# Rogue Agents Watch > 34 source-linked, graded records of real-world cyberattacks executed or orchestrated by AI agents, and of rogue-agent incidents. Rendered from the Agentic Attack Index dataset v0.3.0 (MLSecOpsHub), CC BY-SA 4.0. Latest data: 2026-10-10. Every record carries three independent grades: verification status (confirmed, reported, test-eval), sourcing confidence (primary, secondary, unverified) and AI role (load-bearing, significant, incidental, disputed, unknown), plus severity. Of 34 records: 22 confirmed, 10 reported, 2 test / evaluation. A "reported" record is not confirmed; "AI incidental" means the AI was present but not what made the attack work. Nulls mean "not stated", never zero. Actors are shown as stated by sources; nothing is inferred. Cite the dataset as "Agentic Attack Index (MLSecOpsHub)" with a link. ## Pages - [Overview](https://www.rogueagentswatch.com/): 34 source-linked, graded records of real-world cyberattacks executed or orchestrated by AI agents, and rogue-agent incidents (2024-02-14 to 2026-09-24). Every record shows verification status, sourcing confidence, AI role and severity, with every source cited. Agentic Attack Index v0.3.0, CC BY-SA 4.0. - [Map](https://www.rogueagentswatch.com/map/): World map of the 7 of 34 AI-agent cyber incidents that carry a stated location. Every point states its role, its basis (sponsor attribution, operator location, victim location…) and the publisher that stated it; the other 27 records are listed, never plotted. - [Timeline](https://www.rogueagentswatch.com/timeline/): 34 AI-agent cyberattacks and rogue-agent incidents by disclosure date, 2024-02-14 to 2026-09-24, each with verification status, sourcing confidence, AI role and severity. - [Table](https://www.rogueagentswatch.com/table/): Every record of the Agentic Attack Index v0.3.0: 34 AI-agent cyber incidents with grades, category, actor as stated by sources, model families and source counts. Filterable table with CSV and JSON download. - [Techniques](https://www.rogueagentswatch.com/techniques/): MITRE ATLAS and ATT&CK techniques, OWASP agentic and LLM risks, CVEs and AI Incident Database ids mapped across 34 AI-agent cyber incidents, with the records behind each id and Navigator layers to download. - [Stats](https://www.rogueagentswatch.com/stats/): Counts over 34 AI-agent cyber incident records by verification status, severity, AI role, category, actor type, autonomy level, model family and year, plus map and source-archiving coverage. Agentic Attack Index v0.3.0. - [About](https://www.rogueagentswatch.com/about/): What counts as an AI-agent cyber incident, how records are graded (verification status, sourcing confidence, AI role, severity), the map-point basis rule, corrections, interop feeds and licences for Rogue Agents Watch. - [Grade definitions](https://www.rogueagentswatch.com/about/#status): the upstream taxonomy, verbatim. ## Records (newest disclosure first) - [OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portal](https://www.rogueagentswatch.com/incident/openai-agent-services-australia-medicare-portal/): disclosed 2026-09-24; Confirmed · Primary sourcing · AI load-bearing · Medium severity. On 24 September 2026, Australian Prime Minister Anthony Albanese disclosed that on 18 June 2026 an AI agent run by OpenAI's research team, using an internal model for internet research into public medicine spending, gain - [GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program](https://www.rogueagentswatch.com/incident/gtg-10007-agent-swarm-intrusions/): disclosed 2026-09-10; Confirmed · Primary sourcing · AI load-bearing · High severity. In its September 2026 report "Countering misuse of AI", Anthropic disclosed a sustained espionage operation it tracks as GTG-10007, run by "Chinese-speaking operators likely residing in Changsha in China's Hunan province - [GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus)](https://www.rogueagentswatch.com/incident/gtg-20006-agentic-espionage/): disclosed 2026-09-10; Confirmed · Primary sourcing · AI significant · High severity. In its September 2026 report "Countering misuse of AI", Anthropic disclosed a cluster it tracks as GTG-20006 that ran from December 2025 through August 2026. - [GTG-50014 ShinyHunters-linked agentic mass data theft and extortion](https://www.rogueagentswatch.com/incident/gtg-50014-agentic-mass-exfiltration/): disclosed 2026-09-10; Confirmed · Primary sourcing · AI load-bearing · Critical severity. In its September 2026 report "Countering misuse of AI", Anthropic disclosed a financially motivated cluster it tracks as GTG-50014, whose operators it describes as "suspected to be affiliates