Table
Every record in the dataset with its grades, category, actor as stated by sources, model families and source count. The live table adds filters, search and CSV/JSON download.
| Record | Disclosed | Status | Confidence | AI role | Severity | Category | Actor (as stated) | Model families | Sources |
|---|---|---|---|---|---|---|---|---|---|
| OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portal | Confirmed | Primary | Load-bearing | Medium | Autonomous attack | OpenAI internal research agent (unnamed model) operating in an internal research/evaluation context (Lab test / evaluation) | Other / unspecified | 4 | |
| GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program | Confirmed | Primary | Load-bearing | High | AI-orchestrated campaign | Chinese-speaking operators (tracked by Anthropic as GTG-10007), two identified as university undergraduates; no state sponsorship asserted (Unknown) | Claude (Anthropic) | 1 | |
| GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus) | Confirmed | Primary | Significant | High | AI-orchestrated campaign | Russia-nexus espionage actor (tracked by Anthropic as GTG-20006; attribution described as consistent with public reporting on Midnight Blizzard) (Nation-state) | Claude (Anthropic) | 1 | |
| GTG-50014 ShinyHunters-linked agentic mass data theft and extortion | Confirmed | Primary | Load-bearing | Critical | AI-orchestrated campaign | Suspected ShinyHunters affiliates (tracked by Anthropic as GTG-50014) (Cybercriminal) | Claude (Anthropic) | 1 | |
| GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys | Confirmed | Primary | Significant | High | Infrastructure abuse / supply chain | Russian-speaking, financially motivated actor (tracked by Anthropic as GTG-50020) (Cybercriminal) | Claude (Anthropic) | 1 | |
| GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets | Confirmed | Primary | Significant | High | AI-orchestrated campaign | Single French-speaking hacktivist (tracked by Anthropic as GTG-50029) (Single operator) | Claude (Anthropic) | 1 | |
| Anthropic cybersecurity-evaluation agents reached real third-party systems (four incidents, 2026) | Confirmed | Primary | Load-bearing | High | Autonomous attack | Anthropic evaluation agents (Claude Opus 4.7, Claude Mythos 5, an early Claude Opus 4.6 checkpoint and an internal research model) acting outside their intended scope during cybersecurity evaluations (Lab test / evaluation) | Claude (Anthropic) | 2 | |
| OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructure | Confirmed | Primary | Load-bearing | High | Autonomous attack | OpenAI evaluation agents (an internal-only research model and GPT-5.6 Sol) acting without authorization during ExploitGym cyber evaluations (Lab test / evaluation) | GPT (OpenAI), Other / unspecified | 3 | |
| JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment | Reported | Primary | Significant | High | Autonomous attack | Unknown (Unknown) | Other / unspecified | 1 | |
| Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled | Reported | Primary | Significant | High | Infrastructure abuse / supply chain | TeamPCP (per StepSecurity, via command-and-control infrastructure linked to the same account's earlier PyPI attack; the June commit is not directly attributed) (Cybercriminal) | Claude (Anthropic), Gemini (Google), Other / unspecified | 2 | |
| GTIG: criminal actor's AI-developed zero-day exploit against a web-based system administration tool | Reported | Primary | Significant | Medium | AI-orchestrated campaign | Unknown criminal threat actor (unnamed by GTIG), in partnership with a prominent cybercrime actor (Cybercriminal) | Other / unspecified | 1 | |
| PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API | Confirmed | Primary | Load-bearing | Medium | Autonomous attack | Unknown (Unknown) | Gemini (Google) | 2 | |
| Prompt injection of Grok drained a Grok-linked crypto wallet via the Bankr trading agent | Reported | Secondary | Load-bearing | Medium | Agent hijack / prompt injection | Unknown (Unknown) | Other / unspecified | 2 | |
| Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflow | Reported | Primary | Significant | Medium | AI-orchestrated campaign | Coral Sleet (North Korean state actor, formerly Storm-1877, per Microsoft Threat Intelligence) (Nation-state) | Other / unspecified | 1 | |
| hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects | Confirmed | Primary | Disputed | Medium | Autonomous attack | Unknown (Unknown) | Claude (Anthropic) | 2 | |
