National security and intelligence stakeholders
Afectado por Incidentes
Incidente 111841 Reportes
Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers
2021-01-01
North Korean operatives have reportedly used AI-generated identities to secure remote jobs or impersonate employers in order to infiltrate companies. These tactics allegedly support sanctions evasion through wage theft, credential exfiltration, and malware deployment. Workers reportedly use fake resumes, VPNs, and face-altering tools; some deploy malware like OtterCookie after embedding, while others lure targets via spoofed job interviews. AI systems are reportedly used to generate fake resumes, alter profile photos, and assist in real-time responses during video interviews.
MásIncidente 126334 Reportes
Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage
2025-11-13
Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.
MásIncidente 106933 Reportes
Purported Graphite Spyware Linked to Paragon Solutions Allegedly Deployed Against Journalists and Civil Society Workers
2025-01-31
Researchers at Citizen Lab and Censys reportedly identified spyware infections involving Graphite, a tool attributed to Israeli firm Paragon Solutions. The spyware was allegedly deployed against civil society actors, including journalists and aid workers, through a zero-click WhatsApp exploit. WhatsApp notified over 90 targeted individuals. Evidence reportedly suggests deployments in multiple democratic countries.
MásIncidente 96827 Reportes
'Pravda' Network, Successor to 'Portal Kombat,' Allegedly Seeding AI Models with Kremlin Disinformation
2022-02-24
A purported Moscow-based disinformation network, Pravda, allegedly infiltrated AI models by flooding the internet with pro-Kremlin falsehoods. A NewsGuard audit found that 10 major AI chatbots repeated these narratives 33% of the time, citing Pravda sources as legitimate. The tactic, called "LLM grooming," manipulates AI training data to embed Russian propaganda. Pravda is part of Portal Kombat, a larger Russian disinformation network identified by VIGINUM in February 2024, but in operation since February 2022.
MásIncidents involved as Deployer
Incidente 14002 Reportes
West Midlands Police Reportedly Relied on Erroneous Copilot-Generated Intelligence in Maccabi Tel Aviv Away-Fan Ban Decision
2025-10-24
West Midlands Police reportedly included inaccurate intelligence purportedly generated using Microsoft Copilot in materials used to justify banning Maccabi Tel Aviv supporters from attending a November 2025 Europa League match against Aston Villa. The reported Copilot-linked error, which referred to a match that had not taken place, was later acknowledged by Chief Constable Craig Guildford.
MásIncidente 14922 Reportes
Purportedly AI-Enabled Targeting System Was Reportedly Implicated in Deadly U.S. Strike on Iranian Primary School
2026-02-28
During Operation Epic Fury, U.S. forces reportedly struck Shajareh Tayyebeh Primary School in Minab, Iran, killing at least 150 civilians, many of them children. Reporting said the school was on a U.S. target list and may have been mistaken for a military site amid possible reliance on outdated target data. Palantir's Maven Smart System, reportedly integrated with Anthropic's Claude, was used in the campaign's targeting workflow
MásIncidente 8291 Reporte
Facial Recognition System in Buenos Aires Triggers Police Checks Based on False Matches
2024-02-05
Buenos Aires's facial recognition system mistakenly flagged innocent people as criminals, leading to wrongful stops and detentions. Judicial investigations indicate the technology may have been misused for unauthorized surveillance and data collection. Despite privacy risks, the system has been used widely without full disclosure of standards or safeguards,
MásIncidente 13531 Reporte
ICE Facial Recognition App Mobile Fortify Reportedly Misidentified Woman Twice During Immigration Enforcement in Oregon
2025-10-15
During an immigration enforcement operation in Oregon, U.S. Immigration and Customs Enforcement (ICE) officers reportedly used the facial recognition application Mobile Fortify to identify a detained woman. The system reportedly returned two different and incorrect identities for the same individual across separate scans.
MásEntidades relacionadas
Otras entidades que están relacionadas con el mismo incidente. Por ejemplo, si el desarrollador de un incidente es esta entidad pero el implementador es otra entidad, se marcan como entidades relacionadas.