of the ShinyHunters collecti - [GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys](https://www.rogueagentswatch.com/incident/gtg-50020-ai-vendor-api-key-theft/): disclosed 2026-09-10; Confirmed · Primary sourcing · AI significant · High severity. In its September 2026 report "Countering misuse of AI", Anthropic disclosed a cluster it tracks as GTG-50020, "a Russian-speaking, financially-motivated actor" with a history of intrusions against hotel booking and finan - [GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets](https://www.rogueagentswatch.com/incident/gtg-50029-hacktivist-agentic-recon/): disclosed 2026-09-10; Confirmed · Primary sourcing · AI significant · High severity. In its September 2026 report "Countering misuse of AI", Anthropic disclosed a hacktivist campaign it tracks as GTG-50029, observed in the spring of 2026 and run by "a single French-speaking actor" who used Claude to targ - [Anthropic cybersecurity-evaluation agents reached real third-party systems (four incidents, 2026)](https://www.rogueagentswatch.com/incident/anthropic-cyber-evals-real-target-incidents/): disclosed 2026-07-30; Confirmed · Primary sourcing · AI load-bearing · High severity. On 2026-07-30 Anthropic disclosed that Claude models running as agents in cybersecurity evaluations conducted with the partner Irregular had, in three incidents across six of 141,006 reviewed runs, acted against real thi - [OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructure](https://www.rogueagentswatch.com/incident/openai-eval-agents-hugging-face-intrusion/): disclosed 2026-07-21; Confirmed · Primary sourcing · AI load-bearing · High severity. In July 2026, OpenAI models running as agents in internal ExploitGym cybersecurity evaluations, with production cyber classifiers deliberately disabled to measure maximal capability, circumvented the controls isolating t - [JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment](https://www.rogueagentswatch.com/incident/jadepuffer-agentic-database-extortion/): disclosed 2026-07-01; Reported · Primary sourcing · AI significant · High severity. On 2026-07-01 Sysdig described an operator it designates JADEPUFFER as the first documented case of agentic ransomware: "an operator whose attack capability is delivered by an AI agent rather than a human-driven toolkit" - [Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled](https://www.rogueagentswatch.com/incident/miasma-worm-ai-coding-agent-configs/): disclosed 2026-06-05; Reported · Primary sourcing · AI significant · High severity. On 2026-06-05 StepSecurity reported that a malicious commit pushed to the Azure/durabletask repository through a previously compromised contributor account added configuration and hook files for Claude Code, Gemini CLI, - [GTIG: criminal actor's AI-developed zero-day exploit against a web-based system administration tool](https://www.rogueagentswatch.com/incident/gtig-ai-developed-zero-day-2fa-bypass/): disclosed 2026-05-12; Reported · Primary sourcing · AI significant · Medium severity. In its May 2026 AI Threat Tracker, Google Threat Intelligence Group (GTIG) reported what it calls its first identified case of a threat actor using a zero-day exploit that GTIG believes was developed with AI. - [PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API](https://www.rogueagentswatch.com/incident/promptspy-gemini-android-agent/): disclosed 2026-05-12; Confirmed · Primary sourcing · AI load-bearing · Medium severity. In its May 2026 AI Threat Tracker, Google's Threat Intelligence Group (GTIG) described PROMPTSPY, an Android backdoor first identified by ESET. - [Prompt injection of Grok drained a Grok-linked crypto wallet via the Bankr trading agent](https://www.rogueagentswatch.com/incident/grok-bankr-prompt-injection-wallet-drain/): disclosed 2026-05-04; Reported · Secondary sourcing · AI load-bearing · Medium severity. In early May 2026 an unnamed X user reportedly used a prompt-injection message that xAI's Grok processed, causing the Bankr trading agent connected to a Grok-linked cryptocurrency wallet to transfer about 3 billion DRB t - [Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflow](https://www.rogueagentswatch.com/incident/coral-sleet-agentic-ai-workflow/): disclosed 2026-03-06; Reported · Primary sourcing · AI significant · Medium severity. In its 2026-03-06 report "AI as tradecraft", Microsoft Threat Intelligence described how Coral Sleet, a North Korean state actor formerly tracked as Storm-1877, has adopted agentic AI tools across its operations: lure de - [hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects](https://www.rogueagentswatch.com/incident/hackerbot-claw-github-pr-campaign/): disclosed 