Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Découvrir les incidents
  • Vue spatiale
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Soumettre des rapports d'incident
  • Classement des reporters
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Contrôle des risques
  • Incident au hasard
  • S'inscrire
Fermer
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Découvrir les incidents
  • Vue spatiale
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Soumettre des rapports d'incident
  • Classement des reporters
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Contrôle des risques
  • Incident au hasard
  • S'inscrire
Fermer
Entités

National security and intelligence stakeholders

Affecté par des incidents

Incident 111839 Rapports
Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

2021-01-01

North Korean operatives have reportedly used AI-generated identities to secure remote jobs or impersonate employers in order to infiltrate companies. These tactics allegedly support sanctions evasion through wage theft, credential exfiltration, and malware deployment. Workers reportedly use fake resumes, VPNs, and face-altering tools; some deploy malware like OtterCookie after embedding, while others lure targets via spoofed job interviews. AI systems are reportedly used to generate fake resumes, alter profile photos, and assist in real-time responses during video interviews.

Plus

Incident 126327 Rapports
Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

2025-11-13

Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.

Plus

Incident 54317 Rapports
Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

2023-05-22

A Twitter/X account allegedly impersonating Bloomberg reportedly posted an image falsely showing an explosion near the Pentagon. Analysts reportedly described the image as likely AI-generated. The post reportedly spread through major accounts before officials confirmed no incident occurred. Markets reportedly dipped during the short period when the hoax circulated.

Plus

Incident 10545 Rapports
Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

2025-04-23

In April 2025, Anthropic published a report detailing several misuse cases involving its Claude LLM, all detected in March. These included an "influence-as-a-service" operation that orchestrated over 100 social media bots; an effort to scrape and test leaked credentials for security camera access; a recruitment fraud campaign targeting Eastern Europe; and a novice actor developing sophisticated malware. Anthropic banned the accounts involved but could not confirm downstream deployment.

Plus

Entités liées
Autres entités liées au même incident. Par exemple, si le développeur d'un incident est cette entité mais que le responsable de la mise en œuvre est une autre entité, ils sont marqués comme entités liées.
 

Entity

Misinformation spreaders

Incidents involved as Deployer
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

Plus
Entity

Disinformation spreaders

Incidents involved as Deployer
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

Plus
Entity

Unknown malicious actors

Incidents involved as Deployer
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

Unknown AI image generator developer

Incidents involved as Developer
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

Unknown deepfake technology

Incidents involved as Developer
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

Twitter Users

Affecté par des incidents
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

Family of People Near Pentagon

Affecté par des incidents
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

Investors

Affecté par des incidents
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

General public

Affecté par des incidents
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

General public of the United States

Affecté par des incidents
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

Truth

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

Epistemic integrity

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

Unknown AI image generator

Incidents implicated systems
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

X (Twitter)

Incidents implicated systems
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

Social media platforms

Incidents implicated systems
  • Incident 543
    17 Report

    Purported AI-Generated Image of Explosion Near Pentagon Reportedly Triggers Brief Market Dip and Public Confusion

Plus
Entity

Yahoo Boys

Incidents involved as Deployer
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Scammers from West Africa

Incidents involved as Deployer
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Scammers from Nigeria

Incidents involved as Deployer
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Scammers from Morocco

Incidents involved as Deployer
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Scammers from Ghana

Incidents involved as Deployer
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Brouteurs

Incidents involved as Deployer
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Unknown deepfake technology developers

Incidents involved as Developer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Unknown voice cloning technology developers

Incidents involved as Developer
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Widows

Affecté par des incidents
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Matthew W. McFarlane

Affecté par des incidents
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Impersonated American military officials

Affecté par des incidents
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Emotionally vulnerable individuals

Affecté par des incidents
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

American widows

Affecté par des incidents
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

Plus
Entity

Unknown voice cloning technology

Incidents implicated systems
  • Incident 912
    2 Report

    Yahoo Boys and Scammers from Morocco Allegedly Target U.S. Widows and Vulnerable Individuals with 'Artificial Patriot' Scams

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Unknown cybercriminals

Incidents involved as Deployer
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Influence-as-a-service operators

Incidents involved as Deployer
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

Anthropic

Incidents involved as Developer
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

social media users

Affecté par des incidents
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

People targeted by malware

Affecté par des incidents
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

Job seekers in Eastern Europe

Affecté par des incidents
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

IoT security camera owners

Affecté par des incidents
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

LLM-enhanced malware toolkits

Incidents implicated systems
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

Claude AI models

Incidents implicated systems
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

Claude

Incidents implicated systems
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

AI-generated social media bots

Incidents implicated systems
  • Incident 1054
    5 Report

    Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development

Plus
Entity

Unknown disinformation actors

Incidents involved as Deployer
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

Plus
Entity

Unknown disinformation actor targeting Paul Kagame

Incidents involved as Deployer
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

Plus
Entity

Unknown deepfake technology developer

Incidents involved as Developer
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

Plus
Entity

Regional peacebuilding efforts in the African Great Lakes region

Affecté par des incidents
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

Plus
Entity

Paul Kagame

Affecté par des incidents
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

Plus
Entity

Government of Rwanda

Affecté par des incidents
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

Plus
Entity

General public of the Democratic Republic of the Congo

Affecté par des incidents
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

Plus
Entity

General public of Rwanda

Affecté par des incidents
  • Incident 1098
    1 Report

    Image Purporting to Show President Paul Kagame of Rwanda in M23 Uniform Reportedly AI-Generated

Plus
Entity

Unknown disinformation actors targeting Royal Malaysia Police

Incidents involved as Deployer
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

Plus
Entity

Unknown disinformation actors in Malaysia

Incidents involved as Deployer
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

