Evidence over alarm
THE SOURCE LIBRARY / ORIGINAL REPORTING

Read the evidence.
See the context.

Go straight to the original reports, investigations, and disclosures. Then follow the individual cases into plain-language explanations.

Reports are not incidents. One report can describe several cases. Several reports can describe the same case. Dates below are publication dates, not a measure of attack growth.

01 / THE EVIDENCEWhat did the source report?

Read the original account and its limits.

02 / THE EXPLANATIONWhat happened in this case?

Follow the actions, outcomes, and uncertainty.

03 / THE RESPONSEWhat can defenders do?

Explore the framework and its guidance sources.

FOLLOW THE SOURCES

The reading room.

Catalog reviewed Sep 11, 2026
26 reportsLatest publication month first
Anthropic

The source for several campaigns and a related deception case in this collection.

HOW TO READ THIS SOURCE

A multi-topic provider report. Its reporting window does not date every individual case.

Catalog entry reviewed Sep 11, 2026
Google Threat Intelligence Group

Agent workflows, AI assets and software supply chains.

HOW TO READ THIS SOURCE

Selected cases; not a census or a global acceleration measure.

REFERENCED IN EXPLAINERS
Catalog entry reviewed Sep 11, 2026
Google Threat Intelligence Group

Google examines suspected AI-assisted exploit development, malware that consults AI, and attacks through software used by AI systems. The report also describes threat actors experimenting with agents for security testing.

HOW TO READ THIS SOURCE

Combines investigations, model activity and software analysis. Some findings concern plans or inferred AI use, rather than successful attacks. Report date does not date every example.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026
Google Threat Intelligence Group

An update covering late-2025 activity connects AI use with phishing and target research, examines attempts to copy model capabilities, and describes experimental malware. It also documents deceptive instructions hosted through public AI-chat sharing features.

HOW TO READ THIS SOURCE

Primarily Q4 2025 observations, with some earlier examples. Model extraction is a different risk from stealing users’ data. Experiments and operational campaigns require separate treatment.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026
OpenAI

Date Bait combines human operators and AI chatbots in a romance-and-task scam. False Witness impersonates lawyers and authorities to target previous fraud victims. Both illustrate AI-assisted deception; the report also covers separate influence operations.

HOW TO READ THIS SOURCE

Included for online fraud and impersonation, not as proof of technical intrusion. Claimed victim losses and scale drawn from scammer inputs were not independently verified.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026
Google Threat Intelligence Group

Google describes malware calling AI while it runs, alongside continued use of AI for coding, research and deception. Its examples distinguish tools seen in operations from prototypes still being tested.

HOW TO READ THIS SOURCE

Broader than Gemini activity alone. Malware families are not incident counts; experimental capabilities and advertised services do not establish successful victim compromises.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026
OpenAI

Three cyber investigations examine malware development and tailored phishing by Russian-, Korean- and Chinese-language operators. The report describes AI assisting existing workflows and preserves limits on attribution, off-platform visibility and claims of new attacker capability.

HOW TO READ THIS SOURCE

Language alone is not attribution. Overlapping indicators connect some activity to other investigations, but do not prove every related malware sample was generated using AI.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026
OpenAI

ScopeCreep used AI while developing malware disguised as a gaming utility. Other cases describe China-linked actors using models for research and technical support, alongside employment fraud, social engineering and scams.

HOW TO READ THIS SOURCE

ScopeCreep was likely active, but widespread distribution was not established. Threat-actor experiments with automation do not demonstrate successful autonomous intrusion.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026
Anthropic

Anthropic describes attempted use of exposed camera passwords, recruitment scams and malware development by a novice. A separate case examines coordinated influence activity. Accounts were banned, while successful deployment of the cyber and fraud examples remained unconfirmed.

HOW TO READ THIS SOURCE

Published April 23 despite the March edition label. The linked PDF covers only the influence case; the cyber and fraud case studies are in the HTML.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026
OpenAI

Cases include suspected North Korean actors researching intrusion tools, deceptive employment, and online scams. OpenAI also describes sharing malware-related indicators discovered in model conversations so other defenders could detect the files.

HOW TO READ THIS SOURCE

Selected investigations combine model activity and outside evidence. Attribution is qualified; the cyber section reports no novel capability from the model responses.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026
Google Threat Intelligence Group

An early baseline of tracked government-backed groups using Gemini for research, coding and persuasive content. Google found productivity benefits, but no novel attack capabilities in the activity it analyzed.

HOW TO READ THIS SOURCE

Analysis centers on Gemini web-app use by tracked groups. Prompts show attempted assistance, not necessarily deployment, success or the wider prevalence of AI attacks.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026
OpenAI

Three cyber case studies cover blocked phishing aimed at OpenAI employees, research into industrial control systems, and Android malware development. They show AI supporting established attacker tasks alongside a separate set of influence operations.

HOW TO READ THIS SOURCE

SweetSpecter, CyberAv3ngers and STORM-0817 have separate evidence and outcomes. The report does not establish that AI caused earlier infrastructure attacks attributed to those groups.

FURTHER READING

Background reading. No individual case from this report is currently linked in the incident library.

Catalog entry reviewed Sep 11, 2026

Read the source, then check what it establishes. A provider’s disclosure, an affected organization’s account, and an independent review offer different perspectives. Inclusion is not endorsement or independent confirmation.

Download the catalog
FROM EVIDENCE TO DEFENSE

Looking for security guidance?

NIST, OWASP, NCSC, and CISA guidance is collected with the AI security framework. Those sources explain practices for defenders; they are distinct from incident reports.

Explore the guidance sources