Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Entities

National security and intelligence stakeholders

Incidents Harmed By

Incident 111839 Report
Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

2021-01-01

North Korean operatives have reportedly used AI-generated identities to secure remote jobs or impersonate employers in order to infiltrate companies. These tactics allegedly support sanctions evasion through wage theft, credential exfiltration, and malware deployment. Workers reportedly use fake resumes, VPNs, and face-altering tools; some deploy malware like OtterCookie after embedding, while others lure targets via spoofed job interviews. AI systems are reportedly used to generate fake resumes, alter profile photos, and assist in real-time responses during video interviews.

More

Incident 126327 Report
Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

2025-11-13

Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.

More

Incident 54317 Report
Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

2023-05-22

A Twitter/X account allegedly impersonating Bloomberg reportedly posted an image falsely showing an explosion near the Pentagon. Analysts reportedly described the image as likely AI-generated. The post reportedly spread through major accounts before officials confirmed no incident occurred. Markets reportedly dipped during the short period when the hoax circulated.

More

Incident 10545 Report
Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

2025-04-23

In April 2025, Anthropic published a report detailing several misuse cases involving its Claude LLM, all detected in March. These included an "influence-as-a-service" operation that orchestrated over 100 social media bots; an effort to scrape and test leaked credentials for security camera access; a recruitment fraud campaign targeting Eastern Europe; and a novice actor developing sophisticated malware. Anthropic banned the accounts involved but could not confirm downstream deployment.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Misinformation spreaders

Incidents involved as Deployer
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

More
Entity

Disinformation spreaders

Incidents involved as Deployer
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

More
Entity

Unknown malicious actors

Incidents involved as Deployer
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

Unknown AI image generator developer

Incidents involved as Developer
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

Unknown deepfake technology

Incidents involved as Developer
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

Twitter Users

Incidents Harmed By
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

Family of People Near Pentagon

Incidents Harmed By
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

Investors

Incidents Harmed By
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

General public

Incidents Harmed By
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

General public of the United States

Incidents Harmed By
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

Truth

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

Epistemic integrity

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

Unknown AI image generator

Incidents implicated systems
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

X (Twitter)

Incidents implicated systems
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

Social media platforms

Incidents implicated systems
  • Incident 543
    17 Reports

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

More
Entity

Yahoo Boys

Incidents involved as Deployer
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Scammers from West Africa

Incidents involved as Deployer
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Scammers from Nigeria

Incidents involved as Deployer
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Scammers from Morocco

Incidents involved as Deployer
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Scammers from Ghana

Incidents involved as Deployer
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Brouteurs

Incidents involved as Deployer
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Unknown deepfake technology developers

Incidents involved as Developer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Unknown voice cloning technology developers

Incidents involved as Developer
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Widows

Incidents Harmed By
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Matthew W. McFarlane

Incidents Harmed By
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Impersonated American military officials

Incidents Harmed By
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Emotionally vulnerable individuals

Incidents Harmed By
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

American widows

Incidents Harmed By
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

More
Entity

Unknown voice cloning technology

Incidents implicated systems
  • Incident 912
    2 Reports

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Unknown cybercriminals

Incidents involved as Deployer
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Influence-as-a-service operators

Incidents involved as Deployer
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

Anthropic

Incidents involved as Developer
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

social media users

Incidents Harmed By
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

People targeted by malware

Incidents Harmed By
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

Job seekers in Eastern Europe

Incidents Harmed By
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

IoT security camera owners

Incidents Harmed By
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

LLM-enhanced malware toolkits

Incidents implicated systems
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

Claude AI models

Incidents implicated systems
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

Claude

Incidents implicated systems
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

AI-generated social media bots

Incidents implicated systems
  • Incident 1054
    5 Reports

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

More
Entity

Unknown disinformation actors

Incidents involved as Deployer
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

More
Entity

Unknown disinformation actor targeting Paul Kagame

Incidents involved as Deployer
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

More
Entity

Unknown deepfake technology developer

Incidents involved as Developer
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

More
Entity

Regional peacebuilding efforts in the African Great Lakes region

Incidents Harmed By
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

More
Entity

Paul Kagame

Incidents Harmed By
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

More
Entity

Government of Rwanda

Incidents Harmed By
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

More
Entity

General public of the Democratic Republic of the Congo

Incidents Harmed By
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

More
Entity

General public of Rwanda

Incidents Harmed By
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

More
Entity

Unknown disinformation actors targeting Royal Malaysia Police

Incidents involved as Deployer
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

More
Entity

Unknown disinformation actors in Malaysia

Incidents involved as Deployer
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

