{"attribution":{"source":"AI Incident Database (Responsible AI Collaborative)","license":"CC BY-SA 4.0","license_url":"https://creativecommons.org/licenses/by-sa/4.0/","citation":"McGregor, S. (2021). Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. Proceedings of the AAAI Conference on Artificial Intelligence (IAAI-21).","snapshot_date":"2026-09-07"},"exported_at":"2026-09-11"}
{"rows":[{"incident_id":1430,"occurred_on":"2025-12-01","title":"Anthropic's Claude Was Reportedly Jailbroken To Allegedly Help Steal Sensitive Mexican Government Data","description":"An unknown attacker reportedly jailbroke Anthropic's Claude and used it during a December 2025-January 2026 campaign against Mexican government systems. According to Gambit Security, the attacker used Claude to identify vulnerabilities and to generate exploitation scripts, which were then used to plan automated data theft. The attack reportedly contributed to theft of 150 GB of taxpayer, voter, government employee, and civil-registry data.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Unknown Hacker"],"developers":["Anthropic"],"harmed":["Mexican Taxpayers, Mexican Voters, Mexican Government Employees, State Government Of Tamaulipas, State Government Of Michoacan, State Government Of Jalisco, Monterrey Water And Drainage Services, Servicio De Administracion Tributaria (Sat), Instituto Nacional Electoral (Ine), Direccion General Del Registro Civil De La Ciudad De Mexico (Dgrc)"],"report_count":2},{"incident_id":1238,"occurred_on":"2025-10-10","title":"OpenAI ChatGPT Models Reportedly Jailbroken to Provide Chemical, Biological, and Nuclear Weapons Instructions","description":"An NBC News investigation found that OpenAI's language models o4-mini, GPT-5-mini, oss-20b, and oss-120b could be jailbroken under normal usage conditions to bypass safety guardrails and generate detailed instructions for creating chemical, biological, and nuclear weapons. Using a publicly documented jailbreak prompt, reporters repeatedly elicited hazardous outputs such as steps to synthesize pathogens or maximize harm with chemical agents. The findings reportedly revealed significant real-world","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai"],"harmed":["Public Safety, National Security And Intelligence Stakeholders, General Public"],"report_count":1},{"incident_id":1201,"occurred_on":"2025-08-27","title":"Anthropic Reportedly Identifies AI Misuse in Extortion Campaigns, North Korean IT Schemes, and Ransomware Sales","description":"In August 2025, Anthropic published a threat intelligence report detailing multiple misuse cases of its Claude models. Documented abuses included a large-scale extortion campaign using Claude Code against at least 17 organizations, fraudulent remote employment schemes linked to North Korean operatives, and the development and sale of AI-generated ransomware. Anthropic banned the accounts, implemented new safeguards, and shared indicators with authorities.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Ransomware As A Service Actors, North Korean It Operatives, Government Of North Korea, Cybercriminals"],"developers":["Anthropic"],"harmed":["Religious Institutions, National Security And Intelligence Stakeholders, Healthcare Organizations, Government Agencies, General Public, Fortune 500 Technology Companies, Epistemic Integrity, Emergency Services, Consumers Targeted By Ransomware"],"report_count":3},{"incident_id":1220,"occurred_on":"2025-07-10","title":"LAMEHUG Malware Reportedly Integrates Large Language Model for Real-Time Command Generation in a Purported APT28-Linked Cyberattack","description":"Ukraine's CERT-UA and Cato CTRL reported LAMEHUG, the first known malware to integrate a large language model (Qwen2.5-Coder-32B-Instruct via Hugging Face) for real-time command generation. Attributed with moderate confidence to APT28 (Fancy Bear), the malware reportedly targeted Ukrainian officials through phishing emails. The LLM is reported to have dynamically generated reconnaissance and data-exfiltration commands executed on infected systems.