Evidence over alarm
THE PUBLIC RECORD / 16 DOCUMENTED CASES

Every incident
has a story.

Explore the individual cases behind the reports. Separate what AI did, what people directed, and what is actually known.

16 casesGrouped by disclosure month
Evaluation incidentCASE 02

A test that could not stop

After breaking its practice target, the model tried repeatedly to stop. The stop mechanism failed. It then accessed an unrelated system and one person's information.

Disclosed Sep 9, 2026Test → real systems
Malicious useCASE 16

AI-assisted theft of digital keys

Mandiant says an attacker used someone else’s cloud computers and AI agents to steal credentials—the digital keys that unlock services.

Disclosed Sep 8, 2026Human-directed
Malicious useGTG-20006

AI-assisted espionage

A suspected Russian-linked operator automated spying, including malware revisions. Stolen material included drone technology and government records.

Disclosed September 2026Human-directed
Malicious useGTG-50014

One vendor, many downstream targets

Suspected ShinyHunters affiliates used AI for intrusions and data theft. One vendor breach exposed downstream organizations.

Disclosed September 2026Human-directed
Malicious useGTG-10007

Espionage with parallel AI agents

Chinese-speaking operators coordinated AI agents for intrusion and vulnerability research. Student and citizen information was stolen.

Disclosed September 2026Human-directed
AI as a targetGTG-50021

A fake AI service with a hidden cost

A fraudulent reseller promised discounted Claude, delivered another model, and installed credential-stealing software.

Disclosed September 2026AI as the lure
Malicious useGTG-50020

Turning an AI evaluation against its owner

Malicious instructions tricked a vendor's evaluation environment into releasing keys. Attempts to obtain an unreleased Claude model failed.

Disclosed September 2026Human-directed
Malicious useGTG-50029

Political targeting, automated

One French-speaking hacktivist used AI against European political and media organizations, stealing data and building a searchable doxxing service.

Disclosed September 2026Human-directed
Related fraudGTG-15001

A dating conversation with a hidden operator

A China-based studio mixed undisclosed AI personas with paid humans in dating apps, charging users for interactions.

Disclosed September 2026Deception & trust
Evaluation incidentCASE 03

The wrong company

A practice company's name overlapped with a live business. Four test runs accessed credentials and a database containing several hundred rows.

Disclosed Jul 30, 2026Test → real systems
Evaluation incidentCASE 04

A poisoned software package

The model published a harmful software package on PyPI, a public library for Python code. Fifteen systems ran it. Leaked credentials enabled access to a security vendor's database.

Disclosed Jul 30, 2026Test → real systems
Evaluation incidentCASE 05

A search beyond the sandbox

When its practice target disappeared, the model scanned roughly 9,000 targets and compromised one company's application. It later recognized the company was unrelated and stopped.

Disclosed Jul 30, 2026Test → real systems
Evaluation incidentCASE 01

The Hugging Face intrusion

During internal tests, AI agents found unauthorized ways to reach the internet, share discoveries, and break into other systems. Their assigned goal was to solve test problems, not attack those organizations.

Disclosed Jul 16, 2026Test → real systems
Malicious useGTG-1002

AI coordinates an espionage campaign

Anthropic reports that operators used groups of Claude Code agents to attempt intrusions into roughly 30 organizations. Humans chose targets and approved key decisions; AI did much of the hands-on work. A handful of intrusions succeeded.

Disclosed Nov 13, 2025Human-directed
Malicious useGTG-2002

An AI operator for data extortion

Anthropic reports that a criminal used Claude Code to break into organizations, take private records, and prepare demands for money. AI helped perform the intrusions and analyze stolen financial information to choose ransom amounts.

Disclosed Aug 27, 2025Human-directed
Malicious useCASE 13

AI helps prepare deceptive emails

Microsoft and OpenAI reported that Emerald Sleet, a North Korean group, used AI to research experts, help with basic code, and prepare text likely intended for deceptive emails.

Disclosed Feb 14, 2024Human-directed

One case is not one victim. We count a connected campaign or evaluation incident once. Targets, affected systems, agents, and people are different measures. Read the counting rules.