More
Entity

Tan Sri Acryl Sani Abdullah Sani

Incidents Harmed By
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

More
Entity

Royal Malaysia Police

Incidents Harmed By
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

More
Entity

General public of Malaysia

Incidents Harmed By
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

More
Entity

TikTok

Incidents implicated systems
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

More
Entity

North Korea

Incidents involved as Deployer
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Lazarus Group

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

BlueNoroff

Incidents involved as Deployer
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Unknown voice cloning technology developer

Incidents involved as Developer
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Zoom

Incidents Harmed By
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Web3

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Unnamed Web3 employee

Incidents Harmed By
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

macOS users

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Cryptocurrency infrastructure

Incidents Harmed By
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Telegram

Incidents implicated systems
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

macOS

Incidents implicated systems
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Cryptocurrency wallets

Incidents implicated systems
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

More
Entity

Yang Di

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

WaterPlum

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Wagemole

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Void Dokkaebi

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

UNC5267

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Son Un Chol

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Sok Kwang Hyok

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Sim Hyon-Sop

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Rim Un Chol

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Ri Kyong Sik

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Reconnaissance General Bureau

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

PurpleBravo

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

North Korean threat actors

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Minh Phuong Ngoc Vong

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Matthew Isaac Knoot

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Ko Chung Sok

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Kim Ye Won

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Kim Sang Man

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Kim Ryu Song

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Kim Mu Rim

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Jong Song Hwa

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Jong Kyong Chol

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Jang Chol Myong

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Hyon Chol Song

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Gwisin Gang

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Government of North Korea

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Famous Chollima

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Department 53

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Contagious Interview

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Christina Chapman

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Choe Jong Yong

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Cho Chung Pom

Incidents involved as Deployer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Unknown large language model developers

Incidents involved as Developer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

OpenAI

Incidents involved as Developer
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

Western companies

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

SSA

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Social Security Administration

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Recruitment teams

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Oleksandr Didenko

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Jiho Han

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

IRS

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Interviewees

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Internal Revenue Service

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Human resources staff

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Hiring managers

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Haoran Xu

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Employers

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Developers

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Cryptocurrency platforms

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Companies in the United States

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Chunji Jin

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Blockchain projects

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Andrew M.

Incidents Harmed By
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

WebSocket-based C2

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Video interview platforms

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Upwork

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Unknown large language models

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

remote3

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Remote admin tools

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Raspberry Pi Zero

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

OtterCookie v4

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

OtterCookie v3

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

OtterCookie

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Laptop farms

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Job boards

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

InvisibleFerret

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

GitHub

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

FTP exfiltration

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Freelance platforms

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Flashpoint-detected info-stealing malware

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Document verification systems

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Digital identity verification services

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

ChatGPT

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

BYOD (Bring Your Own Device)

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

BeaverTail

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Astrill VPN

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

ARP packet signaling

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

AgencyHill99

Incidents implicated systems
  • Incident 1118
    39 Reports

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

More
Entity

Ransomware-as-a-service actors

Incidents involved as Deployer
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

North Korean IT operatives

Incidents involved as Deployer
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Religious institutions

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Healthcare organizations

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Government agencies

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Fortune 500 technology companies

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Emergency services

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Consumers targeted by ransomware

Incidents Harmed By
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

LLM-enhanced ransomware toolkits

Incidents implicated systems
  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Claude code

Incidents implicated systems
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Agentic AI system

Incidents implicated systems
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Reports

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

More
Entity

Velvet Chollima

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

THALLIUM

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

Kimsuky Group

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

Group 0094

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

Emerald Sleet

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

Black Banshee

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

APT43

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

South Korean defense personnel

Incidents Harmed By
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

Government of South Korea

Incidents Harmed By
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

General public of South Korea

Incidents Harmed By
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

Hancom Office

Incidents implicated systems
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

More
Entity

Unknown Chinese state-sponsored entity

Incidents involved as Deployer
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

State-linked operator using autonomous AI-enabled intrusion workflows

Incidents involved as Deployer
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

GTG-1002

Incidents involved as Deployer
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Targets of autonomous AI-enabled intrusion operations

Incidents Harmed By
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Entities targeted by GTG-1002

Incidents Harmed By
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Open-source penetration testing tools

Incidents implicated systems
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Model Context Protocol (MCP)

Incidents implicated systems
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

MCP-integrated toolchain

Incidents implicated systems
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

GTG-1002's autonomous orchestration framework

Incidents implicated systems
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Autonomous AI-enabled intrusion orchestration framework

Incidents implicated systems
  • Incident 1263
    27 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2024 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 353a03d