Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Entities

hackers

Incidents involved as Deployer

Incident 1989 Report
Deepfake Video of Ukrainian President Yielding to Russia Posted on Ukrainian Websites and Social Media

2022-03-16

A quickly-debunked deepfaked video of the Ukrainian President Volodymyr Zelenskyy was posted on various Ukrainian websites and social media platforms encouraging Ukrainians to surrender to Russian forces during the Russia-Ukraine war.

More

Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

2026-07-01

From July 1–4, 2026, suspected China-linked hackers reportedly used a multi-agent framework built on Hermes and OpenClaw to compromise Taiwanese government systems. The agents reportedly compromised 85 credentials and used persistent access to connected systems to exfiltrate more than 2,564 personnel records. Taiwan later confirmed an overseas AI-assisted campaign against government agencies, without attributing it to China.

More

Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

2026-07-09

Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.

More

Incident 16703 Report
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

2026-05-10

An unidentified attacker reportedly used an LLM agent during a May 10 intrusion after exploiting a vulnerable marimo Python notebook. The agent reportedly reused harvested AWS credentials to obtain an SSH key, then pivoted through a bastion host and exfiltrated the schema and contents of an internal PostgreSQL database. Sysdig attributed the post-compromise command stream to real-time agent execution rather than a prebuilt script.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Unknown

Incidents involved as Developer
  • Incident 198
    9 Reports

    Deepfake Video of Ukrainian President Yielding to Russia Posted on Ukrainian Websites and Social Media

More
Entity

Volodymyr Zelenskyy

Incidents Harmed By
  • Incident 198
    9 Reports

    Deepfake Video of Ukrainian President Yielding to Russia Posted on Ukrainian Websites and Social Media

More
Entity

Ukrainian social media users

Incidents Harmed By
  • Incident 198
    9 Reports

    Deepfake Video of Ukrainian President Yielding to Russia Posted on Ukrainian Websites and Social Media

More
Entity

Ukrainian public

Incidents Harmed By
  • Incident 198
    9 Reports

    Deepfake Video of Ukrainian President Yielding to Russia Posted on Ukrainian Websites and Social Media

More
Entity

Meta

Incidents involved as both Developer and Deployer
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Instagram

Incidents involved as Deployer
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

Incidents implicated systems
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Chatbot developers

Incidents involved as Developer
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Sephora

Incidents Harmed By
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Privacy

Incidents Harmed By
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Meta users

Incidents Harmed By
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

John F. Bentivegna

Incidents Harmed By
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Jane Manchun Wong

Incidents Harmed By
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Instagram users

Incidents Harmed By
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Barack Obama White House Instagram account

Incidents Harmed By
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Barack Obama

Incidents Harmed By
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Social media platforms

Incidents implicated systems
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Meta AI support chatbot

Incidents implicated systems
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Meta AI

Incidents implicated systems
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Large language models

Incidents implicated systems
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Instagram account recovery system

Incidents implicated systems
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Chatbots

Incidents implicated systems
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Automated account recovery systems

Incidents implicated systems
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

AI customer support systems

Incidents implicated systems
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Enterprise AI systems

Incidents implicated systems
  • Incident 1510
    2 Reports

    Meta AI Support Bot Reportedly Enabled Takeovers of High-Profile Instagram Accounts

More
Entity

Threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

China-linked threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

More
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Agentic threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Peter Steinberger

Incidents involved as Developer
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

More
Entity

Nous Research

Incidents involved as Developer
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

AI agent system developers

Incidents involved as Developer
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Taiwanese government employees

Incidents Harmed By
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

More
Entity

Taiwanese government agencies

Incidents Harmed By
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

More
Entity

Taiwan Ministry of Justice

Incidents Harmed By
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

More
Entity

National security and intelligence stakeholders

Incidents Harmed By
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Information security

Incidents Harmed By
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Governments

Incidents Harmed By
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Government of Taiwan

Incidents Harmed By
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

More
Entity

Government agencies

Incidents Harmed By
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

OpenClaw

Incidents implicated systems
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

More
Entity

Hermes Agent

Incidents implicated systems
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

AI agent systems

Incidents implicated systems
  • Incident 1646
    4 Reports

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Cybercriminals

Incidents involved as Deployer
  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Thailand Ministry of Finance

Incidents Harmed By
  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Government of Thailand

Incidents Harmed By
  • Incident 1669
    4 Reports

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

More
Entity

Victims of automated cybercrime

Incidents Harmed By
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Enterprise IT systems

Incidents Harmed By
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Amazon Web Services (AWS) customers

Incidents Harmed By
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More
Entity

marimo

Incidents implicated systems
  • Incident 1670
    3 Reports

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • dd3f754