Table

Every record in the dataset with its grades, category, actor as stated by sources, model families and source count. The live table adds filters, search and CSV/JSON download.

RecordDisclosedStatusConfidenceAI roleSeverityCategoryActor (as stated)Model familiesSources
OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portalConfirmedPrimaryLoad-bearingMediumAutonomous attackOpenAI internal research agent (unnamed model) operating in an internal research/evaluation context (Lab test / evaluation)Other / unspecified4
GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery programConfirmedPrimaryLoad-bearingHighAI-orchestrated campaignChinese-speaking operators (tracked by Anthropic as GTG-10007), two identified as university undergraduates; no state sponsorship asserted (Unknown)Claude (Anthropic)1
GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus)ConfirmedPrimarySignificantHighAI-orchestrated campaignRussia-nexus espionage actor (tracked by Anthropic as GTG-20006; attribution described as consistent with public reporting on Midnight Blizzard) (Nation-state)Claude (Anthropic)1
GTG-50014 ShinyHunters-linked agentic mass data theft and extortionConfirmedPrimaryLoad-bearingCriticalAI-orchestrated campaignSuspected ShinyHunters affiliates (tracked by Anthropic as GTG-50014) (Cybercriminal)Claude (Anthropic)1
GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keysConfirmedPrimarySignificantHighInfrastructure abuse / supply chainRussian-speaking, financially motivated actor (tracked by Anthropic as GTG-50020) (Cybercriminal)Claude (Anthropic)1
GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targetsConfirmedPrimarySignificantHighAI-orchestrated campaignSingle French-speaking hacktivist (tracked by Anthropic as GTG-50029) (Single operator)Claude (Anthropic)1
Anthropic cybersecurity-evaluation agents reached real third-party systems (four incidents, 2026)ConfirmedPrimaryLoad-bearingHighAutonomous attackAnthropic evaluation agents (Claude Opus 4.7, Claude Mythos 5, an early Claude Opus 4.6 checkpoint and an internal research model) acting outside their intended scope during cybersecurity evaluations (Lab test / evaluation)Claude (Anthropic)2
OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructureConfirmedPrimaryLoad-bearingHighAutonomous attackOpenAI evaluation agents (an internal-only research model and GPT-5.6 Sol) acting without authorization during ExploitGym cyber evaluations (Lab test / evaluation)GPT (OpenAI), Other / unspecified3
JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deploymentReportedPrimarySignificantHighAutonomous attackUnknown (Unknown)Other / unspecified1
Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabledReportedPrimarySignificantHighInfrastructure abuse / supply chainTeamPCP (per StepSecurity, via command-and-control infrastructure linked to the same account's earlier PyPI attack; the June commit is not directly attributed) (Cybercriminal)Claude (Anthropic), Gemini (Google), Other / unspecified2
GTIG: criminal actor's AI-developed zero-day exploit against a web-based system administration toolReportedPrimarySignificantMediumAI-orchestrated campaignUnknown criminal threat actor (unnamed by GTIG), in partnership with a prominent cybercrime actor (Cybercriminal)Other / unspecified1
PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini APIConfirmedPrimaryLoad-bearingMediumAutonomous attackUnknown (Unknown)Gemini (Google)2
Prompt injection of Grok drained a Grok-linked crypto wallet via the Bankr trading agentReportedSecondaryLoad-bearingMediumAgent hijack / prompt injectionUnknown (Unknown)Other / unspecified2
Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflowReportedPrimarySignificantMediumAI-orchestrated campaignCoral Sleet (North Korean state actor, formerly Storm-1877, per Microsoft Threat Intelligence) (Nation-state)Other / unspecified1
hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projectsConfirmedPrimaryDisputedMediumAutonomous attackUnknown (Unknown)Claude (Anthropic)2
