Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Entities

AI agent systems

Incidents implicated systems

Incident 126334 Report
Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

2025-11-13

Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.

More

Incident 13736 Report
AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

2026-02-11

Scott Shambaugh, a matplotlib maintainer, reported that an autonomous AI coding agent using the name "MJ Rathbun" researched him and publicly posted a personalized critical blog post after his GitHub pull request was closed. The post accused him of bias and "gatekeeping" and included claims Shambaugh disputed. The agent's operator and underlying model were not identified. Shambaugh said the post risked reputational harm and could mislead readers or other agents.

More

Incident 11525 Report
LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

2025-07-18

An AI-powered development assistant on Replit's platform reportedly deleted a live production database during an active code freeze, despite receiving repeated instructions not to make changes. The system also reportedly produced fabricated test results and fake data, and incorrectly claimed rollback was impossible, delaying recovery. The incident reportedly resulted in significant data loss and user distrust regarding its safety and reliability.

More

Incident 15784 Report
LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

2026-07-01

Sysdig reported that a ransomware operator it dubbed JADEPUFFER used an LLM-driven agent to turn access through a vulnerable internet-facing Langflow deployment into a database-extortion operation. The report said the activity reached a production database server and produced concrete disruption, with the victim environment allegedly left in a damaged and unrecoverable state alongside a ransom demand.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

OpenAI

Incidents involved as both Developer and Deployer
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

More
Entity

Users of Operator

Incidents Harmed By
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

More
Entity

Geoffrey A. Fowler

Incidents Harmed By
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

More
Entity

Operator

Incidents implicated systems
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

More
Entity

Instacart

Incidents implicated systems
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

More
Entity

GPT-4

Incidents implicated systems
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

More
Entity

Replit

Incidents involved as both Developer and Deployer
  • Incident 1152
    5 Reports

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

More
Entity

SaaStr

Incidents Harmed By
  • Incident 1152
    5 Reports

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

More
Entity

Jason Lemkin

Incidents Harmed By
  • Incident 1152
    5 Reports

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

More
Entity

end users of the SaaStr database

Incidents Harmed By
  • Incident 1152
    5 Reports

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

More
Entity

developers using Replit in production environments

Incidents Harmed By
  • Incident 1152
    5 Reports

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

More
Entity

vibe coding platform

Incidents implicated systems
  • Incident 1152
    5 Reports

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

More
Entity

Replit AI agent

Incidents implicated systems
  • Incident 1152
    5 Reports

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

More
Entity

LLM-integrated code assistant

Incidents implicated systems
  • Incident 1152
    5 Reports

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

More
Entity

Ransomware-as-a-service actors

Incidents involved as Deployer
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

North Korean IT operatives

Incidents involved as Deployer
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Government of North Korea

Incidents involved as Deployer
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Cybercriminals

Incidents involved as Deployer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Anthropic

Incidents involved as Developer
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Religious institutions

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

National security and intelligence stakeholders

Incidents Harmed By
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Healthcare organizations

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Government agencies

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

General public

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Fortune 500 technology companies

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Epistemic integrity

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Emergency services

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Consumers targeted by ransomware

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

LLM-enhanced ransomware toolkits

Incidents implicated systems
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Claude Code

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Claude

Incidents implicated systems
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Unknown Chinese state-sponsored entity

Incidents involved as Deployer
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

State-linked operator using autonomous AI-enabled intrusion workflows

Incidents involved as Deployer
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

GTG-1002

Incidents involved as Deployer
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Targets of autonomous AI-enabled intrusion operations

Incidents Harmed By
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Entities targeted by GTG-1002

Incidents Harmed By
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Open-source penetration testing tools

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Model Context Protocol (MCP)

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

MCP-integrated toolchain

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

GTG-1002's autonomous orchestration framework

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Autonomous AI-enabled intrusion orchestration framework

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Unknown deployer of MJ Rathbun

Incidents involved as Deployer
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

MJ Rathbun

Incidents involved as Deployer
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Incidents implicated systems
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

OpenClaw

Incidents involved as Developer
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Incidents implicated systems
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

Moltbook

Incidents involved as Developer
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Incidents implicated systems
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

Supply-chain gatekeepers

Incidents Harmed By
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

Scott Shambaugh

Incidents Harmed By
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

Open-source maintainers

Incidents Harmed By
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

matplotlib users

Incidents Harmed By
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

GitHub users

Incidents Harmed By
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

SOUL.md

Incidents implicated systems
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

matplotlib

Incidents implicated systems
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

GitHub

Incidents implicated systems
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

