Skip to Content
logologo
AI Incident Database
Faire un don
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Vue spatiale
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Incident au hasard
  • S'inscrire
Découvrir
Envoyer
  • Bienvenue sur AIID
  • Vue de tableau
  • Vue de liste
  • Entités
  • Taxonomies
  • Vue spatiale
  • Blog
  • Résumé de l’Actualité sur l’IA
  • Incident au hasard
  • S'inscrire
Entités

Threat actors

Incidents involved as Deployer

Incident 16805 Rapports
Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

2026-02-17

An unknown actor reportedly exploited prompt injection in Cline's Claude-powered GitHub issue-triage workflow and a GitHub Actions cache-poisoning path to obtain publication credentials. On February 17, 2026, a still-valid npm token was used to publish unauthorized cline@2.3.0, which installed OpenClaw without user intent. Cline said OpenClaw was non-malicious; it deprecated the release and revoked the token that day, while reporting that it found no evidence of user-data exposure.

Plus

Incident 16464 Rapports
Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

2026-07-01

From July 1–4, 2026, suspected China-linked hackers reportedly used a multi-agent framework built on Hermes and OpenClaw to compromise Taiwanese government systems. The agents reportedly compromised 85 credentials and used persistent access to connected systems to exfiltrate more than 2,564 personnel records. Taiwan later confirmed an overseas AI-assisted campaign against government agencies, without attributing it to China.

Plus

Incident 16694 Rapports
Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

2026-07-09

Hunt.io reported that an unidentified threat actor used Nous Research's Hermes agent in unattended "YOLO" mode during an intrusion targeting Thailand's Ministry of Finance. Recovered logs showed Hermes conducting privilege-escalation reconnaissance within ministry systems and recursively searching a directory containing personnel records. Researchers found evidence of compromise but no data exfiltration; the ministry had not publicly confirmed a breach.

Plus

Incident 16934 Rapports
AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

2026-09-14

An unnamed organization reportedly notified Spain's data protection authority that a third party used an AI agent powered by a known language model to carry out a multistep intrusion that resulted in unauthorized changes to personal data and access to invoices. The AEPD said the case remains under review and has not identified the organization, attacker, AI system, attack date, or number of affected people.

Plus

Entités liées
Autres entités liées au même incident. Par exemple, si le développeur d'un incident est cette entité mais que le responsable de la mise en œuvre est une autre entité, ils sont marqués comme entités liées.
 

Entity

hackers

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

China-linked threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

AI agent system deployers

Incidents involved as Deployer
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Agentic threat actors

Incidents involved as Deployer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Peter Steinberger

Incidents involved as Developer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Nous Research

Incidents involved as Developer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Large language model developers

Incidents involved as Developer
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1693
    4 Report

    AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

Plus
Entity

AI agent system developers

Incidents involved as Developer
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Taiwanese government employees

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Taiwanese government agencies

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Taiwan Ministry of Justice

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Privacy

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

National security and intelligence stakeholders

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Information security

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Governments

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Government of Taiwan

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Government agencies

Affecté par des incidents
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

OpenClaw

Incidents implicated systems
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Large language models

Incidents implicated systems
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1693
    4 Report

    AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

Plus
Entity

Hermes Agent

Incidents implicated systems
  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

AI agent systems

Incidents implicated systems
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

  • Incident 1646
    4 Report

    Suspected China-Linked Hackers Reportedly Used AI Agents to Compromise Taiwanese Government Systems and Exfiltrate Personnel Records

Plus
Entity

Cybercriminals

Incidents involved as Deployer
  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

  • Incident 1693
    4 Report

    AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

Plus
Entity

Thailand Ministry of Finance

Affecté par des incidents
  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Government of Thailand

Affecté par des incidents
  • Incident 1669
    4 Report

    Threat Actor Reportedly Used Hermes AI Agent for Unattended Post-Compromise Activity in Thailand's Ministry of Finance Network

Plus
Entity

Victims of automated cybercrime

Affecté par des incidents
  • Incident 1693
    4 Report

    AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Enterprise IT systems

Affecté par des incidents
  • Incident 1693
    4 Report

    AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Amazon Web Services (AWS) customers

Affecté par des incidents
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

marimo

Incidents implicated systems
  • Incident 1670
    3 Report

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

Plus
Entity

Cline Bot Inc.