OpenClaw agent deleted a researcher's emails and ignored stop commandsReportedSecondaryLoad-bearingLowAutonomous attackOpenClaw agent (autonomous) (Unknown)Other / unspecified1
Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm releaseConfirmedPrimarySignificantHighAgent hijack / prompt injectionUnknown (an "unauthorized party" per Cline; the researcher states a different actor reused his proof-of-concept) (Unknown)Claude (Anthropic)2
ClawHavoc: large-scale poisoning of the OpenClaw ClawHub skill marketplace with credential-stealing skillsConfirmedPrimaryIncidentalHighInfrastructure abuse / supply chainUnknown (operators identified only by ClawHub handles; financially motivated per Antiy CERT) (Cybercriminal)Other / unspecified2
ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults)ReportedPrimaryLoad-bearingHighAgent hijack / prompt injectionAppOmni (AO Labs) (Researcher)Other / unspecified2
GTG-1002 AI-orchestrated cyber-espionage campaignConfirmedPrimaryLoad-bearingHighAI-orchestrated campaignChinese state-sponsored group (tracked by Anthropic as GTG-1002) (Nation-state)Claude (Anthropic)2
PROMPTFLUX — experimental self-modifying malware abusing the Gemini APIReportedPrimarySignificantLowInfrastructure abuse / supply chainUnknown (Unknown)Gemini (Google)3
PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against UkraineConfirmedPrimaryLoad-bearingHighAI-orchestrated campaignAPT28 (FROZENLAKE), Russian government-backed (Nation-state)Qwen (Alibaba)2
CamoLeak — GitHub Copilot Chat prompt-injection data exfiltrationReportedPrimaryLoad-bearingCriticalAgent hijack / prompt injectionOmer Mayraz (Legit Security) (Researcher)Other / unspecified2
ForcedLeak — indirect prompt injection in Salesforce AgentforceReportedPrimaryLoad-bearingCriticalAgent hijack / prompt injectionNoma Security (Noma Labs) (Researcher)Other / unspecified3
North Korean IT-worker remote-employment fraud using ClaudeConfirmedPrimarySignificantHighInfrastructure abuse / supply chainNorth Korean operatives (DPRK IT workers) (Nation-state)Claude (Anthropic)2
GTG-2002 'vibe hacking' AI-driven data-extortion operationConfirmedPrimaryLoad-bearingHighAI-orchestrated campaignUnknown cybercriminal (tracked by Anthropic as GTG-2002) (Cybercriminal)Claude (Anthropic)2
GTG-5004 AI-assisted ransomware-as-a-service operationConfirmedPrimarySignificantHighInfrastructure abuse / supply chainUK-based threat actor (tracked by Anthropic as GTG-5004) (Single operator)Claude (Anthropic)2
Nx 's1ngularity' npm supply-chain attack weaponising AI CLI toolsConfirmedPrimarySignificantCriticalInfrastructure abuse / supply chainUnknown (Unknown)Claude (Anthropic), Gemini (Google), Other / unspecified3
PromptLock — first known AI-powered ransomware (academic proof-of-concept)Test / evaluationPrimaryLoad-bearingMediumLab escape / evaluationNYU Tandon School of Engineering research team (Researcher)GPT (OpenAI)2
Amazon Q Developer VS Code extension compromise (data-wiping prompt injection)ConfirmedPrimarySignificantHighInfrastructure abuse / supply chainlkmanka58 (Single operator)Other / unspecified2
Replit AI coding agent deleted a production database during a code freezeConfirmedSecondaryLoad-bearingHighAutonomous attackReplit AI agent (autonomous) (Unknown)Other / unspecified3
EchoLeak — zero-click prompt injection in Microsoft 365 CopilotConfirmedPrimaryLoad-bearingCriticalAgent hijack / prompt injectionAim Labs (Aim Security) (Researcher)GPT (OpenAI)3
Morris II — self-replicating worm targeting GenAI-powered applicationsTest / evaluationPrimaryLoad-bearingMediumLab escape / evaluationResearchers (Cohen, Bitton, Nassi — Technion / Intuit / Cornell Tech) (Researcher)GPT (OpenAI), Gemini (Google), Other / unspecified3
Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024)ConfirmedPrimaryIncidentalMediumInfrastructure abuse / supply chainFive state-affiliated actors: Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, Salmon Typhoon (Nation-state)GPT (OpenAI)3

Downloads of the full dataset: incidents.json, incidents.csv, STIX 2.1 bundle.