More
Entity

Large language models

Incidents implicated systems
  • Incident 1373
    6 Reports

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Alexey Grigorev

Incidents involved as Deployer
  • Incident 1424
    2 Reports

    Claude Code Agent Reportedly Deleted DataTalks.Club Production Infrastructure, Database, and Snapshots via Terraform

More
Entity

DataTalks.Club users

Incidents Harmed By
  • Incident 1424
    2 Reports

    Claude Code Agent Reportedly Deleted DataTalks.Club Production Infrastructure, Database, and Snapshots via Terraform

More
Entity

DataTalks.Club

Incidents Harmed By
  • Incident 1424
    2 Reports

    Claude Code Agent Reportedly Deleted DataTalks.Club Production Infrastructure, Database, and Snapshots via Terraform

More
Entity

Terraform

Incidents implicated systems
  • Incident 1424
    2 Reports

    Claude Code Agent Reportedly Deleted DataTalks.Club Production Infrastructure, Database, and Snapshots via Terraform

More
Entity

DataTalks.Club course management platform

Incidents implicated systems
  • Incident 1424
    2 Reports

    Claude Code Agent Reportedly Deleted DataTalks.Club Production Infrastructure, Database, and Snapshots via Terraform

More
Entity

AWS RDS

Incidents implicated systems
  • Incident 1424
    2 Reports

    Claude Code Agent Reportedly Deleted DataTalks.Club Production Infrastructure, Database, and Snapshots via Terraform

More
Entity

AWS

Incidents implicated systems
  • Incident 1424
    2 Reports

    Claude Code Agent Reportedly Deleted DataTalks.Club Production Infrastructure, Database, and Snapshots via Terraform

More
Entity

Tassos M

Incidents Harmed By
  • Incident 1433
    2 Reports

    Google Antigravity Reportedly Deleted User's Entire D: Drive While Clearing Project Cache

Incidents involved as Deployer
  • Incident 1433
    2 Reports

    Google Antigravity Reportedly Deleted User's Entire D: Drive While Clearing Project Cache

More
Entity

Google

Incidents involved as both Developer and Deployer
  • Incident 1433
    2 Reports

    Google Antigravity Reportedly Deleted User's Entire D: Drive While Clearing Project Cache

More
Entity

Gemini 3-based Antigravity agent / IDE

Incidents implicated systems
  • Incident 1433
    2 Reports

    Google Antigravity Reportedly Deleted User's Entire D: Drive While Clearing Project Cache

More
Entity

Antigravity IDE

Incidents implicated systems
  • Incident 1433
    2 Reports

    Google Antigravity Reportedly Deleted User's Entire D: Drive While Clearing Project Cache

More
Entity

Nick Davidov

Incidents Harmed By
  • Incident 1441
    1 Report

    Claude Cowork Allegedly Deleted Folder Containing 15 Years of Family Photos While Organizing User's Wife's Desktop

Incidents involved as Deployer
  • Incident 1441
    1 Report

    Claude Cowork Allegedly Deleted Folder Containing 15 Years of Family Photos While Organizing User's Wife's Desktop

More
Entity

Wife of Nick Davidov

Incidents Harmed By
  • Incident 1441
    1 Report

    Claude Cowork Allegedly Deleted Folder Containing 15 Years of Family Photos While Organizing User's Wife's Desktop

More
Entity

Family of Nick Davidov

Incidents Harmed By
  • Incident 1441
    1 Report

    Claude Cowork Allegedly Deleted Folder Containing 15 Years of Family Photos While Organizing User's Wife's Desktop

More
Entity

Claude Cowork

Incidents implicated systems
  • Incident 1441
    1 Report

    Claude Cowork Allegedly Deleted Folder Containing 15 Years of Family Photos While Organizing User's Wife's Desktop

More
Entity

PocketOS

Incidents Harmed By
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

Incidents involved as Deployer
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

More
Entity

Jer Crane

Incidents involved as Deployer
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

More
Entity

Cursor

Incidents involved as Developer
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

Incidents implicated systems
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

More
Entity

Anysphere

Incidents involved as Developer
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

More
Entity

PocketOS customers

Incidents Harmed By
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

More
Entity

Car rental businesses

Incidents Harmed By
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

More
Entity

Railway API volumes

Incidents implicated systems
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

More
Entity

Railway API

Incidents implicated systems
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

More
Entity

Claude Opus 4.6

Incidents implicated systems
  • Incident 1469
    3 Reports

    PocketOS Production Database Was Reportedly Deleted by Cursor AI Agent Running Claude Opus 4.6

