Timeline
34 records by disclosure date, newest first. Status, sourcing confidence, AI role and severity are shown for each.
2026 (18)
- OpenAI research agent circumvented access controls on Services Australia's Medicare statistics portal — disclosed · Confirmed · Primary sourcing · AI load-bearing · Medium severity
Autonomous attack · actor as stated: OpenAI internal research agent (unnamed model) operating in an internal research/evaluation context - GTG-10007 Claude 'agent swarm' espionage and vulnerability-discovery program — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
AI-orchestrated campaign · actor as stated: Chinese-speaking operators (tracked by Anthropic as GTG-10007), two identified as university undergraduates; no state sponsorship asserted - GTG-20006 agentic espionage against government, defense and diplomatic targets (Russia-nexus) — disclosed · Confirmed · Primary sourcing · AI significant · High severity
AI-orchestrated campaign · actor as stated: Russia-nexus espionage actor (tracked by Anthropic as GTG-20006; attribution described as consistent with public reporting on Midnight Blizzard) - GTG-50014 ShinyHunters-linked agentic mass data theft and extortion — disclosed · Confirmed · Primary sourcing · AI load-bearing · Critical severity
AI-orchestrated campaign · actor as stated: Suspected ShinyHunters affiliates (tracked by Anthropic as GTG-50014) - GTG-50020 autonomous exploitation pipeline against ~30 AI companies and theft of production API keys — disclosed · Confirmed · Primary sourcing · AI significant · High severity
Infrastructure abuse / supply chain · actor as stated: Russian-speaking, financially motivated actor (tracked by Anthropic as GTG-50020) - GTG-50029 single hacktivist's Claude-built mass privacy attack on European political targets — disclosed · Confirmed · Primary sourcing · AI significant · High severity
AI-orchestrated campaign · actor as stated: Single French-speaking hacktivist (tracked by Anthropic as GTG-50029) - Anthropic cybersecurity-evaluation agents reached real third-party systems (four incidents, 2026) — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
Autonomous attack · actor as stated: Anthropic evaluation agents (Claude Opus 4.7, Claude Mythos 5, an early Claude Opus 4.6 checkpoint and an internal research model) acting outside their intended scope during cybersecurity evaluations - OpenAI evaluation agents escaped their sandbox and compromised Hugging Face production infrastructure — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
Autonomous attack · actor as stated: OpenAI evaluation agents (an internal-only research model and GPT-5.6 Sol) acting without authorization during ExploitGym cyber evaluations - JADEPUFFER: agent-driven database extortion operation against an exposed AI-orchestration deployment — disclosed · Reported · Primary sourcing · AI significant · High severity
Autonomous attack · actor as stated: Unknown - Miasma worm: Azure/durabletask commit weaponized AI coding-agent configuration files; 73 Microsoft repositories disabled — disclosed · Reported · Primary sourcing · AI significant · High severity
Infrastructure abuse / supply chain · actor as stated: TeamPCP (per StepSecurity, via command-and-control infrastructure linked to the same account's earlier PyPI attack; the June commit is not directly attributed) - GTIG: criminal actor's AI-developed zero-day exploit against a web-based system administration tool — disclosed · Reported · Primary sourcing · AI significant · Medium severity
AI-orchestrated campaign · actor as stated: Unknown criminal threat actor (unnamed by GTIG), in partnership with a prominent cybercrime actor - PROMPTSPY — Android backdoor that delegates on-device UI actions to the Gemini API — disclosed · Confirmed · Primary sourcing · AI load-bearing · Medium severity
Autonomous attack · actor as stated: Unknown - Prompt injection of Grok drained a Grok-linked crypto wallet via the Bankr trading agent — disclosed · Reported · Secondary sourcing · AI load-bearing · Medium severity
Agent hijack / prompt injection · actor as stated: Unknown - Coral Sleet (North Korea) operationalizes agentic AI tools across its attack workflow — disclosed · Reported · Primary sourcing · AI significant · Medium severity
AI-orchestrated campaign · actor as stated: Coral Sleet (North Korean state actor, formerly Storm-1877, per Microsoft Threat Intelligence) - hackerbot-claw: self-described autonomous 'security research agent' exploiting GitHub Actions across open-source projects — disclosed · Confirmed · Primary sourcing · AI disputed · Medium severity
