Every AI-enabled attack we can prove happened.
247 publicly documented incidents, charted month by month from January 2024 to August 2026.
June to August 2026 holds more documented incidents than 2024 and 2025 combined.
Loading the ledger…
Mapped to what actually goes wrong.
Every incident is tagged against the six attack classes Salience Cyber was built to see — the four named on the Salience Cyber platform, plus supply chain and synthetic media. An incident can carry more than one tag; most real intrusions do.
Every sparkline runs January 2024 to August 2026 on one shared scale, so the six are directly comparable — a flat line means that class stayed flat, not that it is too small to see. Select a class to filter the timeline.
Who is on the receiving end.
Two dimensions the underlying sources actually support: which ecosystem absorbed the attack, and whether an organisation was breached or a researcher found the hole first.
Both compose with the search, attack class, and date range below.
Where the damage landed
One ecosystem per incident, so these sum to all 247. Click a row to filter.
Breached, or found first?
The cut that matters most: someone was hurt, versus someone found the hole before anyone was.
Theater coverage is thin, and shown as such
Only of 247 entries name where the victim was. The rest are vendor products, packages, or multi-region campaigns with no location on the record.
This is a gap in the underlying catalogs, not a rendering choice. Most entries in an AI-infrastructure incident registry describe a compromised codebase rather than a company in a country, so there is no victim geography to plot. A world map here would chart our metadata coverage rather than the threat. Per-incident victim country and sector can be added, but only by going back to primary sources incident by incident — that is research, not extraction.
Monthly counts behind every chart on this page
The same 32-month series drawn in the hero curve, the density chart above, and the six attack-class sparklines. In view tracks your current filters; the class columns are the unfiltered reference series.
The activity is growing. The AI share of it is the part nobody can measure.
218 published figures, January 2022 to September 2026, ordered by the period each one measures rather than when it was printed. Charted separately from the incident timeline above, which is ordered by disclosure date — the two conventions are months apart and putting them on one axis would draw a difference that does not exist.
And the AI-attributed share of it
Eight published estimates of the same quantity — what share of phishing is AI-generated — spanning 4% to 82.6%. A 20.6× spread. The one estimate drawn from a measured series with a published method puts it at 10%; every figure above 80% is single-source and unverified, and two of them are the same vendor’s telemetry counted twice. One vendor’s own classifier returned 4%, then 56%, then 40% across three consecutive months.None of this says the AI share is small — it says nobody is instrumented to know it. The lowest estimate here is as unsourced as the highest.
What is measurably growing, and is measurably about AI
- AI-related CVEs6922,130per year, 2023 to 2025
- Shadow AI in breaches20%43%of breached organisations
- Own AI models breached13%21%of breached organisations
- Exposed Ray servershundreds200,000+internet-facing, 2024 to 2025
- AI governance coverage37%32%moved backwards
The AI attack surface has a true zero baseline: the evidence base holds no measurements of it for 2022 and one for 2023, because it did not exist at scale. Unlike the macro series above,25 of the 28 findings in this domain carry no counter-evidence. Of the three that do, two are the catalogue compiler’s own methodological notes rather than independent findings; the third reports that AI governance coverage fell. None is a refutation.
The underlying figures
| Series | Source | First | Last | Change |
|---|---|---|---|---|
| Confirmed breaches | Verizon DBIR | 2022 · 5,212 | 2026 · 22,000 | +322% |
| Reported losses | FBI IC3 | 2022 · $10,300m | 2025 · $20,877m | +103% |
| CVEs published | CVE Program | 2023 · 28,818 | 2025 · 48,185 | +67% |
| Reported incidents | FBI IC3 | 2022 · 809,576 | 2025 · 1,008,597 | +25% |
Two catalogs, merged, with every conflict on the record.
This ledger consolidates two independently compiled sources. Where they disagreed on a date, a figure, or an attribution, the conflict was recorded rather than silently resolved — and the entry follows the primary or vendor source.
Figures as a table
| Sources cited | Entries |
|---|---|
| 1 | 29 |
| 2 | 89 |
| 3 | 61 |
| 4 | 31 |
| 5 | 21 |
| 6 | 6 |
| 7 | 2 |
| 8 | 7 |
| 10 | 1 |
Figures as a table
| Threat family | Confirmed | Entries |
|---|---|---|
| Agentic exploitation | 45 | 96 |
| Supply chain | 46 | 72 |
| AI-generated malware | 40 | 64 |
| Shadow AI & exposure | 17 | 57 |
| Prompt injection | 20 | 48 |
| Synthetic media | 4 | 6 |
Where the data comes from
awesome-ai-agent-attacks
A curated chronological timeline of AI agent security incidents, breaches, and vulnerabilities, maintained byDavid Grice. Primary- and vendor-sourced throughout: Anthropic, AWS, Sysdig, Hunt.io, CISA, UK AISI, arXiv.View the repository →
“The Receipts”
A narrative catalog of 32 incidents across 51 footnotes. It contributed coverage the timeline lacked entirely: the GTG-2002 extortion campaign, the five GTIG malware families that call an LLM at runtime, four deepfake-enabled fraud cases, synthetic-identity insider threat, postmark-mcp, and the fourteen-company Claude Code / Codex case. 22 entries here carry its contributions.
Where the two sources disagreed
Where the two sources disagreed
- Mexican government records exfiltrated. 195 million via a secondary aggregator, against roughly 400 million in Check Point’s own report. Command and session counts match exactly, so both derive from the same research — the record counts are measuring different things. Neither figure should be cited bare.
- CyberStrikeAI / FortiGate. Secondary reporting says the models executed custom exploit paths. AWS documented no FortiGate CVE exploitation at all: it was brute-forcing exposed management ports. The AI contribution was scale, not exploitation.
- Step Finance. Secondary reporting attributes the $40M loss to agents transferring treasury without approval. The primary account puts initial access at an executive device compromise — agent overprivilege was the amplifier, not the entry point.
- Thailand Ministry of Finance. The secondary account dates it to June and adds a cross-platform backdoor that appears in no primary source. This ledger uses the July disclosure date and flags the backdoor as unconfirmed.
Known limits of the counts
The curve tracks disclosure, not incidence.
Part of the 2026 climb is real escalation, and part is a research community that got much better at looking. CISA KEV additions, vendor threat reports, and coordinated disclosure all cluster, which pushes several incidents into the month they were published rather than the month they happened.
Six entries carry a year but no month in their sources. They are grouped as Undated in the timeline and given their own row in the table view, rather than being assigned a date the sources do not support.
Where a claim’s authority actually comes from.
Six incidents in the narrative source cite one aggregator as “ibid.” — an aggregator itself summarizing Check Point, AWS, Hunt.io, Sysdig, OALABS, and Hugging Face. Here those claims are re-anchored to the underlying primary and vendor reporting, with the aggregator kept as corroboration rather than as the citation of record.
Provider-authored assessments are flagged in the entry itself — Anthropic’s 80–90% autonomy figure for GTG-1002, for example. They rest on a vendor’s visibility into its own service, and independent public validation is limited.
Ledger compiled 25 August 2026. All incident data is publicly reported and cited inline.