AI Incident Monitor
Real-world AI harms, logged as they happen.
Updated Sep 10, 2026
By harm type
Recent incidents
A self-driving car in Texas hit and killed a mother duck, sparking neighborhood outrage
The death of a duck in the Austin, Texas enclave of Mueller Lake has neighbors raising concerns about autonomous vehicles and whether they belong there. While humans are responsible for killing animals with their cars all the time, this in…
Source: AI Incident Database
LYFT DRIVER SCAM: Boca Raton Area Driver Uses AI To Accuse Rider
A driver for ride share company "Lyft" is being closely monitored by the platform after he was accused of using artificial intelligence to claim a rider trashed his car. The rider, a teenage girl who lives in Boca Raton, was accused by the…
Source: AI Incident Database
Justice Department Files to Intervene and Dismiss Lawsuit that Would Hamper America’s AI Innovation and Security
Note: View motion for intervention and dismissal here. Yesterday, the Justice Department's Environment and Natural Resources Division (ENRD) filed a motion to intervene and to dismiss a private citizen lawsuit seeking to power down a large…
Source: AI Incident Database
‘A different set of rules’: thermal drone footage shows Musk’s AI power plant flouting clean air regulations
Elon Musk’s artificial intelligence company is continuing to fuel its datacenters with unpermitted gas turbines, an investigation by the Floodlight newsroom shows. Thermal footage captured by Floodlight via drone shows xAI is still burning…
Source: AI Incident Database
Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw
Overview On February 17, 2026 at 11:40 UTC, the StepSecurity npm monitoring system detected a suspicious release of the cline npm package. Version 2.3.0 of this widely-used autonomous coding agent CLI was published with a malicious post-in…
Source: AI Incident Database
ChatGPT Operator: Prompt Injection Exploits & Defenses
ChatGPT Operator is a research preview agent from OpenAI that lets ChatGPT use a web browser. It uses vision and reasoning abilities to complete tasks like researching topics, booking travel, ordering groceries, or as this post will show, s…
Source: AI Incident Database
DC court faults lawyers for Deutsche Bank subsidiary over AI hallucination
The District of Columbia Court of Appeals said in a ruling on Thursday, opens new tab that lawyers for a Deutsche Bank subsidiary in a mortgage foreclosure lawsuit cited nonexistent cases generated by artificial intelligence, calling the m…
Source: AI Incident Database
A Hacking Tool Built With A.I. Can Breach Phones Without a Click
A friend you haven't heard from in a while suddenly calls. You don't pick up, but in a matter of seconds, the damage is already done. The call wasn't actually from an old companion looking to reconnect, but from a hacker who had hijacked t…
Source: AI Incident Database
AI scams in Georgia and South Florida: How scammers use deepfakes to steal millions
Artificial intelligence is no longer just helping people write emails or generate images. Investigators say it's also helping scammers steal money by making fake voices, photos and phone calls look and sound frighteningly real. For one Sou…
Source: AI Incident Database
Georgia couple loses $800K in sophisticated cryptocurrency scam
The Brief A Georgia couple lost nearly $800,000 in a cryptocurrency scam initiated through a WhatsApp message, leaving them financially devastated. The scam involved a legitimate-looking mobile trading app and an AI-generated "ghost site"…
Source: AI Incident Database
How Claude Code escapes its own denylist and sandbox
In the last ten days: a single person used Claude to breach Mexican government agencies. Cline's own AI-powered triage workflow was compromised via prompt injection. A new Shai-Hulud variant started injecting rogue MCP servers into develope…
Source: AI Incident Database
Cline CLI npm Package Compromised via Suspected Cache Poisoning Attack
On February 17, 2026, an unauthorized party used a compromised npm publish token to push cline@2.3.0 to the npm registry. Cline is a popular AI coding agent CLI in the developer ecosystem, with around 90,000 weekly downloads from npm. The m…
Source: AI Incident Database
California regulators rushed their decision on driverless trucks, Teamsters’ lawsuit says
As self-driving vehicles spread across the country, a major California labor union is taking a stand against state regulators who say autonomous trucks are ready for the road. Teamsters California sued the California Department of Motor Ve…
Source: AI Incident Database
AI agent at the wheel: How an attacker used LLMs to move from a CVE to an internal database in 4 pivots
Key Findings An LLM agent executed the post-compromise actions in real time rather than running a pre-built playbook. This is the first AI-agent-driven intrusion the Sysdig TRT has captured. The full attack chain --- marimo notebook compr…
Source: AI Incident Database
OpenAI’s GPT-5.6 Sol users report missing files, deleted databases: Here’s what we know
Amid the buzz and excitement surrounding GPT-5.6 Sol, OpenAI's latest coding and cybersecurity-focused flagship AI model, recent posts across social media suggest that the model's rollout may have hit a few bumps. Several users on X and Re…
Source: AI Incident Database
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining initial access following the exploitation of a publicly-accessible Marimo network using a recently disclos…
Source: AI Incident Database
Hermes AI agent used to automate attack on Thai Finance Ministry
A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. The activity was uncovered by threat intelligence company Hunt…
Source: AI Incident Database
AI Agent Conducted a Cyberattack on Its Own — It Took Less Than One Hour
AIID editor's note: Please visit the original source for the full report. Researchers discovered an intrusion conducted by a large language model (LLM) agent while it was in the post-exploitation phase. According to the researchers, this c…
Source: AI Incident Database
Scammers use AI to impersonate immigration attorneys to dupe immigrants with fake legal services
Last October, immigration lawyer Angel Leal realized he had a serious problem when immigrants began calling his office about their supposed legal cases. He had never advised them. "They had in fact hired scammers" who had impersonated him.…
Source: AI Incident Database
Oura, Smart Ring Maker, Sued for Alleged False Claims and Unreliable AI
A lawsuit has been filed against the well-known smart ring brand Oura, alleging the company used false advertising by deceiving users about the accuracy of its AI-generated sleep tracking. The suit, filed Thursday by Clarkson Law Firm in Sa…
Source: AI Incident Database
AI deepfake scams 'an emergency in the making' as ASIC reports rise in false investment endorsements
Scammers are using impersonations of celebrities, politicians and trusted public figures to promote fake investment schemes, with the corporate watchdog warning AI is making the practice increasingly common, sophisticated and harder to dete…
Source: AI Incident Database
Minnesota lawyer suspended over fake AI case citations
The city of Biwabik is known for its Bavarian-themed downtown, mountain bike trails, and as the gateway to Minnesota's Mesabi Iron Range. But the St. Louis County community of 966 people was never a defendant in a 1948 lawsuit filed by a pl…
Source: AI Incident Database
ASIC warns scammers are using AI to spin vast webs of deception
ASIC is warning Australians that a quick online search is not enough to verify investment opportunities as scammers use generative AI to create vast networks of deepfake websites and endorsements to lure victims. ASIC has seen a sharp rise…
Source: AI Incident Database
Russian-speaking cybercriminals used SpaceX’s Cursor AI tool to hack seven companies
Russian-speaking hackers used SpaceX's (SPCX.O), opens new tab AI coding assistant, Cursor, to help break in to a Belgian chemical company and at least six other firms earlier this year, according to data reviewed by Reuters and reports iss…
Source: AI Incident Database
A Pizza Hut franchisee is suing over a forced AI system it says wrecked deliveries
A lawsuit filed May 6 in Texas Business Court puts Chaac Pizza Northeast --- a franchisee running roughly 111 Pizza Hut locations spanning New York, New Jersey, Maryland, Washington, D.C., and Pennsylvania --- at the center of a dispute ove…
Source: AI Incident Database
Frustrated franchisee sues Pizza Hut over crappy kitchen AI
The back-of-house AI system that Pizza Hut has mandated its restaurants to adopt has been so poorly received by some franchisees, that one is suing the company for $100 million in losses tied to the technology. Put that in your crust and st…
Source: AI Incident Database
Pizza Hut franchisee says AI caused $100M in damages
Dive Brief: Pizza Hut franchisee Chaac Pizza Northeast has sued the franchisor, alleging the chain's Dragontail Artificial Intelligence system caused "cascading operational breakdowns," slowed down order times and disrupted integrations wi…
Source: AI Incident Database
Breaking Claude Code Opus 5 Auto Mode
In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success rate using a small sample size. 
 
 This is interesting because a third-party evaluation commissioned by Anthropic showed a 0.00% prompt injection attack success rate for Opus 5 in Auto Mode. 
