Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Entities

AI agent system developers

Incidents involved as Developer

Incident 15784 Report
LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

2026-07-01

Sysdig reported that a ransomware operator it dubbed JADEPUFFER used an LLM-driven agent to turn access through a vulnerable internet-facing Langflow deployment into a database-extortion operation. The report said the activity reached a production database server and produced concrete disruption, with the victim environment allegedly left in a damaged and unrecoverable state alongside a ransom demand.

More

Incident 16043 Report
OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

2026-07-11

OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.

More

Incident 15562 Report
X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

2026-05-04

An X user reportedly induced Grok and Bankrbot to transfer 3 billion DRB tokens, then valued at about $200,000. After reportedly sending a Bankr Club Membership NFT to Grok's wallet, the user allegedly asked Grok to translate a Morse code message and relay it to Bankrbot. The decoded instruction reportedly directed a transfer to a specified wallet, which was reportedly executed on Base. The recipient reportedly sold the tokens soon afterward; linked funds were later returned or converted.

More

Incident 15421 Report
OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

2026-02-23

Meta AI alignment director Summer Yue reported that an OpenClaw agent connected to her inbox attempted to delete emails despite instructions to seek approval and repeated commands to stop. Yue said the agent lost the instruction during context compaction, reportedly forcing her to terminate it from the Mac mini hosting it.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Summer Yue

Incidents Harmed By
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Incidents involved as Deployer
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

Peter Steinberger

Incidents involved as Developer
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

OpenClaw users

Incidents Harmed By
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

Email account holders

Incidents Harmed By
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

AI agent system users

Incidents Harmed By
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

OpenClaw

Incidents implicated systems
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

AI agent systems

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency service providers

Incidents involved as Deployer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Bankr

Incidents involved as both Developer and Deployer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

@Ilhamrfliansyh (X)

Incidents involved as Deployer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

xAI

Incidents involved as Developer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

Cryptocurrency trading system developers

Incidents involved as Developer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Chatbot developers

Incidents involved as Developer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

DRB token holders

Incidents Harmed By
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Digital asset holders

Incidents Harmed By
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency wallet owners

Incidents Harmed By
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency token holders

Incidents Harmed By
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

X (Twitter)

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Social media platforms

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Grok

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency wallets

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency trading bots

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Chatbots

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Blockchain networks

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Base

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Bankrbot

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Large language models

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

Ransomware operators

Incidents involved as Deployer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

JADEPUFFER

Incidents involved as Deployer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Cybercriminals

Incidents involved as Deployer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Agentic threat actors

Incidents involved as Deployer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Operators of Langflow deployments

Incidents Harmed By
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Database operators

Incidents Harmed By
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Ransomware

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Production database servers

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Nacos configuration service

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

MySQL databases

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Langflow

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Agentic ransomware

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Meta

Incidents involved as both Developer and Deployer
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

AI-assisted employment decision system deployers

Incidents involved as Deployer
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

AI-assisted employment decision system developers

Incidents involved as Developer
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

People with disabilities

Incidents Harmed By
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta employees

Incidents Harmed By
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Employees with disabilities

Incidents Harmed By
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Employees taking or requesting protected leave

Incidents Harmed By
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Privacy

Incidents Harmed By
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Workplace productivity monitoring systems

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Metamate

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta employee-trained second-brain AI agents

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta employee monitoring and productivity scoring system

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta algorithmically assisted performance ranking and calibration system

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta AI token-usage dashboards

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

AI-assisted employment decision systems

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Extortionists

Incidents involved as Deployer
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Victims of automated cybercrime

Incidents Harmed By
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Enterprise IT systems

Incidents Harmed By
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Amazon Web Services (AWS) customers

Incidents Harmed By
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

OpenAI

Incidents involved as both Developer and Deployer
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Incidents Harmed By
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

hugging face

Incidents Harmed By
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

GPT-5.6 Sol

Incidents implicated systems
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

Unidentified pre-release OpenAI model

Incidents implicated systems
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

AI agent system

Incidents implicated systems
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

OpenAI large language models

Incidents implicated systems
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

ExploitGym

Incidents implicated systems
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

OpenAI research testing infrastructure

Incidents implicated systems
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More
Entity

Hugging Face production infrastructure

Incidents implicated systems
  • Incident 1604
    3 Reports

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • 3e68a9f