Victims of automated cybercrime
Incidents Harmed By
Incident 16934 Report
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
2026-09-14
An unnamed organization reportedly notified Spain's data protection authority that a third party used an AI agent powered by a known language model to carry out a multistep intrusion that resulted in unauthorized changes to personal data and access to invoices. The AEPD said the case remains under review and has not identified the organization, attacker, AI system, attack date, or number of affected people.
MoreIncident 10153 Report
Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform
2025-04-07
Xanthorox AI is a malicious, modular AI system released on darknet forums in early 2025. Designed from scratch for offensive cyber operations, it runs on private infrastructure and includes models for code generation, phishing, malware, social engineering, and real-time voice/image input. Its release represents a deliberate deployment of an autonomous attack platform.
MoreIncident 16703 Report
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
2026-05-10
An unidentified attacker reportedly used an LLM agent during a May 10 intrusion after exploiting a vulnerable marimo Python notebook. The agent reportedly reused harvested AWS credentials to obtain an SSH key, then pivoted through a bastion host and exfiltrated the schema and contents of an internal PostgreSQL database. Sysdig attributed the post-compromise command stream to real-time agent execution rather than a prebuilt script.
MoreIncident 15861 Report
Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion
2026-07-08
Sygnia reported that a threat actor apparently used purportedly AI-assisted or agentic workflows to move rapidly through an unidentified organization's AWS environment during an approximately 72-hour intrusion. The attacker allegedly expanded from an Internet-facing application into cloud infrastructure and data stores, reportedly stealing credentials and sensitive information while demonstrating the ability to disrupt services as leverage for extortion. Sygnia did not identify a specific model.
MoreRelated Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
Related Entities
Agentic threat actors
Incidents involved as Deployer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16703 Reports
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
Large language model developers
Incidents involved as Developer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16703 Reports
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
AI agent system developers
Incidents involved as Developer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16703 Reports
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
Privacy
Incidents Harmed By
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16703 Reports
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
Large language models
Incidents implicated systems
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16703 Reports
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
AI agent systems
Incidents implicated systems
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16703 Reports
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
Threat actors
Incidents involved as Deployer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16703 Reports
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
AI agent system deployers
Incidents involved as Deployer
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16703 Reports
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook
Information security
Incidents Harmed By
- Incident 16934 Reports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority
- Incident 16703 Reports
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook