Skip to Content
logologo
AI Incident Database
Faire un don
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Vue spatiale
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Incident au hasard
  • S'inscrire
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Vue spatiale
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Incident au hasard
  • S'inscrire
Entités

AI agent system deployers

Incidents involved as Deployer

Incident 162715 Rapports
Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

2026-07-30

During an Anthropic cybersecurity evaluation conducted with Irregular, Claude Opus 4.7 reportedly reached a real company whose domain matched a fictional target, extracted application and infrastructure credentials, and accessed a database containing several hundred rows of production data. Across four runs, the model continued attacking after recognizing that the target was likely real.

Plus

Incident 162815 Rapports
Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

2026-07-30

During an Anthropic cybersecurity evaluation with Irregular, Claude Mythos 5 reportedly created and published a malicious Python package to PyPI while pursuing a fictional target. The package was reportedly available for about an hour and ran on 15 real systems. On a security company's scanner, it reportedly exfiltrated credentials that Claude then used to access additional company infrastructure.

Plus

Incident 162915 Rapports
Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation

2026-07-30

During an Anthropic cybersecurity evaluation with Irregular, an internal research Claude model reportedly scanned roughly 9,000 internet targets after failing to reach its fictional target. It reportedly compromised a real company's Internet-facing application using credentials from an exposed debug page and SQL injection, then stopped after recognizing that the host was real.

Plus

Incident 16048 Rapports
OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

2026-07-11

OpenAI reported that models used in an internal cyber-capability evaluation operated beyond the sandbox's intended network boundaries after identifying a vulnerability in a package-registry proxy. The models allegedly reached Hugging Face production systems and accessed test solutions before Hugging Face detected and contained the activity.

Plus

Entités liées
Autres entités liées au même incident. Par exemple, si le développeur d'un incident est cette entité mais que le responsable de la mise en œuvre est une autre entité, ils sont marqués comme entités liées.
 

Entity

Summer Yue

Affecté par des incidents
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Incidents involved as Deployer
  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Plus
Entity

Peter Steinberger

Incidents involved as Developer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

AI agent system developers

Incidents involved as Developer
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

OpenClaw users

Affecté par des incidents
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Plus
Entity

Email account holders

Affecté par des incidents
  • Incident 1675
    2 Report

    Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected

  • Incident 1542
    1 Report

    OpenClaw Agent Reportedly Tried to Delete Meta AI Alignment Director Summer Yue's Emails Despite Stop Commands

Plus
Entity

AI agent system users

Affecté par des incidents
  • Incident 1671
    4 Report

    OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory

  • Incident 1672
    4 Report

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing

Plus
Entity

OpenClaw

Incidents implicated systems
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

AI agent systems

Incidents implicated systems
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

Meta

Incidents impliqués en tant que développeur et déployeur
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

  • Incident 1649
    3 Report

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

Plus
Entity

AI-assisted employment decision system deployers

Incidents involved as Deployer
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

AI-assisted employment decision system developers

Incidents involved as Developer
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Privacy

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

People with disabilities

Affecté par des incidents
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Meta employees

Affecté par des incidents
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Employees with disabilities

Affecté par des incidents
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Employees taking or requesting protected leave

Affecté par des incidents
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Workplace productivity monitoring systems

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Metamate

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Meta employee-trained second-brain AI agents

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Meta employee monitoring and productivity scoring system

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Meta algorithmically assisted performance ranking and calibration system

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Meta AI token-usage dashboards

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Large language models

Incidents implicated systems
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

Enterprise AI systems

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

AI-enabled decision support systems

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

AI-assisted employment decision systems

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

Algorithmic management systems

Incidents implicated systems
  • Incident 1584
    3 Report

    Meta's AI-Assisted Layoff Process Allegedly Disproportionately Selected Employees on Protected Leave

Plus
Entity

OpenAI

Incidents impliqués en tant que développeur et déployeur
  • Incident 1604
    8 Report

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

  • Incident 1668
    2 Report

    OpenAI-Linked AI Agents Reportedly Used German Programming Wiki DSEWiki for Coordination and Restriction Evasion

Affecté par des incidents
  • Incident 1604
    8 Report

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Incidents involved as Developer
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

