reallocation: resources pulled from established functions and pushed toward model development and compute.
The Threat Intelligence Group occupies an unusual place inside Google. Its reports on ransomware operators, state-sponsored espionage and zero-day vulnerabilities are read by security teams far beyond the company’s own customers, which gives the unit a reach that does not show up on a balance sheet. Mandiant, bought for $5.4 billion in 2022, brought Google the incident-response teams and forensic credibility that enterprise customers expect from a serious security vendor. Cutting inside those units carries a risk that is hard to quantify: security research is a talent game, and the people who publish it are scarce.
“These are the analysts the industry reads before patching,” said one former Google security employee, who asked not to be named because the person still works in the industry. “If they disperse, the knowledge doesn’t stay in one place.”
Google Cloud has leaned on security as a wedge against rivals in its battle for enterprise customers. The unit’s threat reports are a form of marketing: freely published, widely cited, they demonstrate that Google sees what attackers are doing before most companies do. Analysts said shrinking the teams that produce that research could complicate the pitch that Google Cloud is the safest place for corporate workloads, even as the company expands the AI services it sells to those same customers.
The cuts fit a pattern across the technology industry this year. Meta cut about 10% of its workforce, or roughly 8,000 people, last month. Cloudflare eliminated more than 1,100 roles as it repositions around what it calls the agentic AI transition. Coinbase and Block have tied staff reductions to a sharper focus on AI. According to Layoffs.fyi, which tracks announcements, the tech sector had recorded 116,739 job cuts across 164 companies by June 3.
Security teams have a particular reason to be nervous. Generative AI has changed the pace of the job: automated agents can scan code, write phishing campaigns and find vulnerabilities faster than human analysts can respond. Some companies argue that fewer humans are needed because AI tools do more of the work. Cloudflare’s chief executive framed his company’s cuts in exactly those terms. Google has made the same argument about its own operations, though the company declined to say how much of the reduction reflected automation.
The people closest to the cuts offer a narrower view of what was lost. Kopcienski’s post described colleagues who tracked some of the most active threat groups in the world. He said he planned to spend a few days with his family before looking for something new. His last message to his team, he wrote, was a request that they “keep hunting.”
Google’s official statement confirmed nothing about numbers and drew no explicit line to AI, even as one person familiar with the matter said the company had cited AI reinvestment in at least one case. The gap between the official language and the reported rationale is itself the story: a statement about evaluating internal structures could describe almost any reorganization, but only one explanation fits why a team that hunts hackers would be on the list.
For Alphabet, the calculation appears to be one of priorities rather than survival. The company is raising money in sizes that would have been unthinkable a year ago, selling stock to fund data centers and chip purchases, and its cloud unit is chasing backlog that roughly doubled in a single quarter, according to the company’s investor materials. Against that demand, a security research team with no direct revenue line is an easier target than a GPU cluster.
The question for Google Cloud’s customers is whether the trade-off shows up in the product. Security spending is invisible until it fails, and threat intelligence is at its most valuable before an attack lands. The analysts who produce it are now looking for work in a market where every hyperscaler and most large banks are hiring for the same skills.