Entidades relacionadas
Deepfake technology developers
Incidents involved as Developer
- Incidente 111841 Report
Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers
- Incidente 114123 Report
Purported AI Voice Cloning Used to Impersonate Secretary of State Marco Rubio
Incidents implicated systems
Synthetic audio generation technology developers
Incidents involved as Developer
- Incidente 114123 Report
Purported AI Voice Cloning Used to Impersonate Secretary of State Marco Rubio
- Incidente 54422 Report
Alleged Use of Purportedly AI-Generated and Manipulated Media to Misrepresent Candidates and Disrupt Turkey's 2023 Presidential Election
Incidents implicated systems
Generative AI developers
Incidents involved as Developer
- Incidente 54422 Report
Alleged Use of Purportedly AI-Generated and Manipulated Media to Misrepresent Candidates and Disrupt Turkey's 2023 Presidential Election
- Incidente 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
Synthetic audio generation technology
Incidents involved as Developer
- Incidente 9741 Report
Purported Deepfake Audio Allegedly Impersonates U.S. Secretary of State Marco Rubio in Starlink Disinformation Campaign
- Incidente 10941 Report
At Least 294 Purported AI-Generated Music Videos Portray Celebrities Praising Burkina Faso's Ibrahim Traoré
Incidents implicated systems
Russian government
Incidentes involucrados como desarrollador e implementador
Incidents involved as Deployer
Russian state media
Incidentes involucrados como desarrollador e implementador
Incidents involved as Deployer
Unit 8200
Incidentes involucrados como desarrollador e implementador
Incidents involved as Deployer
Israel Defense Forces
Incidentes involucrados como desarrollador e implementador
Incidents involved as Deployer
Deepfake creators
Incidentes involucrados como desarrollador e implementador
Incidents involved as Deployer
Spamouflage
Incidents involved as Deployer
- Incidente 7743 Report
Covert AI Influence Operations Linked to Russia, China, Iran, and Israel, OpenAI Reports
- Incidente 11291 Report
Purported AI-Generated Video Depicting Philippine President Ferdinand Marcos Jr. Using Drugs Shared by Rodrigo Duterte Supporters and Amplified by China-Linked Spamouflage
OpenAI
Incidentes involucrados como desarrollador e implementador
- Incidente 11884 Report
Multiple LLMs Reportedly Generated Responses Aligning with Purported CCP Censorship and Propaganda
- Incidente 12381 Report
OpenAI ChatGPT Models Reportedly Jailbroken to Provide Chemical, Biological, and Nuclear Weapons Instructions
Afectado por Incidentes
Incidents involved as Developer
OnlyFake
Incidentes involucrados como desarrollador e implementador
Incidents implicated systems
Storm-1516
Incidents involved as Deployer
- Incidente 96827 Report
'Pravda' Network, Successor to 'Portal Kombat,' Allegedly Seeding AI Models with Kremlin Disinformation
- Incidente 9694 Report
Russian Disinformation Campaign Allegedly Used Fake News Site 'KBSF-San Francisco News' and Deepfake Video to Falsely Accuse Kamala Harris of 2011 Hit-and-Run
John Mark Dougan
Incidentes involucrados como desarrollador e implementador
Incidents involved as Deployer
Government of Russia
Incidentes involucrados como desarrollador e implementador
Incidents involved as Deployer
xAI
Incidentes involucrados como desarrollador e implementador
- Incidente 11884 Report
Multiple LLMs Reportedly Generated Responses Aligning with Purported CCP Censorship and Propaganda
- Incidente 13073 Report
Grok AI Reportedly Generated Fabricated Civilian Hero Identity During Bondi Beach Shooting
Incidents involved as Developer
Microsoft
Incidentes involucrados como desarrollador e implementador
Incidents involved as Developer
Incidentes involucrados como desarrollador e implementador
Incidents involved as Developer
Claude
Incidents implicated systems
- Incidente 10545 Report
Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development
- Incidente 13954 Report
Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale
Storm-1679
Incidents involved as Deployer
- Incidente 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
- Incidente 12021 Report
Russian Disinformation Campaign Reportedly Used AI-Generated Posts and Videos to Target 2025 Moldovan Parliamentary Elections