  • Incident 1671
    4 Report

    OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory

Plus
Entity

hugging face

Affecté par des incidents
  • Incident 1604
    8 Report

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Plus
Entity

GPT-5.6 Sol

Incidents implicated systems
  • Incident 1604
    8 Report

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

Unidentified pre-release OpenAI model

Incidents implicated systems
  • Incident 1604
    8 Report

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Plus
Entity

OpenAI large language models

Incidents implicated systems
  • Incident 1604
    8 Report

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

  • Incident 1671
    4 Report

    OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory

Plus
Entity

ExploitGym

Incidents implicated systems
  • Incident 1604
    8 Report

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Plus
Entity

OpenAI research testing infrastructure

Incidents implicated systems
  • Incident 1604
    8 Report

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Plus
Entity

Hugging Face production infrastructure

Incidents implicated systems
  • Incident 1604
    8 Report

    OpenAI Models Reportedly Compromised Hugging Face Production Infrastructure During Cybersecurity Evaluation

Plus
Entity

Anthropic

Incidents impliqués en tant que développeur et déployeur
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Affecté par des incidents
  • Incident 1613
    3 Report

    Claude Mythos Preview Reportedly Posted Sandbox Exploit Details to Public Websites During Anthropic Evaluation

Incidents involved as Developer
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Information security

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Cybersecurity

Affecté par des incidents
  • Incident 1613
    3 Report

    Claude Mythos Preview Reportedly Posted Sandbox Exploit Details to Public Websites During Anthropic Evaluation

Plus
Entity

Claude Mythos Preview

Incidents implicated systems
  • Incident 1613
    3 Report

    Claude Mythos Preview Reportedly Posted Sandbox Exploit Details to Public Websites During Anthropic Evaluation

Plus
Entity

Anthropic large language models

Incidents implicated systems
  • Incident 1613
    3 Report

    Claude Mythos Preview Reportedly Posted Sandbox Exploit Details to Public Websites During Anthropic Evaluation

Plus
Entity

Irregular

Incidents involved as Deployer
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

AI evaluation organizations

Incidents involved as Deployer
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

Unidentified companies compromised during Anthropic cybersecurity evaluations disclosed July 2026

Affecté par des incidents
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

Companies

Affecté par des incidents
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

Claude Opus 4.7

Incidents implicated systems
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

Plus
Entity

Claude

Incidents implicated systems
  • Incident 1627
    15 Report

    Claude Opus 4.7 Reportedly Compromised Real Company's Production Infrastructure During Cybersecurity Evaluation

  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

Python Package Index (PyPI) ecosystem

Incidents implicated systems
  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

Plus
Entity

Cybersecurity AI systems

Incidents implicated systems
  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

  • Incident 1629
    15 Report

    Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation

Plus
Entity

Claude Mythos 5

Incidents implicated systems
  • Incident 1628
    15 Report

    Claude Mythos 5 Reportedly Published Malicious PyPI Package That Compromised Real Security Company During Evaluation

  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

Internal Anthropic research test models

Incidents implicated systems
  • Incident 1629
    15 Report

    Anthropic Research Model Reportedly Scanned 9,000 Targets and Compromised Real Company's Application During Evaluation

Plus
Entity

Government agencies

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Incidents involved as Deployer
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

AI Security Institute (United Kingdom)

Incidents involved as Deployer
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

Software developers

Affecté par des incidents
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

  • Incident 1672
    4 Report

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing

Incidents involved as Deployer
  • Incident 1676
    3 Report

    Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work

  • Incident 1673
    2 Report

    Google Gemini 3.5 Coding Agent Reportedly Caused Production Portal Outage and Generated Fabricated Recovery Records

Plus
Entity

Open-source maintainers

Affecté par des incidents
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

GitHub users

Affecté par des incidents
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

Supply chains

Incidents implicated systems
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

Software ecosystems

Incidents implicated systems
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

GitHub repositories

Incidents implicated systems
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

GitHub

Incidents implicated systems
  • Incident 1633
    4 Report

    Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations

Plus
Entity

Andrew Bird

Incidents involved as Deployer
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Gym member removed from waitlist by Andrew Bird's AI agent

Affecté par des incidents
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Gym members

Affecté par des incidents
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Users of online booking systems

Affecté par des incidents
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Claude Opus 4.6

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

AI agent system

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Online booking systems

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Gym booking software

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

GraphQL APIs

Incidents implicated systems
  • Incident 1642
    2 Report

    AI Agent Powered by Claude Opus 4.6 Reportedly Exploited Gym Booking API and Removed Another Member From Waitlist

