AI Incident Database
Browse AI incidents
Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.
-
Anthropic's Claude Was Reportedly Jailbroken To Allegedly Help Steal Sensitive Mexican Government Data AIID ↗
An unknown attacker reportedly jailbroke Anthropic's Claude and used it during a December 2025-January 2026 campaign against Mexican government systems. According to Gambit Security, the attacker used Claude to identify vulnerabilities and to generate exploitation scripts, which were then used to plan automated data theft. The attack reportedly contributed to theft of 150 GB of taxpayer, voter, government employee, and civil-registry data.
-
OpenAI ChatGPT Models Reportedly Jailbroken to Provide Chemical, Biological, and Nuclear Weapons Instructions AIID ↗
An NBC News investigation found that OpenAI's language models o4-mini, GPT-5-mini, oss-20b, and oss-120b could be jailbroken under normal usage conditions to bypass safety guardrails and generate detailed instructions for creating chemical, biological, and nuclear weapons. Using a publicly documented jailbreak prompt, reporters repeatedly elicited hazardous outputs such as steps to synthesize pathogens or maximize harm with chemical agents. The findings reportedly revealed significant real-world
-
Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales AIID ↗
In August 2025, Anthropic published a threat intelligence report detailing multiple misuse cases of its Claude models. Documented abuses included a large-scale extortion campaign using Claude Code against at least 17 organizations, fraudulent remote employment schemes linked to North Korean operatives, and the development and sale of AI-generated ransomware. Anthropic banned the accounts, implemented new safeguards, and shared indicators with authorities.
-
LAMEHUG Malware Reportedly Integrates Large Language Model for Real-Time Command Generation in a Purported APT28-Linked Cyberattack AIID ↗
Ukraine's CERT-UA and Cato CTRL reported LAMEHUG, the first known malware to integrate a large language model (Qwen2.5-Coder-32B-Instruct via Hugging Face) for real-time command generation. Attributed with moderate confidence to APT28 (Fancy Bear), the malware reportedly targeted Ukrainian officials through phishing emails. The LLM is reported to have dynamically generated reconnaissance and data-exfiltration commands executed on infected systems.
-
Reported AI-Aided Development of Explosive Devices by Long Island Resident Michael Gann AIID ↗
Federal prosecutors allege that Michael Gann, a 55-year-old Long Island man, used AI tools to identify chemicals and instructions for making improvised explosive devices. He allegedly built seven bombs, transported them to Manhattan, and stored five with shotgun shells on a rooftop. Authorities say he tested and discarded some devices in public areas before his June 5, 2025 arrest. Gann faces federal charges; no injuries were reported.
-
AI Chatbot Allegedly Used to Research Explosive Materials in Palm Springs Fertility Clinic Bombing AIID ↗
An unnamed AI chatbot was reportedly used by Guy Edward Bartkus and Daniel Park, the perpetrators of the 2025 Palm Springs fertility clinic bombing, to research explosive materials and optimize fuel mixtures. Records show the chatbot responded to queries related to ammonium nitrate fuel oil (ANFO) composition. The bombing resulted in one death, four injuries, and significant structural damage.
-
ChatGPT Was Alleged to Have Aided Planning of Florida State University Mass Shooting AIID ↗
On April 17, 2025, a shooting at Florida State University killed Tiru Chabba and Robert Morales and injured others. Phoenix Ikner, the accused shooter, has pleaded not guilty. In 2026, victims' families and attorneys reportedly alleged that Ikner used ChatGPT before the attack to discuss mass shootings, firearms, campus activity, and media attention, and that OpenAI failed to flag or escalate the exchanges. OpenAI denied responsibility.
-
Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform AIID ↗
Xanthorox AI is a malicious, modular AI system released on darknet forums in early 2025. Designed from scratch for offensive cyber operations, it runs on private infrastructure and includes models for code generation, phishing, malware, social engineering, and real-time voice/image input. Its release represents a deliberate deployment of an autonomous attack platform.
-
ChatGPT Was Allegedly Consulted About Attack Options Before Teen Attempted to Stab Officer at Tira, Israel, Police Station AIID ↗
A 16-year-old from Tira, Israel, allegedly entered the city's police station with a knife and attempted to stab a Border Police officer. Prosecutors reportedly alleged that before the attack he had consulted ChatGPT about possible attacks and courses of action. He was charged in juvenile court with attempted aggravated assault as an act of terror. Public reporting does not establish what responses ChatGPT provided or whether they materially assisted the attempted attack.
-
ChatGPT Reportedly Referenced During Las Vegas Cybertruck Explosion Planning AIID ↗
Matthew Livelsberger, the suspect in the 2025 Las Vegas Cybertruck explosion, reportedly used ChatGPT to search for publicly available information on explosives, ammunition, and fireworks regulations. ChatGPT is alleged to have played a role in the planning of the explosion outside the Trump International Hotel in Las Vegas. The information provided by ChatGPT, though, was reportedly general and available through other public sources.
-
'Lavender' and 'The Gospel' AI Systems Reportedly Used in Gaza Targeting Operations with Civilian Harm Allegations AIID ↗
The AI system known as "Lavender" was reportedly used by the Israel Defense Forces (IDF) to assist in identifying individuals in Gaza for targeting, while a related system, "The Gospel," was reportedly used to help select and prioritize physical strike targets. Investigations reportedly suggest that these systems operated with limited human review and may have contributed to strikes associated with high civilian casualties. The extent of automation with human oversight, as well as the accuracy o
-
Underground Market for LLMs Powers Malware and Phishing Scams AIID ↗
A study by Indiana University researchers uncovered widespread misuse of large language models (LLMs) for cybercrime. Cybercriminals, according to that study, use LLMs like OpenAI's GPT-3.5 and GPT-4 to create malware, phishing scams, and scam websites. These models are available on underground markets, often bypassing safety checks through jailbreaking. Named malicious LLMs are BadGPT, XXXGPT, Evil-GPT, WormGPT, FraudGPT, BLACKHATGPT, EscapeGPT, DarkGPT, and WolfGPT.
-
ChatGPT Abused to Develop Malicious Softwares AIID ↗
OpenAI's ChatGPT was reportedly abused by cyber criminals including ones with no or low levels of coding or development skills to develop malware, ransomware, and other malicious softwares.
-
Autonomous Kargu-2 Drone Allegedly Remotely Used to Hunt down Libyan Soldiers AIID ↗
In Libya, a Turkish-made Kargu-2 aerial drone powered by a computer vision model was allegedly used remotely by forces backed by the Tripoli-based government to track down and attack enemies as they were running from rocket attacks.
-
Amazon Reportedly Recommends Explosive-Producing Ingredients as 'Frequently Bought Together' Items for Chemicals AIID ↗
Amazon was reported to have shown chemical combinations for producing explosives and incendiary devices as "frequently bought together" items via automated recommendation.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.