概要: 世界的なサイバー犯罪ネットワーク「Storm-2139」は、盗まれた認証情報を悪用し、AIの安全対策を迂回するためのカスタムツールを開発したとされています。彼らは、著名人の同意のない親密な画像を含む有害なディープフェイクコンテンツを生成したと報じられています。また、彼らのソフトウェアは、コンテンツモデレーションの無効化、AIアクセスの乗っ取り、違法サービスの転売を行っていたと報告されています。マイクロソフトは2024年12月にこの活動を阻止し、訴訟を起こしました。その後、2025年2月にネットワークの主要メンバーを特定しました。
Editor Notes: The date for this incident, 12/19/2024, is the date Microsoft filed its lawsuit, which can be read here: https://www.noticeofpleadings.net/fizzdog/files/COMPLAINT_AND_SUMMONS/2024.12.19_DE_001_%5BMicrosoft%5D_Complaint.pdf. However, the lawsuit explains, "Defendants conspired to operate the Azure Abuse Enterprise through a pattern of racketeering activity in furtherance of the common purpose of the Enterprise sometime prior to July 2024." Additionally, it details allegations of wire fraud (18 U.S.C. § 1343), stating that prior to July 2024, the defendants stole authentication information from Microsoft customers to fraudulently access the Azure OpenAI Service and deplete account balances (page 36). For information on a specific timeline, Microsoft's lawsuit also explains that "[f]rom July 26, 2024, to at least September 17, 2024, Defendants transmitted and/or caused to be transmitted by means of wire communication in interstate and foreign commerce writings, signals, and pictures for the purpose of executing their scheme to defraud" (page 37).
推定: Unidentified Storm-2139 actor from Illinois , Unidentified Storm-2139 actor from Florida , Storm-2139 , Ricky Yuen (cg-dot) , Phát Phùng Tấn (Asakuri) , Arian Yadegarnia (Fiz) , Alan Krysiak (Drago) , Proxy and credential abuse networks , Microsoft Azure OpenAI Service , Content moderation systems , Azure Abuse Enterprise , API authentication mechanisms , AI safety guardrails と Generative AI systemsが開発し提供したAIシステムで、Victims of deepfake abuse , OpenAI , Microsoft , celebrities , Azure OpenAI customers と AI service providersに影響を与えた
インシデントのステータス
Risk Subdomain
A further 23 subdomains create an accessible and understandable classification of hazards and harms associated with AI
4.3. Fraud, scams, and targeted manipulation
Risk Domain
The Domain Taxonomy of AI Risks classifies risks into seven AI risk domains: (1) Discrimination & toxicity, (2) Privacy & security, (3) Misinformation, (4) Malicious actors & misuse, (5) Human-computer interaction, (6) Socioeconomic & environmental harms, and (7) AI system safety, failures & limitations.
- Malicious Actors & Misuse
Entity
Which, if any, entity is presented as the main cause of the risk
Human
Timing
The stage in the AI lifecycle at which the risk is presented as occurring
Post-deployment
Intent
Whether the risk is presented as occurring as an expected or unexpected outcome from pursuing a goal
Intentional
インシデントレポート
レポートタイムライン
Loading...
Steven Masadaによるインシデント後のレスポンス
マイクロソフトのデジタル犯罪対策ユニット(DCU)は、AIサービスの安全性と完全性を確保するため、法的措置を講じています。バージニア州東部地区連邦地方裁判所で公開された訴状によると、マイクロソフトは、マイクロソフトのAIサービスを含む生成型AIサービスの安全対策を意図的に回避し、攻撃的で有害なコンテンツを作成するツールを開発するサイバー犯罪者を阻止するための措置を講じています。マイクロソフトは、製品とサービスの不正利用に対する耐性を高めるために多大な努力を続けていますが、サイ…
Loading...
Steven Masadaによるインシデント後のレスポンス
最近の民事訴訟に対する修正された訴状において、Microsoft は、Microsoft の Azure OpenAI サービスを含む生成 AI サービスのガードレールを回避するように設計された悪意のあるツールの主な開発者の名前を挙げています。私たちは現在、特定された被告に対してこの法的措置を講じ、彼らの行為を止め、彼らの違法な活動を解体し続け、私たちの AI 技術を武器にしようとする他者を阻止しようとしています。
名指しされた人物は、(1) イラン出身の Arian Yad…
Loading...