Plus
Entity

Tan Sri Acryl Sani Abdullah Sani

Affecté par des incidents
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

Plus
Entity

Royal Malaysia Police

Affecté par des incidents
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

Plus
Entity

General public of Malaysia

Affecté par des incidents
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

Plus
Entity

TikTok

Incidents implicated systems
  • Incident 1116
    1 Report

    Alleged Deepfake Video Depicts Former Malaysian Inspector-General of Police Tan Sri Acryl Sani Abdullah in Financial Misconduct Context

Plus
Entity

North Korea

Incidents involved as Deployer
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Lazarus Group

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

BlueNoroff

Incidents involved as Deployer
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Unknown voice cloning technology developer

Incidents involved as Developer
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Zoom

Affecté par des incidents
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Web3

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Unnamed Web3 employee

Affecté par des incidents
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

macOS users

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Cryptocurrency infrastructure

Affecté par des incidents
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Telegram

Incidents implicated systems
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

macOS

Incidents implicated systems
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Cryptocurrency wallets

Incidents implicated systems
  • Incident 1117
    1 Report

    North Korea-Linked Actors Allegedly Use AI Executive Deepfakes in Zoom Phishing Targeting Web3 Employee

Plus
Entity

Yang Di

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

WaterPlum

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Wagemole

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Void Dokkaebi

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

UNC5267

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Son Un Chol

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Sok Kwang Hyok

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Sim Hyon-Sop

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Rim Un Chol

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Ri Kyong Sik

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Reconnaissance General Bureau

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

PurpleBravo

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

North Korean threat actors

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Minh Phuong Ngoc Vong

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Matthew Isaac Knoot

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Ko Chung Sok

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Kim Ye Won

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Kim Sang Man

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Kim Ryu Song

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Kim Mu Rim

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Jong Song Hwa

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Jong Kyong Chol

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Jang Chol Myong

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Hyon Chol Song

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Gwisin Gang

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Government of North Korea

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Famous Chollima

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Department 53

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Contagious Interview

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Christina Chapman

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Choe Jong Yong

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Cho Chung Pom

Incidents involved as Deployer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Unknown large language model developers

Incidents involved as Developer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

OpenAI

Incidents involved as Developer
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

Western companies

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

SSA

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Social Security Administration

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Recruitment teams

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Oleksandr Didenko

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Jiho Han

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

IRS

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Interviewees

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Internal Revenue Service

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Human resources staff

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Hiring managers

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Haoran Xu

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Employers

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Developers

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Cryptocurrency platforms

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Companies in the United States

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Chunji Jin

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Blockchain projects

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Andrew M.

Affecté par des incidents
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

WebSocket-based C2

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Video interview platforms

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Upwork

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Unknown large language models

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

remote3

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Remote admin tools

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Raspberry Pi Zero

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

OtterCookie v4

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

OtterCookie v3

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

OtterCookie

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Laptop farms

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Job boards

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

InvisibleFerret

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

GitHub

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

FTP exfiltration

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Freelance platforms

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Flashpoint-detected info-stealing malware

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Document verification systems

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Digital identity verification services

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

ChatGPT

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

BYOD (Bring Your Own Device)

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

BeaverTail

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Astrill VPN

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

ARP packet signaling

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

AgencyHill99

Incidents implicated systems
  • Incident 1118
    39 Report

    Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers

Plus
Entity

Ransomware-as-a-service actors

Incidents involved as Deployer
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

North Korean IT operatives

Incidents involved as Deployer
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Religious institutions

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Healthcare organizations

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Government agencies

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Fortune 500 technology companies

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Emergency services

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Consumers targeted by ransomware

Affecté par des incidents
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

LLM-enhanced ransomware toolkits

Incidents implicated systems
  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Claude code

Incidents implicated systems
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Agentic AI system

Incidents implicated systems
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

  • Incident 1201
    3 Report

    Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales

Plus
Entity

Velvet Chollima

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

THALLIUM

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

Kimsuky Group

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

Group 0094

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

Emerald Sleet

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

Black Banshee

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

APT43

Incidents involved as Deployer
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

South Korean defense personnel

Affecté par des incidents
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

Government of South Korea

Affecté par des incidents
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

General public of South Korea

Affecté par des incidents
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

Hancom Office

Incidents implicated systems
  • Incident 1208
    1 Report

    North Korea's Kimsuky Group Reportedly Uses AI-Generated Military ID Deepfakes in Phishing Campaign

Plus
Entity

Unknown Chinese state-sponsored entity

Incidents involved as Deployer
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

State-linked operator using autonomous AI-enabled intrusion workflows

Incidents involved as Deployer
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

GTG-1002

Incidents involved as Deployer
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Targets of autonomous AI-enabled intrusion operations

Affecté par des incidents
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Entities targeted by GTG-1002

Affecté par des incidents
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Open-source penetration testing tools

Incidents implicated systems
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Model Context Protocol (MCP)

Incidents implicated systems
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

MCP-integrated toolchain

Incidents implicated systems
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

GTG-1002's autonomous orchestration framework

Incidents implicated systems
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus
Entity

Autonomous AI-enabled intrusion orchestration framework

Incidents implicated systems
  • Incident 1263
    27 Report

    Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage

Plus

Recherche

  • Définition d'un « incident d'IA »
  • Définir une « réponse aux incidents d'IA »
  • Feuille de route de la base de données
  • Travaux connexes
  • Télécharger la base de données complète

Projet et communauté

  • À propos de
  • Contacter et suivre
  • Applications et résumés
  • Guide de l'éditeur

Incidents

  • Tous les incidents sous forme de liste
  • Incidents signalés
  • File d'attente de soumission
  • Affichage des classifications
  • Taxonomies

2024 - AI Incident Database

  • Conditions d'utilisation
  • Politique de confidentialité
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 353a03d