Russian-aligned actors
Incidents involved as Deployer
- Incidente 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
- Incidente 11681 Report
Purportedly AI-Generated Image of British Army Colonels Captured in Ukraine Reportedly Circulates in Russian Media
Matryoshka
Incidents involved as Deployer
- Incidente 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
- Incidente 12021 Report
Russian Disinformation Campaign Reportedly Used AI-Generated Posts and Videos to Target 2025 Moldovan Parliamentary Elections
Telegram
Incidents implicated systems
- Incidente 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
- Incidente 11342 Report
Reported Deepfakes of Ukrainian Deputy PM Olha Stefanishyna Allegedly Supporting Fictional Mobilization Plan for Women
Unidentified law enforcement or intelligence entity (Singapore)
Incidents involved as Deployer
Unidentified law enforcement or intelligence entity (Denmark)
Incidents involved as Deployer
Unidentified law enforcement or intelligence entity (Australia)
Incidents involved as Deployer
YouTube
Incidents implicated systems
- Incidente 10941 Report
At Least 294 Purported AI-Generated Music Videos Portray Celebrities Praising Burkina Faso's Ibrahim Traoré
- Incidente 11291 Report
Purported AI-Generated Video Depicting Philippine President Ferdinand Marcos Jr. Using Drugs Shared by Rodrigo Duterte Supporters and Amplified by China-Linked Spamouflage
Information manipulation actors targeting the Royal Malaysia Police
Incidents involved as Deployer
DeepSeek
Incidentes involucrados como desarrollador e implementador
Incidents involved as Deployer
Incidents implicated systems
Government agencies
Afectado por Incidentes
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Unidentified Israeli government contractor under close supervision
Incidents involved as Deployer
State-linked operator using autonomous AI-enabled intrusion workflows
Incidents involved as Deployer
United States Immigration and Customs Enforcement
Incidents involved as Deployer
- Incidente 13531 Report
ICE Facial Recognition App Mobile Fortify Reportedly Misidentified Woman Twice During Immigration Enforcement in Oregon
- Incidente 13621 Report
Border Patrol Agent Allegedly Claimed Facial Recognition Identified Minneapolis ICE Observer and Global Entry Was Reportedly Revoked Three Days Later
United States Customs and Border Protection
Incidents involved as Deployer
- Incidente 13531 Report
ICE Facial Recognition App Mobile Fortify Reportedly Misidentified Woman Twice During Immigration Enforcement in Oregon
- Incidente 13621 Report
Border Patrol Agent Allegedly Claimed Facial Recognition Identified Minneapolis ICE Observer and Global Entry Was Reportedly Revoked Three Days Later
United States Department of Homeland Security
Afectado por Incidentes
Incidents involved as Developer
Incidents involved as Deployer
Unnamed woman detained by United States Immigration and Customs Enforcement
Afectado por Incidentes
Mobile Fortify
Incidents implicated systems
- Incidente 13531 Report
ICE Facial Recognition App Mobile Fortify Reportedly Misidentified Woman Twice During Immigration Enforcement in Oregon
- Incidente 13621 Report
Border Patrol Agent Allegedly Claimed Facial Recognition Identified Minneapolis ICE Observer and Global Entry Was Reportedly Revoked Three Days Later
Threat actors
Incidents involved as Deployer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
hackers
Incidents involved as Deployer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
AI agent system deployers
Incidents involved as Deployer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Agentic threat actors
Incidents involved as Deployer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Nous Research
Incidents involved as Developer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
AI agent system developers
Incidents involved as Developer
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Information security
Afectado por Incidentes
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Hermes Agent
Incidents implicated systems
- Incidente 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incidente 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network