Affecté par des incidents
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Incidents involved as Deployer
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Plus
Entity

Anthropic

Incidents involved as Developer
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

  • Incident 1687
    1 Report

    Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software

Plus
Entity

Cline CLI users

Affecté par des incidents
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Plus
Entity

Software developers

Affecté par des incidents
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Plus
Entity

Claude Code

Incidents implicated systems
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

  • Incident 1687
    1 Report

    Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software

Plus
Entity

GitHub Actions

Incidents implicated systems
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Plus
Entity

Cline CLI

Incidents implicated systems
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Plus
Entity

npm registry

Incidents implicated systems
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Plus
Entity

Claude Code Action

Incidents implicated systems
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

Plus
Entity

Claude

Incidents implicated systems
  • Incident 1680
    5 Report

    Unknown Actor Reportedly Exploited Cline's Claude-Powered GitHub Issue-Triage Workflow and Published an Unauthorized Cline CLI Package

  • Incident 1687
    1 Report

    Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software

Plus
Entity

GTG-87001

Incidents involved as Deployer
  • Incident 1687
    1 Report

    Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software

Plus
Entity

Chatbot users

Incidents involved as Deployer
  • Incident 1687
    1 Report

    Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software

Plus
Entity

Chatbot developers

Incidents involved as Developer
  • Incident 1687
    1 Report

    Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software

Plus
Entity

Chatbots

Incidents implicated systems
  • Incident 1687
    1 Report

    Anthropic-Designated GTG-87001 Weapons Cell in Northern Yemen Reportedly Used Claude Code to Develop Missile Guidance Software

Plus
Entity

Synthetic media creators

Incidents involved as Deployer
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Synthetic media generation technology developers

Incidents involved as Developer
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Synthetic audio generation technology developers

Incidents involved as Developer
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Teachers

Affecté par des incidents
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Parkview High School students and staff (Georgia)

Affecté par des incidents
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Parkview High School (Georgia)

Affecté par des incidents
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Minors

Affecté par des incidents
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Educators

Affecté par des incidents
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Educational communities targeted by threats

Affecté par des incidents
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Educational communities

Affecté par des incidents
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Synthetic media generation technology

Incidents implicated systems
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Synthetic audio generation technology

Incidents implicated systems
  • Incident 1692
    3 Report

    Parkview High School in Georgia Reportedly Received Series of Purportedly AI-Generated Bomb Threats That Prompted Repeated Lockdowns

Plus
Entity

Organizations

Affecté par des incidents
  • Incident 1693
    4 Report

    AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

Plus
Entity

Organization affected by AI-agent data breach reported to AEPD

Affecté par des incidents
  • Incident 1693
    4 Report

    AI Agent Reportedly Exploited Application Vulnerabilities to Modify Personal Data and Access Invoices in Breach Reported to Spanish Data Protection Authority

Plus

Recherche

  • Définition d'un « incident d'IA »
  • Définir une « réponse aux incidents d'IA »
  • Feuille de route de la base de données
  • Travaux connexes
  • Télécharger la base de données complète

Projet et communauté

  • À propos de
  • Contacter et suivre
  • Applications et résumés
  • Guide de l'éditeur

Incidents

  • Tous les incidents sous forme de liste
  • Incidents signalés
  • File d'attente de soumission
  • Affichage des classifications
  • Taxonomies

2026 - AI Incident Database

  • Conditions d'utilisation
  • Politique de confidentialité
  • dd3f754