Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Entities

Content moderation systems

Incidents implicated systems

Incident 9555 Report
Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

2024-12-19

A global cybercrime network, Storm-2139, allegedly exploited stolen credentials and developed custom tools to bypass AI safety guardrails. They reportedly generated harmful deepfake content, including nonconsensual intimate images of celebrities, and their software is reported to have disabled content moderation, hijacked AI access, and resold illicit services. Microsoft disrupted the operation and filed a lawsuit in December 2024, later identifying key members of the network in February 2025.

More

Incident 10551 Report
FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

2025-04-29

FBI Deputy Assistant Director Cynthia Kaiser stated that adversarial actors, particularly those affiliated with China and organized cybercriminal groups, are increasingly integrating AI tools across the cyberattack lifecycle, with documented use cases reportedly including purported AI-generated spear phishing, business identity fabrication, internal network mapping, and deepfake-enabled fraud. The tools are allegedly already assisting intrusions targeting U.S. infrastructure.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Unidentified Storm-2139 actor from Illinois

Incidents involved as both Developer and Deployer
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Unidentified Storm-2139 actor from Florida

Incidents involved as both Developer and Deployer
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Storm-2139

Incidents involved as both Developer and Deployer
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Ricky Yuen (cg-dot)

Incidents involved as both Developer and Deployer
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Phát Phùng Tấn (Asakuri)

Incidents involved as both Developer and Deployer
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Arian Yadegarnia (Fiz)

Incidents involved as both Developer and Deployer
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Alan Krysiak (Drago)

Incidents involved as both Developer and Deployer
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Victims of deepfake abuse

Incidents Harmed By
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

OpenAI

Incidents Harmed By
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Microsoft

Incidents Harmed By
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

celebrities

Incidents Harmed By
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Azure OpenAI customers

Incidents Harmed By
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

AI service providers

Incidents Harmed By
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Proxy and credential abuse networks

Incidents implicated systems
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Microsoft Azure OpenAI Service

Incidents implicated systems
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Generative AI platforms

Incidents implicated systems
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Azure Abuse Enterprise

Incidents implicated systems
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

API authentication mechanisms

Incidents implicated systems
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

AI safety guardrails

Incidents implicated systems
  • Incident 955
    5 Reports

    Global Cybercrime Network Storm-2139 Allegedly Exploits AI to Generate Deepfake Content

More
Entity

Government of China

Incidents involved as Deployer
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

Chinese Communist Party

Incidents involved as Deployer
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

Unknown generative AI developers

Incidents involved as Developer
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

United States critical infrastructure

Incidents Harmed By
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

Private companies

Incidents Harmed By
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

Government agencies

Incidents Harmed By
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

Employees targeted by phishing

Incidents Harmed By
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

Employees targeted by deepfake impersonations

Incidents Harmed By
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

Unknown large language models (LLMs)

Incidents implicated systems
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

Unknown deepfake technology

Incidents implicated systems
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More
Entity

Unknown automated phishing tools

Incidents implicated systems
  • Incident 1055
    1 Report

    FBI Reports AI Use by Threat Actors in Broader Cyber Context Including Infrastructure Intrusions

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 86fe0f5