Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Descubrir
Enviar
  • Bienvenido a la AIID
  • Descubrir Incidentes
  • Vista espacial
  • Vista Tabular
  • Vista de lista
  • Entidades
  • Taxonomías
  • Enviar Informes de Incidentes
  • Ranking de Reportadores
  • Blog
  • Resumen de noticias de IA
  • Control de Riesgos
  • Incidente aleatorio
  • Registrarse
Colapsar
Descubrir
Enviar
  • Bienvenido a la AIID
  • Descubrir Incidentes
  • Vista espacial
  • Vista Tabular
  • Vista de lista
  • Entidades
  • Taxonomías
  • Enviar Informes de Incidentes
  • Ranking de Reportadores
  • Blog
  • Resumen de noticias de IA
  • Control de Riesgos
  • Incidente aleatorio
  • Registrarse
Colapsar
Entidades

Agentic AI system

Incidents implicated systems

Incidente 126327 Reportes
Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

2025-11-13

Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.

Más

Incidente 11525 Reportes
LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

2025-07-18

An AI-powered development assistant on Replit's platform reportedly deleted a live production database during an active code freeze, despite receiving repeated instructions not to make changes. The system also reportedly produced fabricated test results and fake data, and incorrectly claimed rollback was impossible, delaying recovery. The incident reportedly resulted in significant data loss and user distrust regarding its safety and reliability.

Más

Incidente 12013 Reportes
Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

2025-08-27

In August 2025, Anthropic published a threat intelligence report detailing multiple misuse cases of its Claude models. Documented abuses included a large-scale extortion campaign using Claude Code against at least 17 organizations, fraudulent remote employment schemes linked to North Korean operatives, and the development and sale of AI-generated ransomware. Anthropic banned the accounts, implemented new safeguards, and shared indicators with authorities.

Más

Incidente 10281 Reporte
OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

2025-02-07

OpenAI's Operator agent, which is designed to complete real-world web tasks on behalf of users, reportedly executed a $31.43 grocery delivery purchase without user consent. The user had requested a price comparison but did not authorize the transaction. It reportedly bypassed OpenAI's stated safeguard requiring user confirmation before purchases. OpenAI acknowledged the failure and committed to improving safeguards.

Más

Entidades relacionadas
Otras entidades que están relacionadas con el mismo incidente. Por ejemplo, si el desarrollador de un incidente es esta entidad pero el implementador es otra entidad, se marcan como entidades relacionadas.
 

Entity

OpenAI

Incidentes involucrados como desarrollador e implementador
  • Incidente 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Más
Entity

Users of Operator

Afectado por Incidentes
  • Incidente 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Más
Entity

Geoffrey A. Fowler

Afectado por Incidentes
  • Incidente 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Más
Entity

Operator

Incidents implicated systems
  • Incidente 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Más
Entity

Instacart

Incidents implicated systems
  • Incidente 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Más
Entity

GPT-4

Incidents implicated systems
  • Incidente 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Más
Entity

Replit

Incidentes involucrados como desarrollador e implementador
  • Incidente 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Más
Entity

SaaStr

Afectado por Incidentes
  • Incidente 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Más
Entity

Jason Lemkin

Afectado por Incidentes
  • Incidente 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Más
Entity

end users of the SaaStr database

Afectado por Incidentes
  • Incidente 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Más
Entity

developers using Replit in production environments

Afectado por Incidentes
  • Incidente 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Más
Entity

vibe coding platform

Incidents implicated systems
  • Incidente 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Más
Entity

Replit AI agent

Incidents implicated systems
  • Incidente 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Más
Entity

LLM-integrated code assistant

Incidents implicated systems
  • Incidente 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Más
Entity

Unknown cybercriminals

Incidents involved as Deployer
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Ransomware-as-a-service actors

Incidents involved as Deployer
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

North Korean IT operatives

Incidents involved as Deployer
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Anthropic

Incidents involved as Developer
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Religious institutions

Afectado por Incidentes
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Healthcare organizations

Afectado por Incidentes
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Government agencies

Afectado por Incidentes
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Fortune 500 technology companies

Afectado por Incidentes
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Emergency services

Afectado por Incidentes
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Consumers targeted by ransomware

Afectado por Incidentes
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Epistemic integrity

Afectado por Incidentes
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Truth

Afectado por Incidentes
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

General public

Afectado por Incidentes
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

National security and intelligence stakeholders

Afectado por Incidentes
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

LLM-enhanced ransomware toolkits

Incidents implicated systems
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Claude

Incidents implicated systems
  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Claude code

Incidents implicated systems
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incidente 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Más
Entity

Unknown Chinese state-sponsored entity

Incidents involved as Deployer
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más
Entity

State-linked operator using autonomous AI-enabled intrusion workflows

Incidents involved as Deployer
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más
Entity

GTG-1002

Incidents involved as Deployer
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más
Entity

Targets of autonomous AI-enabled intrusion operations

Afectado por Incidentes
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más
Entity

Entities targeted by GTG-1002

Afectado por Incidentes
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más
Entity

Open-source penetration testing tools

Incidents implicated systems
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más
Entity

Model Context Protocol (MCP)

Incidents implicated systems
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más
Entity

MCP-integrated toolchain

Incidents implicated systems
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más
Entity

GTG-1002's autonomous orchestration framework

Incidents implicated systems
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más
Entity

Autonomous AI-enabled intrusion orchestration framework

Incidents implicated systems
  • Incidente 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Más

Investigación

  • Definición de un “Incidente de IA”
  • Definición de una “Respuesta a incidentes de IA”
  • Hoja de ruta de la base de datos
  • Trabajo relacionado
  • Descargar Base de Datos Completa

Proyecto y Comunidad

  • Acerca de
  • Contactar y Seguir
  • Aplicaciones y resúmenes
  • Guía del editor

Incidencias

  • Todos los incidentes en forma de lista
  • Incidentes marcados
  • Cola de envío
  • Vista de clasificaciones
  • Taxonomías

2024 - AI Incident Database

  • Condiciones de uso
  • Política de privacidad
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 353a03d