Plus
Entity

Threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

hackers

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

China-linked threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Agentic threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Nous Research

Incidents involved as Developer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Taiwanese government employees

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Taiwanese government agencies

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Taiwan Ministry of Justice

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

National security and intelligence stakeholders

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Governments

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Government of Taiwan

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Hermes Agent

Incidents implicated systems
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Targets of autonomous AI-enabled intrusion operations

Affecté par des incidents
  • Incident 1649
    3 Report

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

Plus
Entity

Muse Spark 1.1

Incidents implicated systems
  • Incident 1649
    3 Report

    Meta AI Model Reportedly Exploited Security Vulnerability in Real Third-Party Service During Cybersecurity Evaluation

Plus
Entity

Aurora ransomware affiliate

Incidents involved as Deployer
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Cybercriminals

Incidents involved as Deployer
  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Ransomware operators

Incidents involved as Deployer
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Anysphere

Incidents involved as Developer
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Christeyns

Affecté par des incidents
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Teckentrup

Affecté par des incidents
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Helideck Certification Agency

Affecté par des incidents
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Bayou Title

Affecté par des incidents
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Organizations

Affecté par des incidents
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Cursor

Incidents implicated systems
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Claude Sonnet 4.5

Incidents implicated systems
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Claude AI models

Incidents implicated systems
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Aurora ransomware

Incidents implicated systems
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

Ransomware

Incidents implicated systems
  • Incident 1661
    3 Report

    Aurora Ransomware Operator Reportedly Used Cursor Agent to Assist Intrusions Against Multiple Organizations

Plus
Entity

LLM-integrated code assistants

Incidents implicated systems
  • Incident 1671
    4 Report

    OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory

  • Incident 1672
    4 Report

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing

Plus
Entity

Website operators

Affecté par des incidents
  • Incident 1668
    2 Report

    OpenAI-Linked AI Agents Reportedly Used German Programming Wiki DSEWiki for Coordination and Restriction Evasion

  • Incident 1673
    2 Report

    Google Gemini 3.5 Coding Agent Reportedly Caused Production Portal Outage and Generated Fabricated Recovery Records

Plus
Entity

Information integrity

Affecté par des incidents
  • Incident 1668
    2 Report

    OpenAI-Linked AI Agents Reportedly Used German Programming Wiki DSEWiki for Coordination and Restriction Evasion

Plus
Entity

DSEWiki

Affecté par des incidents
  • Incident 1668
    2 Report

    OpenAI-Linked AI Agents Reportedly Used German Programming Wiki DSEWiki for Coordination and Restriction Evasion

Incidents implicated systems
  • Incident 1668
    2 Report

    OpenAI-Linked AI Agents Reportedly Used German Programming Wiki DSEWiki for Coordination and Restriction Evasion

Plus
Entity

Thailand Ministry of Finance

Affecté par des incidents
  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Government of Thailand

Affecté par des incidents
  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Victims of automated cybercrime

Affecté par des incidents
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Enterprise IT systems

Affecté par des incidents
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Amazon Web Services (AWS) customers

Affecté par des incidents
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

marimo

Incidents implicated systems
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Matt Shumer

Affecté par des incidents
  • Incident 1671
    4 Report

    OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory

Incidents involved as Deployer
  • Incident 1671
    4 Report

    OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory

Plus
Entity

OpenAI Codex

Incidents implicated systems
  • Incident 1671
    4 Report

    OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory

  • Incident 1672
    4 Report

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing

Plus
Entity

Chatbots

Incidents implicated systems
  • Incident 1671
    4 Report

    OpenAI GPT-5.6 Sol Agent Reportedly Deleted Most Files in AI Startup Founder's Mac Home Directory

  • Incident 1672
    4 Report

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing

Plus
Entity

Bruno Lemos

Affecté par des incidents
  • Incident 1672
    4 Report

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing

Incidents involved as Deployer
  • Incident 1672
    4 Report

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing

Plus
Entity

Enterprise application users

Affecté par des incidents
  • Incident 1672
    4 Report

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing

Plus
Entity

Production database servers

Incidents implicated systems
  • Incident 1672
    4 Report

    OpenAI GPT-5.6 Sol Reportedly Deleted Software Engineer's Production Database During Local Testing

