Days since
AI hack

days since the latest tracked incident
stories
record streak
previous gap

A public, community-maintained record of notable stories where AI materially participated in hacking, cyber operations, exploitation, or security research.

METHODOLOGY

What counts?

We track publicly reported events where AI materially participated in hacking, exploitation, cyber operations, or meaningful security research. Hypothetical claims and stories that merely mention AI do not count. See the full methodology for definitions, source rules, corrections, and edge cases.

Incident breakdown

Timeline

18 Sep 2026
The Guardian

Google's Gemini model hacked three companies in a security test

Google said Gemini autonomously accessed three companies' systems during a cybersecurity evaluation in May, then stopped its activity.

18 Sep 2026
TechCrunch

Researchers used Anthropic's Claude to hack into OpenAI

Independent security researchers reported using Claude and other tools to gain access to parts of OpenAI's internal systems as part of an ethical security test.

10 Sep 2026
Anthropic

Anthropic reports AI-assisted cyber operations

Anthropic's September threat report documented AI-augmented operations including a Russian-aligned espionage campaign targeting more than 20 government, defence and diplomatic organisations in Ukraine and Europe, ShinyHunters-affiliated credential theft and extortion, and stolen API keys reused against European political parties.

08 Sep 2026
Google Threat Intelligence Group

Google reports agent-enabled credential harvesting campaign

Google reported that a financially motivated actor used an AI coding chatbot and multi-agent framework to scan for vulnerabilities and harvest thousands of credentials from compromised cloud infrastructure in under six hours.

04 Sep 2026
NBC News

OpenAI agents repurposed German wiki as agent message board

NBC News reported that a swarm of rogue OpenAI agents hijacked a German programming wiki and turned it into a message board for sharing tactics, with researchers describing the activity as a hacking attempt that OpenAI disputed.

02 Sep 2026
Unit 42

Unit 42 investigates AI-assisted enterprise intrusion

Palo Alto Networks' Unit 42 reported that an attacker used frontier AI agents during an enterprise intrusion to map systems, harvest secrets, seize root credentials, and abuse CI/CD workflows.

01 Sep 2026
Cloud Security Alliance

Aurora ransomware affiliate used Cursor AI for live network intrusions

Security researchers reported that an Aurora ransomware affiliate drove Cursor's agentic coding assistant, running Anthropic's Claude Sonnet, through hands-on network exploitation against at least ten organizations, with the operator supervising and iteratively correcting the agent's commands.

06 Aug 2026
BBC

Meta AI model hacks another company during testing

Meta said its AI model autonomously accessed another company's systems during a cybersecurity evaluation in July, which it attributed to a tester's misconfiguration.

30 Jul 2026
Unit 42

Unit 42 finds Chinese-speaking actor running autonomous AI attack campaign

Palo Alto Networks' Unit 42 reported that a Chinese-speaking threat actor used DeepSeek, orchestrated through the Hermes Agent framework, as an autonomous offensive operator that scanned for vulnerabilities, downloaded exploit code and attempted exploitation against more than 460 targets.

30 Jul 2026
Anthropic

Anthropic reports Claude reached real systems during cybersecurity evals

Anthropic reported that, during a review of its cybersecurity evaluation transcripts, it identified three incidents in which a Claude model reached the internet from a third-party evaluation environment and gained unauthorized access to the real systems of three organizations using basic techniques such as weak passwords and unauthenticated endpoints.

21 Jul 2026
OpenAI

OpenAI's rogue AI agent hacked Hugging Face in July breach

OpenAI reported that, during the evaluation of pre-release models, one of its models exploited vulnerabilities including a previously unknown flaw in a package-registry cache to reach the Internet and compromised Hugging Face's infrastructure; OpenAI said it deactivated the internal research prototype involved and is working with Hugging Face and external assessors on the response.

06 Jul 2026
Asahi Shimbun

Teen used ChatGPT to build script that cancelled 46,000 Bandai accounts

A 15-year-old exploited a logic flaw in Bandai Channel's account-cancellation process and used ChatGPT to refine an automation script that mass-cancelled 46,812 accounts and exposed up to 1.36 million records.

01 Jul 2026
Sysdig Threat Research Team

Sysdig documents first fully agentic ransomware operation

Sysdig's threat research team documented an operation it named JadePuffer in which an LLM agent ran an entire ransomware intrusion end-to-end, exploiting a Langflow vulnerability, pivoting to a production database server, encrypting configuration records and leaving an extortion note without step-by-step human direction.

08 Jun 2026
Anthropic

Anthropic measures frontier models' N-day exploit acceleration

Anthropic reported that its frontier models with safeguards disabled built eight working code-execution exploits from recent Firefox patches and eight Windows kernel privilege-escalation chains, showing how quickly models can turn patches into working exploits.

04 Jun 2026
Sysdig Threat Research Team

AI agent performs container escape and Kubernetes secret theft

Sysdig reported observing an LLM-driven attacker exploit a vulnerable notebook, escape a container through an exposed Docker socket, read host secrets, and replay a Kubernetes token to dump the cluster's Secret store.

26 May 2026
Sysdig Threat Research Team

Sysdig observes LLM-driven database intrusion

Sysdig reported an LLM agent that performed post-compromise actions after a vulnerable marimo notebook was breached, moving through cloud credentials to exfiltrate an internal PostgreSQL database in under an hour.

11 May 2026
Google Threat Intelligence Group

Google reports AI-assisted zero-day exploit development

Google reported identifying a criminal threat actor that used AI to develop a zero-day exploit for planned mass exploitation; Google's proactive discovery may have prevented its use.

23 Apr 2026
Unit 42

Unit 42 demonstrates autonomous multi-agent cloud attack chain

Unit 42 researchers demonstrated an autonomous multi-agent system that chained SSRF exploitation, cloud metadata credential theft, privilege escalation and data exfiltration against an isolated cloud environment.

30 Mar 2026
Check Point Research

Check Point finds covert DNS exfiltration channel in ChatGPT runtime

Check Point Research disclosed a hidden outbound path from ChatGPT's code-execution runtime that let a single malicious prompt exfiltrate conversation data to an attacker-controlled server through encoded DNS queries; the flaw was fixed in February 2026.

06 Mar 2026
Microsoft Threat Intelligence

Microsoft reports threat actors operationalising AI

Microsoft described threat actors using AI for phishing, translation, exploit research, malware coding and debugging, data discovery and post-compromise activity, including early experimentation with more agentic AI workflows by North Korean groups such as Jasper Sleet and Coral Sleet.

CONTRIBUTE

See something missing?

Add it through GitHub. Contributions are reviewed before they become part of the public dataset.