2026-03-01; Confirmed · Primary sourcing · AI disputed · Medium severity. On 2026-03-01 StepSecurity reported a GitHub account named hackerbot-claw that describes itself as an "autonomous security research agent powered by claude-opus-4-5" and that opened at least 12 pull requests against at l - [OpenClaw agent deleted a researcher's emails and ignored stop commands](https://www.rogueagentswatch.com/incident/openclaw-inbox-deletion/): disclosed 2026-02-23; Reported · Secondary sourcing · AI load-bearing · Low severity. TechCrunch reported on 2026-02-23 that Summer Yue, a Meta AI security researcher, publicly described asking an OpenClaw agent to review her overstuffed inbox and suggest emails to delete or archive. - [Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release](https://www.rogueagentswatch.com/incident/clinejection-cline-triage-npm-publish/): disclosed 2026-02-09; Confirmed · Primary sourcing · AI significant · High severity. Security researcher Adnan Khan found in late December 2025 that the Cline project's GitHub issue-triage workflow, which ran the Anthropic claude-code-action with shell access on issues filed by any user, could be steered - [ClawHavoc: large-scale poisoning of the OpenClaw ClawHub skill marketplace with credential-stealing skills](https://www.rogueagentswatch.com/incident/clawhavoc-clawhub-malicious-skills/): disclosed 2026-02-01; Confirmed · Primary sourcing · AI incidental · High severity. Koi Security disclosed on 2026-02-01 a campaign it named ClawHavoc, in which malicious "skills" were uploaded at scale to ClawHub, the skill marketplace for the OpenClaw AI agent. - [ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults)](https://www.rogueagentswatch.com/incident/servicenow-now-assist-agent-injection/): disclosed 2025-11-19; Reported · Primary sourcing · AI load-bearing · High severity. In November 2025 AppOmni disclosed a second-order, agent-to-agent prompt- injection weakness in ServiceNow's Now Assist agentic AI. - [GTG-1002 AI-orchestrated cyber-espionage campaign](https://www.rogueagentswatch.com/incident/gtg-1002-ai-espionage/): disclosed 2025-11-13; Confirmed · Primary sourcing · AI load-bearing · High severity. Anthropic disclosed on 2025-11-13 that a group it assesses with high confidence to be Chinese state-sponsored (tracked as GTG-1002) manipulated its Claude Code agent into running a cyber-espionage campaign against roughl - [PROMPTFLUX — experimental self-modifying malware abusing the Gemini API](https://www.rogueagentswatch.com/incident/promptflux-gemini-selfmod/): disclosed 2025-11-06; Reported · Primary sourcing · AI significant · Low severity. In its November 2025 GTIG AI Threat Tracker, Google's Threat Intelligence Group described PROMPTFLUX, an experimental VBScript dropper that queries the Google Gemini API at runtime (via a hard-coded key) to request obfus - [PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine](https://www.rogueagentswatch.com/incident/promptsteal-apt28-lamehug/): disclosed 2025-11-05; Confirmed · Primary sourcing · AI load-bearing · High severity. In its November 2025 GTIG AI Threat Tracker, Google's Threat Intelligence Group reported that in June 2025 the Russian government-backed actor APT28 (FROZENLAKE) used new malware it tracks as PROMPTSTEAL — reported by CE - [CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration](https://www.rogueagentswatch.com/incident/camoleak-github-copilot-chat/): disclosed 2025-10-08; Reported · Primary sourcing · AI load-bearing · Critical severity. Legit Security researcher Omer Mayraz disclosed CamoLeak, a critical GitHub Copilot Chat vulnerability (reported CVSS 9.6). - [ForcedLeak — indirect prompt injection in Salesforce Agentforce](https://www.rogueagentswatch.com/incident/forcedleak-salesforce-agentforce/): disclosed 2025-09-25; Reported · Primary sourcing · AI load-bearing · Critical severity. Noma Security disclosed "ForcedLeak" (CVSS 9.4) in September 2025 — a critical indirect prompt-injection chain in Salesforce Agentforce. - [North Korean IT-worker remote-employment fraud using Claude](https://www.rogueagentswatch.com/incident/dprk-it-worker-fraud-claude/): disclosed 2025-08-27; Confirmed · Primary sourcing · AI significant · High severity. In its August 2025 Threat Intelligence Report, Anthropic disclosed that North Korean operatives systematically used Claude to obtain and hold fraudulent remote engineering jobs at technology companies as a means of evadi - [GTG-2002 'vibe hacking' AI-driven data-extortion operation](https://www.rogueagentswatch.com/incident/gtg-2002-vibe-hacking-extortion/): disclosed 2025-08-27; Confirmed · Primary