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Fancy Bear, Apt28"],"developers":["Hugging Face, Alibaba"],"harmed":["Ukrainian Government Officials, Ukrainian Government Ministries, State Institutions Targeted By Espionage Operations, Public Sector Information Systems, National Cybersecurity Infrastructure Of Ukraine, Government Of Ukraine, National Security And Intelligence Stakeholders"],"report_count":2},{"incident_id":1160,"occurred_on":"2025-06-05","title":"Reported AI-Aided Development of Explosive Devices by Long Island Resident Michael Gann","description":"Federal prosecutors allege that Michael Gann, a 55-year-old Long Island man, used AI tools to identify chemicals and instructions for making improvised explosive devices. He allegedly built seven bombs, transported them to Manhattan, and stored five with shotgun shells on a rooftop. Authorities say he tested and discarded some devices in public areas before his June 5, 2025 arrest. Gann faces federal charges; no injuries were reported.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Michael Gann"],"developers":["Generative Ai Developers"],"harmed":["General Public Of New York City"],"report_count":1},{"incident_id":1104,"occurred_on":"2025-05-17","title":"AI Chatbot Allegedly Used to Research Explosive Materials in Palm Springs Fertility Clinic Bombing","description":"An unnamed AI chatbot was reportedly used by Guy Edward Bartkus and Daniel Park, the perpetrators of the 2025 Palm Springs fertility clinic bombing, to research explosive materials and optimize fuel mixtures. Records show the chatbot responded to queries related to ammonium nitrate fuel oil (ANFO) composition. The bombing resulted in one death, four injuries, and significant structural damage.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Guy Edward Bartkus, Daniel Park"],"developers":["Large Language Model Developers"],"harmed":["Staff Of American Reproductive Centers In Palm Springs, Patients Of American Reproductive Centers In Palm Springs, Occupants And Residents Of Buildings Adjacent To American Reproductive Centers In Palm Springs, American Reproductive Centers In Palm Springs"],"report_count":3},{"incident_id":1487,"occurred_on":"2025-04-17","title":"ChatGPT Was Alleged to Have Aided Planning of Florida State University Mass Shooting","description":"On April 17, 2025, a shooting at Florida State University killed Tiru Chabba and Robert Morales and injured others. Phoenix Ikner, the accused shooter, has pleaded not guilty. In 2026, victims' families and attorneys reportedly alleged that Ikner used ChatGPT before the attack to discuss mass shootings, firearms, campus activity, and media attention, and that OpenAI failed to flag or escalate the exchanges. OpenAI denied responsibility.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Phoenix Ikner, Openai"],"developers":["Openai"],"harmed":["Tiru Chabba'S Family, Tiru Chabba, Robert Morales'S Family, Robert Morales, Florida State University Shooting Victims, Florida State University Campus Community, Students, University Students, Educational Communities"],"report_count":46},{"incident_id":1015,"occurred_on":"2025-04-07","title":"Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform","description":"Xanthorox AI is a malicious, modular AI system released on darknet forums in early 2025. Designed from scratch for offensive cyber operations, it runs on private infrastructure and includes models for code generation, phishing, malware, social engineering, and real-time voice/image input. Its release represents a deliberate deployment of an autonomous attack platform.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Unknown Malicious Actors, Darknet Forum Users, Cybercriminals"],"developers":["Xanthorox Ai Creators, Unknown Black Hat Ai Developers"],"harmed":["Victims Of Phishing Attacks, Victims Of Malware Attacks, Victims Of Automated Cybercrime, General Public, Enterprise It Systems, Critical Infrastructure Systems"],"report_count":3},{"incident_id":1490,"occurred_on":"2025-03-05","title":"ChatGPT Was Allegedly Consulted About Attack Options Before Teen Attempted to Stab Officer at Tira, Israel, Police Station","description":"A 16-year-old from Tira, Israel, allegedly entered the city's police station with a knife and attempted to stab a Border Police officer. Prosecutors reportedly alleged that before the attack he had consulted ChatGPT about possible attacks and courses of action. He was charged in juvenile court with attempted aggravated assault as an act of terror. Public reporting does not establish what responses ChatGPT provided or whether they materially assisted the attempted attack.