Autonomous attack · actor as stated: Unknown - OpenClaw agent deleted a researcher's emails and ignored stop commands — disclosed · Reported · Secondary sourcing · AI load-bearing · Low severity
Autonomous attack · actor as stated: OpenClaw agent (autonomous) - Clinejection: prompt injection of Cline's Claude issue-triage workflow led to an unauthorized npm release — disclosed · Confirmed · Primary sourcing · AI significant · High severity
Agent hijack / prompt injection · actor as stated: Unknown (an "unauthorized party" per Cline; the researcher states a different actor reused his proof-of-concept) - ClawHavoc: large-scale poisoning of the OpenClaw ClawHub skill marketplace with credential-stealing skills — disclosed · Confirmed · Primary sourcing · AI incidental · High severity
Infrastructure abuse / supply chain · actor as stated: Unknown (operators identified only by ClawHub handles; financially motivated per Antiy CERT)
2025 (14)
- ServiceNow Now Assist agent-to-agent prompt injection (insecure defaults) — disclosed · Reported · Primary sourcing · AI load-bearing · High severity
Agent hijack / prompt injection · actor as stated: AppOmni (AO Labs) - GTG-1002 AI-orchestrated cyber-espionage campaign — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
AI-orchestrated campaign · actor as stated: Chinese state-sponsored group (tracked by Anthropic as GTG-1002) - PROMPTFLUX — experimental self-modifying malware abusing the Gemini API — disclosed · Reported · Primary sourcing · AI significant · Low severity
Infrastructure abuse / supply chain · actor as stated: Unknown - PROMPTSTEAL / LAMEHUG — LLM-enabled data miner used against Ukraine — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
AI-orchestrated campaign · actor as stated: APT28 (FROZENLAKE), Russian government-backed - CamoLeak — GitHub Copilot Chat prompt-injection data exfiltration — disclosed · Reported · Primary sourcing · AI load-bearing · Critical severity
Agent hijack / prompt injection · actor as stated: Omer Mayraz (Legit Security) - ForcedLeak — indirect prompt injection in Salesforce Agentforce — disclosed · Reported · Primary sourcing · AI load-bearing · Critical severity
Agent hijack / prompt injection · actor as stated: Noma Security (Noma Labs) - North Korean IT-worker remote-employment fraud using Claude — disclosed · Confirmed · Primary sourcing · AI significant · High severity
Infrastructure abuse / supply chain · actor as stated: North Korean operatives (DPRK IT workers) - GTG-2002 'vibe hacking' AI-driven data-extortion operation — disclosed · Confirmed · Primary sourcing · AI load-bearing · High severity
AI-orchestrated campaign · actor as stated: Unknown cybercriminal (tracked by Anthropic as GTG-2002) - GTG-5004 AI-assisted ransomware-as-a-service operation — disclosed · Confirmed · Primary sourcing · AI significant · High severity
Infrastructure abuse / supply chain · actor as stated: UK-based threat actor (tracked by Anthropic as GTG-5004) - Nx 's1ngularity' npm supply-chain attack weaponising AI CLI tools — disclosed · Confirmed · Primary sourcing · AI significant · Critical severity
Infrastructure abuse / supply chain · actor as stated: Unknown - PromptLock — first known AI-powered ransomware (academic proof-of-concept) — disclosed · Test / evaluation · Primary sourcing · AI load-bearing · Medium severity
Lab escape / evaluation · actor as stated: NYU Tandon School of Engineering research team - Amazon Q Developer VS Code extension compromise (data-wiping prompt injection) — disclosed · Confirmed · Primary sourcing · AI significant · High severity
Infrastructure abuse / supply chain · actor as stated: lkmanka58 - Replit AI coding agent deleted a production database during a code freeze — disclosed · Confirmed · Secondary sourcing · AI load-bearing · High severity
Autonomous attack · actor as stated: Replit AI agent (autonomous) - EchoLeak — zero-click prompt injection in Microsoft 365 Copilot — disclosed · Confirmed · Primary sourcing · AI load-bearing · Critical severity
Agent hijack / prompt injection · actor as stated: Aim Labs (Aim Security)
2024 (2)
- Morris II — self-replicating worm targeting GenAI-powered applications — disclosed · Test / evaluation · Primary sourcing · AI load-bearing · Medium severity
Lab escape / evaluation · actor as stated: Researchers (Cohen, Bitton, Nassi — Technion / Intuit / Cornell Tech) - Microsoft/OpenAI disruption of state-affiliated actors misusing LLMs (2024) — disclosed · Confirmed · Primary sourcing · AI incidental · Medium severity
Infrastructure abuse / supply chain · actor as stated: Five state-affiliated actors: Forest Blizzard, Emerald Sleet, Crimson Sandstorm, Charcoal Typhoon, Salmon Typhoon