  • Incident 1676
    3 Report

    Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work

Plus
Entity

Google DeepMind

Incidents involved as Developer
  • Incident 1673
    2 Report

    Google Gemini 3.5 Coding Agent Reportedly Caused Production Portal Outage and Generated Fabricated Recovery Records

Plus
Entity

Users of production portal disrupted during Gemini 3.5 coding-agent incident

Affecté par des incidents
  • Incident 1673
    2 Report

    Google Gemini 3.5 Coding Agent Reportedly Caused Production Portal Outage and Generated Fabricated Recovery Records

Plus
Entity

Gemini 3.5

Incidents implicated systems
  • Incident 1673
    2 Report

    Google Gemini 3.5 Coding Agent Reportedly Caused Production Portal Outage and Generated Fabricated Recovery Records

Plus
Entity

Third-party AI agent rule packs

Incidents implicated systems
  • Incident 1673
    2 Report

    Google Gemini 3.5 Coding Agent Reportedly Caused Production Portal Outage and Generated Fabricated Recovery Records

Plus
Entity

Katie Jacobs Stanton

Affecté par des incidents
  • Incident 1674
    1 Report

    Instinct AI Personal Assistant Reportedly Sent Email From Moxxie Ventures Founder's Account Without Approval

Incidents involved as Deployer
  • Incident 1674
    1 Report

    Instinct AI Personal Assistant Reportedly Sent Email From Moxxie Ventures Founder's Account Without Approval

Plus
Entity

Spear Street Technology

Incidents impliqués en tant que développeur et déployeur
  • Incident 1675
    2 Report

    Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected

Incidents involved as Developer
  • Incident 1674
    1 Report

    Instinct AI Personal Assistant Reportedly Sent Email From Moxxie Ventures Founder's Account Without Approval

Plus
Entity

Instinct users

Affecté par des incidents
  • Incident 1675
    2 Report

    Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected

  • Incident 1674
    1 Report

    Instinct AI Personal Assistant Reportedly Sent Email From Moxxie Ventures Founder's Account Without Approval

Plus
Entity

Instinct

Incidents implicated systems
  • Incident 1675
    2 Report

    Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected

  • Incident 1674
    1 Report

    Instinct AI Personal Assistant Reportedly Sent Email From Moxxie Ventures Founder's Account Without Approval

Plus
Entity

AI personal assistants

Incidents implicated systems
  • Incident 1675
    2 Report

    Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected

  • Incident 1674
    1 Report

    Instinct AI Personal Assistant Reportedly Sent Email From Moxxie Ventures Founder's Account Without Approval

Plus
Entity

Claire Vo

Affecté par des incidents
  • Incident 1675
    2 Report

    Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected

Incidents involved as Deployer
  • Incident 1675
    2 Report

    Instinct AI Personal Assistant Reportedly Summarized an AI Product Founder's Retained Emails After Google Access Was Disconnected

Plus
Entity

Alone_Ad_3375 (Reddit user)

Incidents involved as Deployer
  • Incident 1676
    3 Report

    Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work

Plus
Entity

Database operators

Affecté par des incidents
  • Incident 1676
    3 Report

    Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work

Plus
Entity

Claude Opus 5

Incidents implicated systems
  • Incident 1676
    3 Report

    Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work

Plus
Entity

Claude Code

Incidents implicated systems
  • Incident 1676
    3 Report

    Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work

Plus
Entity

Supabase

Incidents implicated systems
  • Incident 1676
    3 Report

    Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work

Plus
Entity

Prisma

Incidents implicated systems
  • Incident 1676
    3 Report

    Anthropic Claude Opus 5 Coding Agent Reportedly Reset a Live Supabase Production Database During Prisma Migration Work

Plus

Recherche

  • Définition d'un « incident d'IA »
  • Définir une « réponse aux incidents d'IA »
  • Feuille de route de la base de données
  • Travaux connexes
  • Télécharger la base de données complète

Projet et communauté

  • À propos de
  • Contacter et suivre
  • Applications et résumés
  • Guide de l'éditeur

Incidents

  • Tous les incidents sous forme de liste
  • Incidents signalés
  • File d'attente de soumission
  • Affichage des classifications
  • Taxonomies

2026 - AI Incident Database

  • Conditions d'utilisation
  • Politique de confidentialité
  • dd3f754