Stats
Counts over the 34 records of dataset v0.3.0, taken verbatim from the upstream summary. Every figure is a number of records; a gap is a missing value upstream, never zero.
Verification status
- Confirmed
- 22
- Reported
- 10
- Test / evaluation
- 2
Severity
- High
- 18
- Medium
- 9
- Critical
- 5
- Low
- 2
AI role
- Load-bearing
- 18
- Significant
- 13
- Incidental
- 2
- Disputed
- 1
Incident category
- AI-orchestrated campaign
- 9
- Infrastructure abuse / supply chain
- 9
- Autonomous attack
- 8
- Agent hijack / prompt injection
- 6
- Lab escape / evaluation
- 2
Actor type
- Unknown
- 10
- Cybercriminal
- 6
- Nation-state
- 6
- Researcher
- 6
- Lab test / evaluation
- 3
- Single operator
- 3
Agentic autonomy level
- Not applicable
- 10
- Supervised-autonomous
- 8
- Fully-autonomous
- 7
- Tool-assisted
- 5
- Unknown
- 3
- Human-in-the-loop
- 1
Model family
- Other / unspecified
- 16
- Claude (Anthropic)
- 14
- Gemini (Google)
- 5
- GPT (OpenAI)
- 5
- Qwen (Alibaba)
- 1
Year of disclosure
- 2024
- 2
- 2025
- 14
- 2026
- 18
Map coverage
- Records with a stated location
- 7 of 34
- Points
- 12 (12 country-level centroids)
- By role
- origin 9, target 3
- By basis
- Actor location 1, Sponsor attribution 8, Victim location 3
Source archiving
- Source URLs
- 69
- With an archived copy
- 61 (88%)