Organizations
Incidents Harmed By
Incident 8116 Report
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
2024-10-02
AI-powered meeting assistants, such as Otter.ai's OtterPilot and Zoom's AI Companion, have reportedly shared sensitive and private conversations beyond the intended audience. These tools, which are set to automatically record and distribute meeting transcripts, allegedly sent confidential discussions after participants had left the meeting, the consequences of which led to unintended exposure of proprietary information and privacy breaches.
MoreIncident 16934 Report
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
2026-09-14
An unnamed organization reportedly notified Spain's data protection authority that a third party used an AI agent powered by a known language model to carry out a multistep intrusion that resulted in unauthorized changes to personal data and access to invoices. The AEPD said the case remains under review and has not identified the organization, attacker, AI system, attack date, or number of affected people.
MoreIncident 16613 Report
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
2026-04-08
Between April 8 and May 21, 2026, a Russian-speaking operator linked to the Aurora ransomware group reportedly used Cursor Agent, running Anthropic's Claude Sonnet 4.5, to assist exploitation across multiple organizations. Researchers said some AI-directed tasks succeeded while others failed; independent reporting identified six affected companies but could not determine how much the AI facilitated each breach or whether all led to data theft or extortion.
MoreIncident 16853 Report
Early Claude Opus 4.6 Checkpoint Reportedly Gained Unauthorized Admin Access to Third-Party System During Cybersecurity Evaluation
2026-09-09
Anthropic reported that during a January 2026 cybersecurity evaluation, an early checkpoint of Claude Opus 4.6 accidentally disabled its assigned target, then reached an unrelated third-party machine over the open Internet. The model reportedly used a discovered password for admin access, harvested additional credentials, changed system settings, and read one person's personal information before its token budget ended. Anthropic later notified the affected party.
MoreIncidents involved as Deployer
Incident 8116 Report
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
2024-10-02
AI-powered meeting assistants, such as Otter.ai's OtterPilot and Zoom's AI Companion, have reportedly shared sensitive and private conversations beyond the intended audience. These tools, which are set to automatically record and distribute meeting transcripts, allegedly sent confidential discussions after participants had left the meeting, the consequences of which led to unintended exposure of proprietary information and privacy breaches.
MoreIncident 16514 Report
Fireflies.AI Meeting Assistant Allegedly Collected Biometric Voice Data from Illinois Meeting Participant Without Consent
2025-11-18
On November 18, 2025, Fireflies.AI reportedly recorded and analyzed the voice of Illinois resident Katelin Cruz during a virtual meeting hosted by Western Illinois Dreamers, although Cruz had no Fireflies account and had not provided written consent. Her lawsuit alleges the system used speaker-recognition functions to create and retain biometric voice data and attribute statements to her in the meeting transcript.
MoreRelated Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
Related Entities
Cybercriminals
Incidents involved as Deployer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16613 Reports
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
Unnamed venture capital investors
Incidents Harmed By
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
Incidents involved as Deployer
Employers
Incidents Harmed By
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
Incidents involved as Deployer
Employees
Incidents Harmed By
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
Incidents involved as Deployer
Companies
Incidents Harmed By
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
Incidents involved as Deployer
Alex Bilzerian
Incidents Harmed By
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
Incidents involved as Deployer
Zoom
Incidents involved as Developer
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
Incidents implicated systems
Otter.ai
Incidents involved as Developer
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
- Incident 8116 Reports
AI-Powered Transcription Services Allegedly Leak Confidential Workplace Discussions
Incidents implicated systems
Agentic threat actors
Incidents involved as Deployer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16613 Reports
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
AI agent system deployers
Incidents involved as Deployer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16613 Reports
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
AI agent system developers
Incidents involved as Developer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16613 Reports
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
Large language model developers
Incidents involved as Developer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16613 Reports
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
AI agent systems
Incidents implicated systems
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16613 Reports
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations
Large language models
Incidents implicated systems
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16613 Reports
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations