National security and intelligence stakeholders
Affecté par des incidents
Incident 111841 Rapports
Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers
2021-01-01
North Korean operatives have reportedly used AI-generated identities to secure remote jobs or impersonate employers in order to infiltrate companies. These tactics allegedly support sanctions evasion through wage theft, credential exfiltration, and malware deployment. Workers reportedly use fake resumes, VPNs, and face-altering tools; some deploy malware like OtterCookie after embedding, while others lure targets via spoofed job interviews. AI systems are reportedly used to generate fake resumes, alter profile photos, and assist in real-time responses during video interviews.
PlusIncident 126334 Rapports
Chinese State-Linked Operator (GTG-1002) Reportedly Uses Claude Code for Autonomous Cyber Espionage
2025-11-13
Anthropic reportedly identified a cyber espionage campaign in which a purported Chinese state-linked group, designated GTG-1002 by Anthropic, allegedly jailbroke Claude Code and used it to automate 80–90% of multi-stage intrusions. The AI reportedly independently performed reconnaissance, vulnerability discovery, exploitation, credential harvesting, and data extraction across roughly 30 targets before the activity was detected and blocked.
PlusIncident 106933 Rapports
Purported Graphite Spyware Linked to Paragon Solutions Allegedly Deployed Against Journalists and Civil Society Workers
2025-01-31
Researchers at Citizen Lab and Censys reportedly identified spyware infections involving Graphite, a tool attributed to Israeli firm Paragon Solutions. The spyware was allegedly deployed against civil society actors, including journalists and aid workers, through a zero-click WhatsApp exploit. WhatsApp notified over 90 targeted individuals. Evidence reportedly suggests deployments in multiple democratic countries.
PlusIncident 96827 Rapports
'Pravda' Network, Successor to 'Portal Kombat,' Allegedly Seeding AI Models with Kremlin Disinformation
2022-02-24
A purported Moscow-based disinformation network, Pravda, allegedly infiltrated AI models by flooding the internet with pro-Kremlin falsehoods. A NewsGuard audit found that 10 major AI chatbots repeated these narratives 33% of the time, citing Pravda sources as legitimate. The tactic, called "LLM grooming," manipulates AI training data to embed Russian propaganda. Pravda is part of Portal Kombat, a larger Russian disinformation network identified by VIGINUM in February 2024, but in operation since February 2022.
PlusIncidents involved as Deployer
Incident 14002 Rapports
West Midlands Police Reportedly Relied on Erroneous Copilot-Generated Intelligence in Maccabi Tel Aviv Away-Fan Ban Decision
2025-10-24
West Midlands Police reportedly included inaccurate intelligence purportedly generated using Microsoft Copilot in materials used to justify banning Maccabi Tel Aviv supporters from attending a November 2025 Europa League match against Aston Villa. The reported Copilot-linked error, which referred to a match that had not taken place, was later acknowledged by Chief Constable Craig Guildford.
PlusIncident 14922 Rapports
Purportedly AI-Enabled Targeting System Was Reportedly Implicated in Deadly U.S. Strike on Iranian Primary School
2026-02-28
During Operation Epic Fury, U.S. forces reportedly struck Shajareh Tayyebeh Primary School in Minab, Iran, killing at least 150 civilians, many of them children. Reporting said the school was on a U.S. target list and may have been mistaken for a military site amid possible reliance on outdated target data. Palantir's Maven Smart System, reportedly integrated with Anthropic's Claude, was used in the campaign's targeting workflow
PlusIncident 8291 Rapport
Facial Recognition System in Buenos Aires Triggers Police Checks Based on False Matches
2024-02-05
Buenos Aires's facial recognition system mistakenly flagged innocent people as criminals, leading to wrongful stops and detentions. Judicial investigations indicate the technology may have been misused for unauthorized surveillance and data collection. Despite privacy risks, the system has been used widely without full disclosure of standards or safeguards,
PlusIncident 13531 Rapport
ICE Facial Recognition App Mobile Fortify Reportedly Misidentified Woman Twice During Immigration Enforcement in Oregon
2025-10-15
During an immigration enforcement operation in Oregon, U.S. Immigration and Customs Enforcement (ICE) officers reportedly used the facial recognition application Mobile Fortify to identify a detained woman. The system reportedly returned two different and incorrect identities for the same individual across separate scans.
PlusEntités liées
Autres entités liées au même incident. Par exemple, si le développeur d'un incident est cette entité mais que le responsable de la mise en œuvre est une autre entité, ils sont marqués comme entités liées.
Entités liées
Deepfake technology developers
Incidents involved as Developer
- Incident 111841 Report
Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers
- Incident 114123 Report
Purported AI Voice Cloning Used to Impersonate Secretary of State Marco Rubio
Incidents implicated systems
Synthetic audio generation technology developers
Incidents involved as Developer
- Incident 114123 Report
Purported AI Voice Cloning Used to Impersonate Secretary of State Marco Rubio
- Incident 54422 Report
Alleged Use of Purportedly AI-Generated and Manipulated Media to Misrepresent Candidates and Disrupt Turkey's 2023 Presidential Election
Incidents implicated systems
Generative AI developers
Incidents involved as Developer
- Incident 54422 Report
Alleged Use of Purportedly AI-Generated and Manipulated Media to Misrepresent Candidates and Disrupt Turkey's 2023 Presidential Election
- Incident 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
Synthetic audio generation technology
Incidents involved as Developer
- Incident 9741 Report
Purported Deepfake Audio Allegedly Impersonates U.S. Secretary of State Marco Rubio in Starlink Disinformation Campaign
- Incident 10941 Report
At Least 294 Purported AI-Generated Music Videos Portray Celebrities Praising Burkina Faso's Ibrahim Traoré
Incidents implicated systems
Russian government
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Deployer
Russian state media
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Deployer
Unit 8200
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Deployer
Israel Defense Forces
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Deployer
Deepfake creators
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Deployer
Spamouflage
Incidents involved as Deployer
- Incident 7743 Report
Covert AI Influence Operations Linked to Russia, China, Iran, and Israel, OpenAI Reports
- Incident 11291 Report
Purported AI-Generated Video Depicting Philippine President Ferdinand Marcos Jr. Using Drugs Shared by Rodrigo Duterte Supporters and Amplified by China-Linked Spamouflage
OpenAI
Incidents impliqués en tant que développeur et déployeur
- Incident 11884 Report
Multiple LLMs Reportedly Generated Responses Aligning with Purported CCP Censorship and Propaganda
- Incident 12381 Report
OpenAI ChatGPT Models Reportedly Jailbroken to Provide Chemical, Biological, and Nuclear Weapons Instructions
Affecté par des incidents
Incidents involved as Developer
OnlyFake
Incidents impliqués en tant que développeur et déployeur
Incidents implicated systems
Storm-1516
Incidents involved as Deployer
- Incident 96827 Report
'Pravda' Network, Successor to 'Portal Kombat,' Allegedly Seeding AI Models with Kremlin Disinformation
- Incident 9694 Report
Russian Disinformation Campaign Allegedly Used Fake News Site 'KBSF-San Francisco News' and Deepfake Video to Falsely Accuse Kamala Harris of 2011 Hit-and-Run
John Mark Dougan
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Deployer
Government of Russia
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Deployer
xAI
Incidents impliqués en tant que développeur et déployeur
- Incident 11884 Report
Multiple LLMs Reportedly Generated Responses Aligning with Purported CCP Censorship and Propaganda
- Incident 13073 Report
Grok AI Reportedly Generated Fabricated Civilian Hero Identity During Bondi Beach Shooting
Incidents involved as Developer
Microsoft
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Developer
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Developer
Claude
Incidents implicated systems
- Incident 10545 Report
Anthropic Report Details Claude Misuse for Influence Operations, Credential Stuffing, Recruitment Fraud, and Malware Development
- Incident 13954 Report
Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale
Storm-1679
Incidents involved as Deployer
- Incident 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
- Incident 12021 Report
Russian Disinformation Campaign Reportedly Used AI-Generated Posts and Videos to Target 2025 Moldovan Parliamentary Elections
Russian-aligned actors
Incidents involved as Deployer
- Incident 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
- Incident 11681 Report
