Skip to Content
logologo
AI Incident Database
Donar
Descubrir
Enviar
  • Bienvenido a la AIID
  • Vista Tabular
  • Vista de lista
  • Entidades
  • Taxonomías
  • Vista espacial
  • Blog
  • Resumen de noticias de IA
  • Incidente aleatorio
  • Registrarse
Descubrir
Enviar
  • Bienvenido a la AIID
  • Vista Tabular
  • Vista de lista
  • Entidades
  • Taxonomías
  • Vista espacial
  • Blog
  • Resumen de noticias de IA
  • Incidente aleatorio
  • Registrarse
Entidades

Agentic threat actors

Incidents involved as Deployer

Incidente 15784 Reportes
LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

2026-07-01

Sysdig reported that a ransomware operator it dubbed JADEPUFFER used an LLM-driven agent to turn access through a vulnerable internet-facing Langflow deployment into a database-extortion operation. The report said the activity reached a production database server and produced concrete disruption, with the victim environment allegedly left in a damaged and unrecoverable state alongside a ransom demand.

Más

Incidente 16464 Reportes
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

2026-07-01

From July 1–4, 2026, suspected China-linked hackers reportedly used a multi-agent framework built on Hermes and OpenClaw to compromise Taiwanese government systems. The agents reportedly compromised 85 credentials and used persistent access to connected systems to exfiltrate more than 2,564 personnel records. Taiwan later confirmed an overseas AI-assisted campaign against government agencies, without attributing it to China.

Más

Incidente 16694 Reportes
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

2026-07-09

Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.

Más

Incidente 16613 Reportes
Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

2026-04-08

Between April 8 and May 21, 2026, a Russian-speaking operator linked to the Aurora ransomware group reportedly used Cursor Agent, running Anthropic's Claude Sonnet 4.5, to assist exploitation across multiple organizations. Researchers said some AI-directed tasks succeeded while others failed; independent reporting identified six affected companies but could not determine how much the AI facilitated each breach or whether all led to data theft or extortion.

Más

Entidades relacionadas
Otras entidades que están relacionadas con el mismo incidente. Por ejemplo, si el desarrollador de un incidente es esta entidad pero el implementador es otra entidad, se marcan como entidades relacionadas.
 

Entity

Ransomware operators

Incidents involved as Deployer
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

JADEPUFFER

Incidents involved as Deployer
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

Más
Entity

Cybercriminals

Incidents involved as Deployer
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

Large language model developers

Incidents involved as Developer
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

AI agent system developers

Incidents involved as Developer
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

Operators of Langflow deployments

Afectado por Incidentes
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

Más
Entity

Database operators

Afectado por Incidentes
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

Más
Entity

Ransomware

Incidents implicated systems
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Production database servers

Incidents implicated systems
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

Más
Entity

Nacos configuration service

Incidents implicated systems
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

Más
Entity

MySQL databases

Incidents implicated systems
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

Más
Entity

Large language models

Incidents implicated systems
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

Langflow

Incidents implicated systems
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

Más
Entity

AI agent systems

Incidents implicated systems
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

Agentic ransomware

Incidents implicated systems
  • Incidente 1578
    4 Report

    LLM-Driven Ransomware Operator Dubbed JADEPUFFER Reportedly Targeted Production Database

Más
Entity

Extortionists

Incidents involved as Deployer
  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Victims of automated cybercrime

Afectado por Incidentes
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Privacy

Afectado por Incidentes
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

Enterprise IT systems

Afectado por Incidentes
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Amazon Web Services (AWS) customers

Afectado por Incidentes
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • Incidente 1586
    1 Report

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

Más
Entity

Threat actors

Incidents involved as Deployer
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

hackers

Incidents involved as Deployer
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

China-linked threat actors

Incidents involved as Deployer
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

Peter Steinberger

Incidents involved as Developer
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

Nous Research

Incidents involved as Developer
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

Taiwanese government employees

Afectado por Incidentes
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

Taiwanese government agencies

Afectado por Incidentes
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

Taiwan Ministry of Justice

Afectado por Incidentes
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

National security and intelligence stakeholders

Afectado por Incidentes
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

Information security

Afectado por Incidentes
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

Governments

Afectado por Incidentes
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

Government of Taiwan

Afectado por Incidentes
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

Government agencies

Afectado por Incidentes
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

OpenClaw

Incidents implicated systems
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Más
Entity

Hermes Agent

Incidents implicated systems
  • Incidente 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

Aurora ransomware affiliate

Incidents involved as Deployer
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Anysphere

Incidents involved as Developer
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Anthropic

Incidents involved as Developer
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Christeyns

Afectado por Incidentes
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Teckentrup

Afectado por Incidentes
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Helideck Certification Agency

Afectado por Incidentes
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Bayou Title

Afectado por Incidentes
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Companies

Afectado por Incidentes
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Organizations

Afectado por Incidentes
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Cursor

Incidents implicated systems
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Claude Sonnet 4.5

Incidents implicated systems
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Claude

Incidents implicated systems
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Claude AI models

Incidents implicated systems
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Aurora ransomware

Incidents implicated systems
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

LLM-integrated code assistants

Incidents implicated systems
  • Incidente 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Más
Entity

Thailand Ministry of Finance

Afectado por Incidentes
  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

Government of Thailand

Afectado por Incidentes
  • Incidente 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Más
Entity

marimo

Incidents implicated systems
  • Incidente 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Más

Investigación

  • Definición de un “Incidente de IA”
  • Definición de una “Respuesta a incidentes de IA”
  • Hoja de ruta de la base de datos
  • Trabajo relacionado
  • Descargar Base de Datos Completa

Proyecto y Comunidad

  • Acerca de
  • Contactar y Seguir
  • Aplicaciones y resúmenes
  • Guía del editor

Incidencias

  • Todos los incidentes en forma de lista
  • Incidentes marcados
  • Cola de envío
  • Vista de clasificaciones
  • Taxonomías

2026 - AI Incident Database

  • Condiciones de uso
  • Política de privacidad
  • dd3f754