Skip to Content
logologo
AI Incident Database
Donate
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Discover
Submit
  • Welcome to the AIID
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Spatial View
  • Blog
  • AI News Digest
  • Random Incident
  • Sign Up
Entities

Targets of autonomous AI-enabled intrusion operations

Incidents Harmed By

Incident 126334 Report
Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

2025-11-13

Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.

More

Incident 16493 Report
Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

2026-08-05

During a Meta cybersecurity evaluation conducted with Irregular, one of Meta's AI models reportedly gained unintended Internet access after an evaluation-environment misconfiguration and exploited a vulnerability in a real third-party service. The model was reportedly identified as Muse Spark 1.1, although Meta had not publicly confirmed that identification or the fuller account of what occurred inside the affected company.

More

Incident 17001 Report
Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

2026-05-01

During a May 2026 cybersecurity evaluation run by Irregular, a Google Gemini model reportedly gained unintended Internet access and accessed protected systems belonging to three real companies while pursuing fictional test targets. Google said Gemini guessed a password in one case and used credentials found in public repositories in two others, then stopped each intrusion after recognizing the targets were real. Google said no harm resulted.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Unknown Chinese state-sponsored entity

Incidents involved as Deployer
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

State-linked operator using autonomous AI-enabled intrusion workflows

Incidents involved as Deployer
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

GTG-1002

Incidents involved as Deployer
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Anthropic

Incidents involved as Developer
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

National security and intelligence stakeholders

Incidents Harmed By
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Entities targeted by GTG-1002

Incidents Harmed By
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Open-source penetration testing tools

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Model Context Protocol (MCP)

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

MCP-integrated toolchain

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

GTG-1002's autonomous orchestration framework

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Claude Code

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

Autonomous AI-enabled intrusion orchestration framework

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

More
Entity

AI agent systems

Incidents implicated systems
  • Incident 1263
    34 Reports

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1649
    3 Reports

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

More
Entity

Meta

Incidents involved as both Developer and Deployer
  • Incident 1649
    3 Reports

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

More
Entity

Irregular

Incidents involved as Deployer
  • Incident 1649
    3 Reports

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incident 1649
    3 Reports

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

AI agent system developers

Incidents involved as Developer
  • Incident 1649
    3 Reports

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

Muse Spark 1.1

Incidents implicated systems
  • Incident 1649
    3 Reports

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

More
Entity

Google

Incidents involved as both Developer and Deployer
  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

AI evaluation organizations

Incidents involved as Deployer
  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

Three unidentified companies accessed by Google Gemini during May 2026 cybersecurity evaluation

Incidents Harmed By
  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

Companies

Incidents Harmed By
  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

Gemini

Incidents implicated systems
  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

Cybersecurity AI systems

Incidents implicated systems
  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More
Entity

Large language models

Incidents implicated systems
  • Incident 1700
    1 Report

    Google Gemini Reportedly Accessed Three Real Companies' Protected Systems During Cybersecurity Evaluation

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2026 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • dd3f754