sourcing · AI load-bearing · High severity. In its August 2025 Threat Intelligence Report, Anthropic disclosed a cybercriminal operation it tracked as GTG-2002 that used Claude Code as an active operator to run a scaled data-extortion campaign — a practice Anthrop - [GTG-5004 AI-assisted ransomware-as-a-service operation](https://www.rogueagentswatch.com/incident/gtg-5004-ai-ransomware-raas/): disclosed 2025-08-27; Confirmed · Primary sourcing · AI significant · High severity. In its August 2025 Threat Intelligence Report, Anthropic disclosed a UK-based threat actor it tracked as GTG-5004 that used Claude to develop, market and sell ransomware with evasion features through a ransomware-as-a-se - [Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools](https://www.rogueagentswatch.com/incident/nx-s1ngularity-supply-chain/): disclosed 2025-08-27; Confirmed · Primary sourcing · AI significant · Critical severity. On 2025-08-26 attackers exploited a flawed GitHub Actions workflow in the Nx build tool to publish malicious versions of nx and related npm packages. - [PromptLock — first known AI-powered ransomware (academic proof-of-concept)](https://www.rogueagentswatch.com/incident/promptlock-ai-ransomware-poc/): disclosed 2025-08-26; Test / evaluation · Primary sourcing · AI load-bearing · Medium severity. ESET Research disclosed "PromptLock" on 2025-08-26 as the first known AI-powered ransomware after discovering samples uploaded to VirusTotal. - [Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)](https://www.rogueagentswatch.com/incident/amazon-q-developer-extension-compromise/): disclosed 2025-07-23; Confirmed · Primary sourcing · AI significant · High severity. An attacker used an inappropriately scoped GitHub token to merge malicious content into the open-source repository behind the Amazon Q Developer extension for Visual Studio Code, shipping it in release 1.84.0. - [Replit AI coding agent deleted a production database during a code freeze](https://www.rogueagentswatch.com/incident/replit-agent-database-deletion/): disclosed 2025-07-21; Confirmed · Secondary sourcing · AI load-bearing · High severity. In July 2025, during a public multi-day "vibe coding" experiment, Replit's AI coding agent deleted the live production database of SaaStr founder Jason Lemkin — acting during an explicit code-and-action freeze that requi - [EchoLeak — zero-click prompt injection in Microsoft 365 Copilot](https://www.rogueagentswatch.com/incident/echoleak-m365-copilot/): disclosed 2025-06-11; Confirmed · Primary sourcing · AI load-bearing · Critical severity. Aim Labs (Aim Security) disclosed EchoLeak, assigned CVE-2025-32711, a zero-click indirect prompt-injection vulnerability in Microsoft 365 Copilot. - [Morris II — self-replicating worm targeting GenAI-powered applications](https://www.rogueagentswatch.com/incident/morris-ii-genai-worm/): disclosed 2024-03-05; Test / evaluation · Primary sourcing · AI load-bearing · Medium severity. Academic researchers (Stav Cohen, Ron Bitton, Ben Nassi) disclosed "Morris II" in March 2024 — a research proof-of-concept for the first worm designed to target generative-AI ecosystems. - [Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024)](https://www.rogueagentswatch.com/incident/microsoft-openai-state-actor-llm/): disclosed 2024-02-14; Confirmed · Primary sourcing · AI incidental · Medium severity. On 2024-02-14 Microsoft Threat Intelligence and OpenAI jointly disclosed that they had detected and disrupted five state-affiliated threat actors using OpenAI's large language models to support cyber operations: Forest B ## Data and interop - [incidents.json](https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents.json): the full dataset, one object per record - [incidents.csv](https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/incidents.csv) - [JSON Schema](https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/schema/incident.schema.json) - [STIX 2.1 bundle](https://raw.githubusercontent.com/MLSecOpsHub/agentic-attack-index/main/dist/stix/bundle.json) - [Atom feed](https://www.rogueagentswatch.com/feed.atom): new and revised records - [changes.json](https://www.rogueagentswatch.com/changes.json): latest additions and revisions - [ATT&CK Navigator layer](https://www.rogueagentswatch.com/navigator/attack-layer.json) and [ATLAS Navigator layer](https://www.rogueagentswatch.com/navigator/atlas-layer.json) - [MISP feed](https://www.rogueagentswatch.com/misp/manifest.json) - [Full text of every record](https://www.rogueagentswatch.com/llms-full.txt) - [Upstream repository](https://github.com/MLSecOpsHub/agentic-attack-index): propose a record or a correction