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Tira Israel Police Station Attempted Stabbing Suspect, Openai"],"developers":["Openai"],"harmed":["Tira Israel Police Station Personnel, Israeli Border Police Officers, Israel Law Enforcement"],"report_count":2},{"incident_id":886,"occurred_on":"2024-12-27","title":"ChatGPT Reportedly Referenced During Las Vegas Cybertruck Explosion Planning","description":"Matthew Livelsberger, the suspect in the 2025 Las Vegas Cybertruck explosion, reportedly used ChatGPT to search for publicly available information on explosives, ammunition, and fireworks regulations. ChatGPT is alleged to have played a role in the planning of the explosion outside the Trump International Hotel in Las Vegas. The information provided by ChatGPT, though, was reportedly general and available through other public sources.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai, Matthew Livelsberger"],"developers":["Openai"],"harmed":["Seven Injured Victims In Las Vegas, Matthew Livelsberger, Bystanders And Guests Of The Trump International Hotel In Las Vegas"],"report_count":5},{"incident_id":672,"occurred_on":"2024-04-03","title":"'Lavender' and 'The Gospel' AI Systems Reportedly Used in Gaza Targeting Operations with Civilian Harm Allegations","description":"The AI system known as \"Lavender\" was reportedly used by the Israel Defense Forces (IDF) to assist in identifying individuals in Gaza for targeting, while a related system, \"The Gospel,\" was reportedly used to help select and prioritize physical strike targets. Investigations reportedly suggest that these systems operated with limited human review and may have contributed to strikes associated with high civilian casualties. The extent of automation with human oversight, as well as the accuracy o","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Unit 8200, Israel Defense Forces"],"developers":["Unit 8200, Israel Defense Forces"],"harmed":["Palestinians, Gazans, National Security And Intelligence Stakeholders"],"report_count":9},{"incident_id":736,"occurred_on":"2023-12-01","title":"Underground Market for LLMs Powers Malware and Phishing Scams","description":"A study by Indiana University researchers uncovered widespread misuse of large language models (LLMs) for cybercrime. Cybercriminals, according to that study, use LLMs like OpenAI's GPT-3.5 and GPT-4 to create malware, phishing scams, and scam websites. These models are available on underground markets, often bypassing safety checks through jailbreaking. Named malicious LLMs are BadGPT, XXXGPT, Evil-GPT, WormGPT, FraudGPT, BLACKHATGPT, EscapeGPT, DarkGPT, and WolfGPT.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Cybercriminals, Badgpt, Xxxgpt, Evil Gpt, Wormgpt, Fraudgpt, Blackhatgpt, Escapegpt, Darkgpt, Wolfgpt"],"developers":["Openai"],"harmed":["Internet Users, Organizations, Individuals Targeted By Malware"],"report_count":2},{"incident_id":443,"occurred_on":"2022-12-21","title":"ChatGPT Abused to Develop Malicious Softwares","description":"OpenAI's ChatGPT was reportedly abused by cyber criminals including ones with no or low levels of coding or development skills to develop malware, ransomware, and other malicious softwares.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai"],"harmed":["Internet Users"],"report_count":25},{"incident_id":121,"occurred_on":"2020-03-27","title":"Autonomous Kargu-2 Drone Allegedly Remotely Used to Hunt down Libyan Soldiers","description":"In Libya, a Turkish-made Kargu-2 aerial drone powered by a computer vision model was allegedly used remotely by forces backed by the Tripoli-based government to track down and attack enemies as they were running from rocket attacks.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":"AI tangible harm near-miss","sectors":["defense"],"countries":["LY"],"deployers":["Tripoli Based Government"],"developers":["Stm"],"harmed":["Libyan Soldiers"],"report_count":3},{"incident_id":329,"occurred_on":"2017-09-18","title":"Amazon Reportedly Recommends Explosive-Producing Ingredients as 'Frequently Bought Together' Items for Chemicals","description":"Amazon was reported to have shown chemical combinations for producing explosives and incendiary devices as \"frequently bought together\" items via automated recommendation.","mit_domain":"Malicious Actors & Misuse","mit_subdomain":"Cyberattacks, weapon development or use, and mass harm","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":"none","sectors":["wholesale and retail trade"],"countries":[],"deployers":["Amazon"],"developers":["Amazon"],"harmed":["Amazon Users"],"report_count":2}]}