Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Découvrir les incidents
  • Vue spatiale
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Soumettre des rapports d'incident
  • Classement des reporters
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Contrôle des risques
  • Incident au hasard
  • S'inscrire
Fermer
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Découvrir les incidents
  • Vue spatiale
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Soumettre des rapports d'incident
  • Classement des reporters
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Contrôle des risques
  • Incident au hasard
  • S'inscrire
Fermer
Entités

Agentic AI system

Incidents implicated systems

Incident 126334 Rapports
Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

2025-11-13

Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.

Plus

Incident 13736 Rapports
AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

2026-02-11

Scott Shambaugh, a matplotlib maintainer, reported that an autonomous AI coding agent using the name "MJ Rathbun" researched him and publicly posted a personalized critical blog post after his GitHub pull request was closed. The post accused him of bias and "gatekeeping" and included claims Shambaugh disputed. The agent's operator and underlying model were not identified. Shambaugh said the post risked reputational harm and could mislead readers or other agents.

Plus

Incident 11525 Rapports
LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

2025-07-18

An AI-powered development assistant on Replit's platform reportedly deleted a live production database during an active code freeze, despite receiving repeated instructions not to make changes. The system also reportedly produced fabricated test results and fake data, and incorrectly claimed rollback was impossible, delaying recovery. The incident reportedly resulted in significant data loss and user distrust regarding its safety and reliability.

Plus

Incident 12013 Rapports
Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

2025-08-27

In August 2025, Anthropic published a threat intelligence report detailing multiple misuse cases of its Claude models. Documented abuses included a large-scale extortion campaign using Claude Code against at least 17 organizations, fraudulent remote employment schemes linked to North Korean operatives, and the development and sale of AI-generated ransomware. Anthropic banned the accounts, implemented new safeguards, and shared indicators with authorities.

Plus

Entités liées
Autres entités liées au même incident. Par exemple, si le développeur d'un incident est cette entité mais que le responsable de la mise en œuvre est une autre entité, ils sont marqués comme entités liées.
 

Entity

OpenAI

Incidents impliqués en tant que développeur et déployeur
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Plus
Entity

Users of Operator

Affecté par des incidents
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Plus
Entity

Geoffrey A. Fowler

Affecté par des incidents
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Plus
Entity

Operator

Incidents implicated systems
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Plus
Entity

Instacart

Incidents implicated systems
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Plus
Entity

GPT-4

Incidents implicated systems
  • Incident 1028
    1 Report

    OpenAI's Operator Agent Reportedly Executed Unauthorized $31.43 Transaction Despite Safety Protocol

Plus
Entity

Replit

Incidents impliqués en tant que développeur et déployeur
  • Incident 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Plus
Entity

SaaStr

Affecté par des incidents
  • Incident 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Plus
Entity

Jason Lemkin

Affecté par des incidents
  • Incident 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Plus
Entity

end users of the SaaStr database

Affecté par des incidents
  • Incident 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Plus
Entity

developers using Replit in production environments

Affecté par des incidents
  • Incident 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Plus
Entity

vibe coding platform

Incidents implicated systems
  • Incident 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Plus
Entity

Replit AI agent

Incidents implicated systems
  • Incident 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Plus
Entity

LLM-integrated code assistant

Incidents implicated systems
  • Incident 1152
    5 Report

    LLM-Driven Replit Agent Reportedly Executed Unauthorized Destructive Commands During Code Freeze, Leading to Loss of Production Data

Plus
Entity

Unknown cybercriminals

Incidents involved as Deployer
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Ransomware-as-a-service actors

Incidents involved as Deployer
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

North Korean IT operatives

Incidents involved as Deployer
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Government of North Korea

Incidents involved as Deployer
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Anthropic

Incidents involved as Developer
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Truth

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Religious institutions

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

National security and intelligence stakeholders

Affecté par des incidents
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Healthcare organizations

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Government agencies

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

General public

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Fortune 500 technology companies

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Epistemic integrity

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Emergency services

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Consumers targeted by ransomware

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

LLM-enhanced ransomware toolkits

Incidents implicated systems
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Claude Code

Incidents implicated systems
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Claude

Incidents implicated systems
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Unknown Chinese state-sponsored entity

Incidents involved as Deployer
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

State-linked operator using autonomous AI-enabled intrusion workflows

Incidents involved as Deployer
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

GTG-1002

Incidents involved as Deployer
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Targets of autonomous AI-enabled intrusion operations

Affecté par des incidents
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Entities targeted by GTG-1002

Affecté par des incidents
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Open-source penetration testing tools

Incidents implicated systems
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Model Context Protocol (MCP)

Incidents implicated systems
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

MCP-integrated toolchain

Incidents implicated systems
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

GTG-1002's autonomous orchestration framework

Incidents implicated systems
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Autonomous AI-enabled intrusion orchestration framework

Incidents implicated systems
  • Incident 1263
    34 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Unknown deployer of MJ Rathbun

Incidents involved as Deployer
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

MJ Rathbun

Incidents involved as Deployer
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

OpenClaw

Incidents involved as Developer
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Moltbook

Incidents involved as Developer
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Supply-chain gatekeepers

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Scott Shambaugh

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Open-source maintainers

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

matplotlib users

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

GitHub users

Affecté par des incidents
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

Unknown large language model

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

SOUL.md

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

matplotlib

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus
Entity

GitHub

Incidents implicated systems
  • Incident 1373
    6 Report

    AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure

Plus

Recherche

  • Définition d'un « incident d'IA »
  • Définir une « réponse aux incidents d'IA »
  • Feuille de route de la base de données
  • Travaux connexes
  • Télécharger la base de données complète

Projet et communauté

  • À propos de
  • Contacter et suivre
  • Applications et résumés
  • Guide de l'éditeur

Incidents

  • Tous les incidents sous forme de liste
  • Incidents signalés
  • File d'attente de soumission
  • Affichage des classifications
  • Taxonomies

2024 - AI Incident Database

  • Conditions d'utilisation
  • Politique de confidentialité
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • e1b50cd