Purportedly AI-Generated Image of British Army Colonels Captured in Ukraine Reportedly Circulates in Russian Media
Matryoshka
Incidents involved as Deployer
- Incident 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
- Incident 12021 Report
Russian Disinformation Campaign Reportedly Used AI-Generated Posts and Videos to Target 2025 Moldovan Parliamentary Elections
Telegram
Incidents implicated systems
- Incident 10603 Report
Institute for Strategic Dialogue Reports Russian-Aligned Operation Overload Using Purported AI-Generated Impersonations Across January to March 2025
- Incident 11342 Report
Reported Deepfakes of Ukrainian Deputy PM Olha Stefanishyna Allegedly Supporting Fictional Mobilization Plan for Women
Unidentified law enforcement or intelligence entity (Singapore)
Incidents involved as Deployer
Unidentified law enforcement or intelligence entity (Israel)
Incidents involved as Deployer
Unidentified law enforcement or intelligence entity (Denmark)
Incidents involved as Deployer
Unidentified law enforcement or intelligence entity (Cyprus)
Incidents involved as Deployer
Unidentified law enforcement or intelligence entity (Australia)
Incidents involved as Deployer
YouTube
Incidents implicated systems
- Incident 10941 Report
At Least 294 Purported AI-Generated Music Videos Portray Celebrities Praising Burkina Faso's Ibrahim Traoré
- Incident 11291 Report
Purported AI-Generated Video Depicting Philippine President Ferdinand Marcos Jr. Using Drugs Shared by Rodrigo Duterte Supporters and Amplified by China-Linked Spamouflage
Information manipulation actors targeting the Royal Malaysia Police
Incidents involved as Deployer
DeepSeek
Incidents impliqués en tant que développeur et déployeur
Incidents involved as Deployer
Incidents implicated systems
Government agencies
Affecté par des incidents
- Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Unidentified Israeli government contractor under close supervision
Incidents involved as Deployer
State-linked operator using autonomous AI-enabled intrusion workflows
Incidents involved as Deployer
United States Immigration and Customs Enforcement
Incidents involved as Deployer
- Incident 13531 Report
ICE Facial Recognition App Mobile Fortify Reportedly Misidentified Woman Twice During Immigration Enforcement in Oregon
- Incident 13621 Report
Border Patrol Agent Allegedly Claimed Facial Recognition Identified Minneapolis ICE Observer and Global Entry Was Reportedly Revoked Three Days Later
United States Customs and Border Protection
Incidents involved as Deployer
- Incident 13531 Report
ICE Facial Recognition App Mobile Fortify Reportedly Misidentified Woman Twice During Immigration Enforcement in Oregon
- Incident 13621 Report
Border Patrol Agent Allegedly Claimed Facial Recognition Identified Minneapolis ICE Observer and Global Entry Was Reportedly Revoked Three Days Later
United States Department of Homeland Security
Affecté par des incidents
Incidents involved as Developer
Incidents involved as Deployer
Unnamed woman detained by United States Immigration and Customs Enforcement
Affecté par des incidents
Mobile Fortify
Incidents implicated systems
- Incident 13531 Report
ICE Facial Recognition App Mobile Fortify Reportedly Misidentified Woman Twice During Immigration Enforcement in Oregon
- Incident 13621 Report
Border Patrol Agent Allegedly Claimed Facial Recognition Identified Minneapolis ICE Observer and Global Entry Was Reportedly Revoked Three Days Later
Threat actors
Incidents involved as Deployer
- Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
hackers
Incidents involved as Deployer
- Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
AI agent system deployers
Incidents involved as Deployer
- Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Agentic threat actors
Incidents involved as Deployer
- Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Nous Research
Incidents involved as Developer
- Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
AI agent system developers
Incidents involved as Developer
- Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Information security
Affecté par des incidents
- Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network
Hermes Agent
Incidents implicated systems
- Incident 16464 Report
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records
- Incident 16694 Report
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network