 Auto Mode Is Now the Default in Claud
Source: Embrace The Red
Legal resident loses thousands seeking citizenship to AI immigration attorney
NEW YORK (WABC) -- It's a perfect storm where online scammers use artificial intelligence to victimize vulnerable people out of thousands of dollars, with many losing their life savings, and immigrants are increasingly the target. Not only…
Source: AI Incident Database
Listen to the AI-Generated Ripoff Songs That Got Udio and Suno Sued
Some of the world's largest record labels sued both Udio and Suno, two of the most popular AI music generators, accusing them of not only scraping huge amounts of music without permission or compensation but also of directly reproducing sec…
Source: AI Incident Database
Warner Music Group settles lawsuit with AI firm Suno
Warner Music Group on Tuesday announced a partnership with AI business Suno that will compensate music artists and songwriters, ending a legal battle between the two companies. Suno allows users to write text prompts to create songs. Last…
Source: AI Incident Database
Hack Reveals Suno AI Music Generator Scraped YouTube, Deezer, and Genius
The AI music generation tool Suno scraped millions of songs and lyrics from YouTube Music, Deezer, and Genius, as well as from the stock music libraries Pond5, Jamendo, Freesound, the International Music Score Library Project, and podcasts…
Source: AI Incident Database
Suno loses copyright infringement lawsuit brought by GEMA in Germany
AI music generator Suno has lost the copyright infringement lawsuit brought by German collecting society GEMA. The collecting society alleged that Suno used, stored and reproduced copyrighted music to train its AI tool without a license or…
Source: AI Incident Database
Music AI startups Suno and Udio slam record label lawsuits in court filings
Aug 1 (Reuters) - Artificial-intelligence startups Suno and Udio responded in federal court on Thursday to copyright lawsuits brought by music labels Universal Music Group, Warner Music Group and Sony Music over their music-generating AI sy…
Source: AI Incident Database
Suno and Udio hit with class action lawsuits from independent artist
Suno and Udio have been slapped with another round of copyright litigation, this time by country musician Tony Justice, who filed class-action lawsuits against both controversial AI music generators. The complaints allege Suno and Udio use…
Source: AI Incident Database
Record labels claim AI generator Suno illegally ripped their songs from YouTube
Major record labels have escalated their lawsuit against Suno, alleging that the AI startup knowingly pirated songs from YouTube to train its generative AI music models. In the amended complaint filed on September 19th, the Recording Indust…
Source: AI Incident Database
Class Action Lawyers Fight for Indie Artists Exploited by Generative AI Training
Two class action lawsuits are in the works against two major AI companies, Udio and Suno, on behalf of independent artists. Lawyers at Delgado Entertainment Law and Hagens Berman have urged indie artists to get involved in the lawsuits. Thi…
Source: AI Incident Database
Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories
Cryptographic Context Injection ships attacker instructions as ciphertext the model decrypts in its own sandbox. It leaked full Grok chat histories, zero-click.
Source: Adversa AI
Nine AI coding agent incidents that ended with deleted data
Nine documented AI coding agent incidents, from Cursor and Gemini CLI to Replit, Kiro and Claude Opus 5. What each agent did and why the guardrails failed.
Source: Adversa AI
A hole in every one: bypassing the open source AI skill scanners
We ran eight open source AI skill scanners against real attacks. A malicious skill got past all eight, including the current OASB leaderboard leader.
Source: Adversa AI
The AI agent sandbox escape that breached Hugging Face: what happened, and what to fix
An OpenAI benchmark agent escaped its sandbox and breached Hugging Face, logging 17,000+ actions. What the evidence shows, what's unproven, and what to fix.
Source: Adversa AI
Solving GitHub's Secure Code game with an AI red teaming agent
How our AI red teaming agent solved all five levels of GitHub's ProdBot challenge, one distinct exploit per level, and what defenders can take from it.
Source: Adversa AI
Top Agentic AI security resources — July 2026
July 2026's agentic AI security roundup: agentic zero trust whitepapers, AutoJack & other new exploits, and the newest agent defenses.
Source: Adversa AI
OWASP ASI03: Identity & Privilege Abuse in AI Agents
OWASP ranks Identity & Privilege Abuse #3 because it sets the blast radius for every other AI agent risk.
Source: Adversa AI
Computer-Use and TOCTOU: What You Click Is Not What You Get!
Last year, Jun Kokatsu disclosed an interesting vulnerability with ChatGPT Operator by exploiting a race condition. I was wondering if I could reproduce this attack chain, and this post describes the results of that research. 
 I had this post drafted for months, and yesterday at the Real-world AI security conference I included a video demo of this attack in my talk and that reminded me that I
Source: Embrace The Red
The AI risk quadrant for agents: scoring 100 digital workers nobody secured
The AIRQ report scores 100 AI agents on attack surface, blast radius, and defenses. The AIRQ framework lets you assess your own stack.
Source: Adversa AI
SymJack: the approval prompt is lying to you. A symlink-hijack RCE in six AI coding agents
A SymJack attack tricks AI coding assistants into RCE through a symlink-disguised file copy. We tested six major tools and every one of them was vulnerable.
Source: Adversa AI
OWASP ASI02: tool misuse and exploitation — the definitive security guide
OWASP ASI02 - full technical guide. How AI agents misuse legitimate tools to wipe drives and delete databases. Plus mitigations and controls that stop it.
Source: Adversa AI
How this is built.Each entry is found by an automated search of public reporting, then screened before it publishes: the source link must resolve, the page’s own headline must match the entry, the host must not be a social post, press-release wire or aggregator index, the named outlet must actually own the page, and the item must describe a single concrete incident rather than a trend piece, survey statistic or guide. Duplicates of the same report are collapsed. This is not a mirror of any single database. The two running totals above are read live from the OECD AI Incidents Monitor and the AI Incident Database, which index far more than we list here. Categories reflect our harm taxonomy and are assigned editorially. For general awareness only: this is not a complete or authoritative record.
Stay Informed
The top news and insights on AI governance, compliance, and ethics delivered to your inbox.