Map
7 of 34 records carry a stated location and appear on the map; 27 do not and are listed below, never plotted. 12 points in total, 12 of them country-level centroids. Every point states its role, the basis it rests on and the publisher that stated it. Nothing is geocoded from a country list or an actor name.
Records with stated map points
Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflow
Reported · Primary sourcing · AI significant · Medium severity
- origin: North Korea (state sponsor, per Microsoft Threat Intelligence) (illustrative, country-level centroid; sponsor attribution, per Microsoft Threat Intelligence; KP)
North Korean IT-worker remote-employment fraud using Claude
Confirmed · Primary sourcing · AI significant · High severity
- origin: North Korea (state sponsor, per Anthropic) (illustrative, country-level centroid; sponsor attribution, per Anthropic; KP)
- target: United States (victim employers, per Anthropic) (illustrative, country-level centroid; victim location, per Anthropic; US)
GTG-1002 AI-orchestrated cyber-espionage campaign
Confirmed · Primary sourcing · AI load-bearing · High severity
- origin: China (state sponsor, per Anthropic) (illustrative, country-level centroid; sponsor attribution, per Anthropic; CN)
GTG-5004 AI-assisted ransomware-as-a-service operation
Confirmed · Primary sourcing · AI significant · High severity
- origin: United Kingdom (actor location, per Anthropic) (illustrative, country-level centroid; actor location, per Anthropic; GB)
Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024)
Confirmed · Primary sourcing · AI incidental · Medium severity
- origin: Russia (state sponsor of Forest Blizzard, per Microsoft) (illustrative, country-level centroid; sponsor attribution, per Microsoft Threat Intelligence; RU)
- origin: North Korea (state sponsor of Emerald Sleet, per Microsoft) (illustrative, country-level centroid; sponsor attribution, per Microsoft Threat Intelligence; KP)
- origin: Iran (state sponsor of Crimson Sandstorm, per Microsoft) (illustrative, country-level centroid; sponsor attribution, per Microsoft Threat Intelligence; IR)
- origin: China (state sponsor of Charcoal Typhoon and Salmon Typhoon, per Microsoft) (illustrative, country-level centroid; sponsor attribution, per Microsoft Threat Intelligence; CN)
OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portal
Confirmed · Primary sourcing · AI load-bearing · Medium severity
- target: Australia (Services Australia portal, per the Prime Minister) (illustrative, country-level centroid; victim location, per Prime Minister of Australia; AU)
PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine
Confirmed · Primary sourcing · AI load-bearing · High severity
- origin: Russia (state sponsor of APT28, per GTIG) (illustrative, country-level centroid; sponsor attribution, per Google Threat Intelligence Group; RU)
- target: Ukraine (target, per GTIG) (illustrative, country-level centroid; victim location, per Google Threat Intelligence Group; UA)
Records without a stated location
- Amazon Q Developer VS Code extension compromise (data-wiping prompt injection) — disclosed · Confirmed · Primary sourcing · AI significant · High severity
- Anthropic cybersecurity-evaluation agents reached real third-party systems (four incidents, 2026) — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
- CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration — disclosed · Reported · Primary sourcing · AI load-bearing · Critical severity
- ClawHavoc: large-scale poisoning of the OpenClaw ClawHub skill marketplace with credential-stealing skills — disclosed · Confirmed · Primary sourcing · AI incidental · High severity
- Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release — disclosed · Confirmed · Primary sourcing · AI significant · High severity
- EchoLeak — zero-click prompt injection in Microsoft 365 Copilot — disclosed · Confirmed · Primary sourcing · AI load-bearing · Critical severity
- ForcedLeak — indirect prompt injection in Salesforce Agentforce — disclosed · Reported · Primary sourcing · AI load-bearing · Critical severity
- Prompt injection of Grok drained a Grok-linked crypto wallet via the Bankr trading agent — disclosed · Reported · Secondary sourcing · AI load-bearing · Medium severity
- GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
- GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus) — disclosed · Confirmed · Primary sourcing · AI significant · High severity
- GTG-2002 'vibe hacking' AI-driven data-extortion operation — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
- GTG-50014 ShinyHunters-linked agentic mass data theft and extortion — disclosed · Confirmed · Primary sourcing · AI load-bearing · Critical severity
- GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys — disclosed · Confirmed · Primary sourcing · AI significant · High severity
- GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets — disclosed · Confirmed · Primary sourcing · AI significant · High severity
- GTIG: criminal actor's AI-developed zero-day exploit against a web-based system administration tool — disclosed · Reported · Primary sourcing · AI significant · Medium severity
- hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects — disclosed · Confirmed · Primary sourcing · AI disputed · Medium severity
- JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment — disclosed · Reported · Primary sourcing · AI significant · High severity
- Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled — disclosed · Reported · Primary sourcing · AI significant · High severity
- Morris II — self-replicating worm targeting GenAI-powered applications — disclosed · Test / evaluation · Primary sourcing · AI load-bearing · Medium severity
- Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools — disclosed · Confirmed · Primary sourcing · AI significant · Critical severity
- OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructure — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
- OpenClaw agent deleted a researcher's emails and ignored stop commands — disclosed · Reported · Secondary sourcing · AI load-bearing · Low severity
- PROMPTFLUX — experimental self-modifying malware abusing the Gemini API — disclosed · Reported · Primary sourcing · AI significant · Low severity
- PromptLock — first known AI-powered ransomware (academic proof-of-concept) — disclosed · Test / evaluation · Primary sourcing · AI load-bearing · Medium severity
- PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API — disclosed · Confirmed · Primary sourcing · AI load-bearing · Medium severity
- Replit AI coding agent deleted a production database during a code freeze — disclosed · Confirmed · Secondary sourcing · AI load-bearing · High severity
- ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults) — disclosed · Reported · Primary sourcing · AI load-bearing · High severity
Basis vocabulary: Sponsor attribution — A cited source attributes the operation to a state sponsor; the point is that state's centroid. Sponsorship says nothing about where the operators sat. Origin points only. Operator location — A cited source states where the operators were located or based. Origin points only. Actor location — A cited source states an individual or criminal actor's country without claiming state sponsorship. Origin points only. Infrastructure — A cited source states where attack infrastructure was hosted. Use sparingly; hosting says little about who or where the actor is. Origin points only. Victim location — A cited source states the country or region of the target. Target points only. Stated precise location — A cited source names a precise place (city, facility) for either role. Never a centroid: illustrative must be false, and a victim site is named only if a first-party or public disclosure already named it.