Skip to Content
logologo
AI Incident Database
寄付する
発見する
投稿する
  • ようこそAIIDへ
  • テーブル表示
  • リスト表示
  • 組織
  • 分類法
  • 空間ビュー
  • ブログ
  • AIニュースダイジェスト
  • おまかせ表示
  • サインアップ
発見する
投稿する
  • ようこそAIIDへ
  • テーブル表示
  • リスト表示
  • 組織
  • 分類法
  • 空間ビュー
  • ブログ
  • AIニュースダイジェスト
  • おまかせ表示
  • サインアップ
組織

Amazon Web Services (AWS) cloud infrastructure

Incidents implicated systems

インシデント 16703 Report
Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

2026-05-10

An unidentified attacker reportedly used an LLM agent during a May 10 intrusion after exploiting a vulnerable marimo Python notebook. The agent reportedly reused harvested AWS credentials to obtain an SSH key, then pivoted through a bastion host and exfiltrated the schema and contents of an internal PostgreSQL database. Sysdig attributed the post-compromise command stream to real-time agent execution rather than a prebuilt script.

もっと

インシデント 15861 Report
Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

2026-07-08

Sygnia reported that a threat actor apparently used purportedly AI-assisted or agentic workflows to move rapidly through an unidentified organization's AWS environment during an approximately 72-hour intrusion. The attacker allegedly expanded from an Internet-facing application into cloud infrastructure and data stores, reportedly stealing credentials and sensitive information while demonstrating the ability to disrupt services as leverage for extortion. Sygnia did not identify a specific model.

もっと

関連団体
同じインシデントに関連するその他のエンティティ。たとえば、インシデントの開発者がこのエンティティで、デプロイヤーが別のエンティティである場合、それらは関連エンティティとしてマークされます。
 

Entity

Extortionists

Incidents involved as Deployer
  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Cybercriminals

Incidents involved as Deployer
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Agentic threat actors

Incidents involved as Deployer
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Large language model developers

Incidents involved as Developer
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

AI agent system developers

Incidents involved as Developer
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Victims of automated cybercrime

影響を受けたインシデント
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Privacy

影響を受けたインシデント
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Enterprise IT systems

影響を受けたインシデント
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Amazon Web Services (AWS) customers

影響を受けたインシデント
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Large language models

Incidents implicated systems
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Amazon Web Services (AWS)

Incidents implicated systems
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

AI agent systems

Incidents implicated systems
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

  • インシデント 1586
    1 レポート

    Threat Actor Reportedly Used AI-Assisted Workflows to Compromise AWS Environment for Extortion

もっと
Entity

Threat actors

Incidents involved as Deployer
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

hackers

Incidents involved as Deployer
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

AI agent system deployers

Incidents involved as Deployer
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

Information security

影響を受けたインシデント
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと
Entity

marimo

Incidents implicated systems
  • インシデント 1670
    3 レポート

    Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

もっと

リサーチ

  • “AIインシデント”の定義
  • “AIインシデントレスポンス”の定義
  • データベースのロードマップ
  • 関連研究
  • 全データベースのダウンロード

プロジェクトとコミュニティ

  • AIIDについて
  • コンタクトとフォロー
  • アプリと要約
  • エディタのためのガイド

インシデント

  • 全インシデントの一覧
  • フラグの立ったインシデント
  • 登録待ち一覧
  • クラスごとの表示
  • 分類法

2026 - AI Incident Database

  • 利用規約
  • プライバシーポリシー
  • dd3f754