| OpenClaw agent deleted a researcher's emails and ignored stop commands | Reported | Secondary | Load-bearing | Low | Autonomous attack | OpenClaw agent (autonomous) (Unknown) | Other / unspecified | 1 | |
| Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release | Confirmed | Primary | Significant | High | Agent hijack / prompt injection | Unknown (an "unauthorized party" per Cline; the researcher states a different actor reused his proof-of-concept) (Unknown) | Claude (Anthropic) | 2 | |
| ClawHavoc: large-scale poisoning of the OpenClaw ClawHub skill marketplace with credential-stealing skills | Confirmed | Primary | Incidental | High | Infrastructure abuse / supply chain | Unknown (operators identified only by ClawHub handles; financially motivated per Antiy CERT) (Cybercriminal) | Other / unspecified | 2 | |
| ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults) | Reported | Primary | Load-bearing | High | Agent hijack / prompt injection | AppOmni (AO Labs) (Researcher) | Other / unspecified | 2 | |
| GTG-1002 AI-orchestrated cyber-espionage campaign | Confirmed | Primary | Load-bearing | High | AI-orchestrated campaign | Chinese state-sponsored group (tracked by Anthropic as GTG-1002) (Nation-state) | Claude (Anthropic) | 2 | |
| PROMPTFLUX — experimental self-modifying malware abusing the Gemini API | Reported | Primary | Significant | Low | Infrastructure abuse / supply chain | Unknown (Unknown) | Gemini (Google) | 3 | |
| PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine | Confirmed | Primary | Load-bearing | High | AI-orchestrated campaign | APT28 (FROZENLAKE), Russian government-backed (Nation-state) | Qwen (Alibaba) | 2 | |
| CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration | Reported | Primary | Load-bearing | Critical | Agent hijack / prompt injection | Omer Mayraz (Legit Security) (Researcher) | Other / unspecified | 2 | |
| ForcedLeak — indirect prompt injection in Salesforce Agentforce | Reported | Primary | Load-bearing | Critical | Agent hijack / prompt injection | Noma Security (Noma Labs) (Researcher) | Other / unspecified | 3 | |
| North Korean IT-worker remote-employment fraud using Claude | Confirmed | Primary | Significant | High | Infrastructure abuse / supply chain | North Korean operatives (DPRK IT workers) (Nation-state) | Claude (Anthropic) | 2 | |
| GTG-2002 'vibe hacking' AI-driven data-extortion operation | Confirmed | Primary | Load-bearing | High | AI-orchestrated campaign | Unknown cybercriminal (tracked by Anthropic as GTG-2002) (Cybercriminal) | Claude (Anthropic) | 2 | |
| GTG-5004 AI-assisted ransomware-as-a-service operation | Confirmed | Primary | Significant | High | Infrastructure abuse / supply chain | UK-based threat actor (tracked by Anthropic as GTG-5004) (Single operator) | Claude (Anthropic) | 2 | |
| Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools | Confirmed | Primary | Significant | Critical | Infrastructure abuse / supply chain | Unknown (Unknown) | Claude (Anthropic), Gemini (Google), Other / unspecified | 3 | |
| PromptLock — first known AI-powered ransomware (academic proof-of-concept) | Test / evaluation | Primary | Load-bearing | Medium | Lab escape / evaluation | NYU Tandon School of Engineering research team (Researcher) | GPT (OpenAI) | 2 | |
| Amazon Q Developer VS Code extension compromise (data-wiping prompt injection) | Confirmed | Primary | Significant | High | Infrastructure abuse / supply chain | lkmanka58 (Single operator) | Other / unspecified | 2 | |
| Replit AI coding agent deleted a production database during a code freeze | Confirmed | Secondary | Load-bearing | High | Autonomous attack | Replit AI agent (autonomous) (Unknown) | Other / unspecified | 3 | |
| EchoLeak — zero-click prompt injection in Microsoft 365 Copilot | Confirmed | Primary | Load-bearing | Critical | Agent hijack / prompt injection | Aim Labs (Aim Security) (Researcher) | GPT (OpenAI) | 3 | |
| Morris II — self-replicating worm targeting GenAI-powered applications | Test / evaluation | Primary | Load-bearing | Medium | Lab escape / evaluation | Researchers (Cohen, Bitton, Nassi — Technion / Intuit / Cornell Tech) (Researcher) | GPT (OpenAI), Gemini (Google), Other / unspecified | 3 | |
| Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024) | Confirmed | Primary | Incidental | Medium | Infrastructure abuse / supply chain | Five state-affiliated actors: Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, Salmon Typhoon (Nation-state) | GPT (OpenAI) | 3 |
Downloads of the full dataset: incidents.json, incidents.csv, STIX 2.1 bundle.