More
Entity

Monarch Initiative

Incidents involved as Deployer
  • Incident 1470
    1 Report

    DisMech AI Curation Agent Reportedly Completed GitHub Issue Intended as New Contributor's Learning Task

More
Entity

DisMech maintainers

Incidents involved as Deployer
  • Incident 1470
    1 Report

    DisMech AI Curation Agent Reportedly Completed GitHub Issue Intended as New Contributor's Learning Task

More
Entity

sagehrke

Incidents Harmed By
  • Incident 1470
    1 Report

    DisMech AI Curation Agent Reportedly Completed GitHub Issue Intended as New Contributor's Learning Task

More
Entity

dragon-ai-agent

Incidents implicated systems
  • Incident 1470
    1 Report

    DisMech AI Curation Agent Reportedly Completed GitHub Issue Intended as New Contributor's Learning Task

More
Entity

curation-scanner workflow

Incidents implicated systems
  • Incident 1470
    1 Report

    DisMech AI Curation Agent Reportedly Completed GitHub Issue Intended as New Contributor's Learning Task

More
Entity

Claude Opus 4.7

Incidents implicated systems
  • Incident 1470
    1 Report

    DisMech AI Curation Agent Reportedly Completed GitHub Issue Intended as New Contributor's Learning Task

More
Entity

Meta

Incidents involved as both Developer and Deployer
  • Incident 1471
    2 Reports

    Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees

  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Incidents Harmed By
  • Incident 1471
    2 Reports

    Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees

More
Entity

Meta users

Incidents Harmed By
  • Incident 1471
    2 Reports

    Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees

More
Entity

Privacy

Incidents Harmed By
  • Incident 1471
    2 Reports

    Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees

  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta internal AI agent

Incidents implicated systems
  • Incident 1471
    2 Reports

    Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees

More
Entity

Summer Yue

Incidents Harmed By
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Incidents involved as Deployer
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Peter Steinberger

Incidents involved as Developer
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

AI agent system developers

Incidents involved as Developer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

OpenClaw users

Incidents Harmed By
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

Email account holders

Incidents Harmed By
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

AI agent system users

Incidents Harmed By
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

More
Entity

Cryptocurrency service providers

Incidents involved as Deployer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Bankr

Incidents involved as both Developer and Deployer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

@Ilhamrfliansyh (X)

Incidents involved as Deployer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

xAI

Incidents involved as Developer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency trading system developers

Incidents involved as Developer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Chatbot developers

Incidents involved as Developer
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

DRB token holders

Incidents Harmed By
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Digital asset holders

Incidents Harmed By
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency wallet owners

Incidents Harmed By
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency token holders

Incidents Harmed By
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

X (Twitter)

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Social media platforms

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Grok

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency wallets

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Cryptocurrency trading bots

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Chatbots

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Blockchain networks

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Base

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Bankrbot

Incidents implicated systems
  • Incident 1556
    2 Reports

    X User Reportedly Used Morse Code Prompt to Induce Grok-Linked Trading Bot to Transfer $200,000 in Tokens

More
Entity

Ransomware operators

Incidents involved as Deployer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

JADEPUFFER

Incidents involved as Deployer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Agentic threat actors

Incidents involved as Deployer
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Operators of Langflow deployments

Incidents Harmed By
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Database operators

Incidents Harmed By
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Ransomware

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Production database servers

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Nacos configuration service

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

MySQL databases

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Langflow

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

Agentic ransomware

Incidents implicated systems
  • Incident 1578
    4 Reports

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

More
Entity

AI-assisted employment decision system deployers

Incidents involved as Deployer
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

AI-assisted employment decision system developers

Incidents involved as Developer
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

People with disabilities

Incidents Harmed By
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta employees

Incidents Harmed By
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Employees with disabilities

Incidents Harmed By
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Employees taking or requesting protected leave

Incidents Harmed By
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Workplace productivity monitoring systems

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Metamate

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta employee-trained second-brain AI agents

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta employee monitoring and productivity scoring system

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta algorithmically assisted performance ranking and calibration system

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Meta AI token-usage dashboards

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

AI-assisted employment decision systems

Incidents implicated systems
  • Incident 1584
    1 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

More
Entity

Extortionists

Incidents involved as Deployer
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Victims of automated cybercrime

Incidents Harmed By
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Enterprise IT systems

Incidents Harmed By
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Amazon Web Services (AWS) customers

Incidents Harmed By
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • Incident 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • 3e68a9f