Home › Resources › Threat Ledger
Salience Cyber Research · Threat Ledger

Every AI-enabled attack we can prove happened.

247 publicly documented incidents, charted month by month from January 2024 to August 2026.

June to August 2026 holds more documented incidents than 2024 and 2025 combined.

96 incidents across those three months, against 73 in the two years before them. The curve below is that fact, drawn from the same 247 entries you can search.
Documented incidents
247
Cited sources
735
Confirmed intrusions
118 of 247
Monthly rate 2024 → 2026
2.7 → 3.4 → 21.8
Coverage
32 months

Loading the ledger…

Coverage

Mapped to what actually goes wrong.

Every incident is tagged against the six attack classes Salience Cyber was built to see — the four named on the Salience Cyber platform, plus supply chain and synthetic media. An incident can carry more than one tag; most real intrusions do.

Every sparkline runs January 2024 to August 2026 on one shared scale, so the six are directly comparable — a flat line means that class stayed flat, not that it is too small to see. Select a class to filter the timeline.

Victimology

Who is on the receiving end.

Two dimensions the underlying sources actually support: which ecosystem absorbed the attack, and whether an organisation was breached or a researcher found the hole first.

Both compose with the search, attack class, and date range below.

Affected ecosystem

Where the damage landed

One ecosystem per incident, so these sum to all 247. Click a row to filter.

Entry type

Breached, or found first?

The cut that matters most: someone was hurt, versus someone found the hole before anyone was.

Named victim locations

Theater coverage is thin, and shown as such

Only of 247 entries name where the victim was. The rest are vendor products, packages, or multi-region campaigns with no location on the record.

This is a gap in the underlying catalogs, not a rendering choice. Most entries in an AI-infrastructure incident registry describe a compromised codebase rather than a company in a country, so there is no victim geography to plot. A world map here would chart our metadata coverage rather than the threat. Per-incident victim country and sector can be added, but only by going back to primary sources incident by incident — that is research, not extraction.

All 247 incidentsIn current view
The measured record

The activity is growing. The AI share of it is the part nobody can measure.

218 published figures, January 2022 to September 2026, ordered by the period each one measures rather than when it was printed. Charted separately from the incident timeline above, which is ordered by disclosure date — the two conventions are months apart and putting them on one axis would draw a difference that does not exist.

And the AI-attributed share of it

Eight published estimates of the same quantity — what share of phishing is AI-generated — spanning 4% to 82.6%. A 20.6× spread. The one estimate drawn from a measured series with a published method puts it at 10%; every figure above 80% is single-source and unverified, and two of them are the same vendor’s telemetry counted twice. One vendor’s own classifier returned 4%, then 56%, then 40% across three consecutive months.None of this says the AI share is small — it says nobody is instrumented to know it. The lowest estimate here is as unsourced as the highest.

What is measurably growing, and is measurably about AI

  • AI-related CVEs6922,130per year, 2023 to 2025
  • Shadow AI in breaches20%43%of breached organisations
  • Own AI models breached13%21%of breached organisations
  • Exposed Ray servershundreds200,000+internet-facing, 2024 to 2025
  • AI governance coverage37%32%moved backwards

The AI attack surface has a true zero baseline: the evidence base holds no measurements of it for 2022 and one for 2023, because it did not exist at scale. Unlike the macro series above,25 of the 28 findings in this domain carry no counter-evidence. Of the three that do, two are the catalogue compiler’s own methodological notes rather than independent findings; the third reports that AI governance coverage fell. None is a refutation.

Four independent macro series, each indexed to its own first year so that incommensurable units — breach counts, dollars, complaint tallies, CVE totals — can share one canvas without being summed. All four rise. What cannot be drawn with them is the AI-attributed share of that activity: the published estimates of it disagree by 20.6×, which is the measurement gap this platform exists to close.
The underlying figures
Macro series, first and last measured values, with the indexed change.
SeriesSourceFirstLastChange
Confirmed breachesVerizon DBIR2022 · 5,2122026 · 22,000+322%
Reported lossesFBI IC32022 · $10,300m2025 · $20,877m+103%
CVEs publishedCVE Program2023 · 28,8182025 · 48,185+67%
Reported incidentsFBI IC32022 · 809,5762025 · 1,008,597+25%
Provenance

Two catalogs, merged, with every conflict on the record.

This ledger consolidates two independently compiled sources. Where they disagreed on a date, a figure, or an attribution, the conflict was recorded rather than silently resolved — and the entry follows the primary or vendor source.

Figures as a table
Sources citedEntries
129
289
361
431
521
66
72
87
101
How well evidenced each ledger entry is: 735 source citations across 247 entries, a mean of 2.98 independent sources per entry. Every entry carries at least one.
Figures as a table
Threat familyConfirmedEntries
Agentic exploitation4596
Supply chain4672
AI-generated malware4064
Shadow AI & exposure1757
Prompt injection2048
Synthetic media46
Of 247 ledger entries, 118 are classed as confirmed intrusions; the remainder are vulnerability disclosures and research reporting. The split is shown per threat family, because it varies widely between them.
Where the data comes from
Source 1 · Base timeline

awesome-ai-agent-attacks

A curated chronological timeline of AI agent security incidents, breaches, and vulnerabilities, maintained byDavid Grice. Primary- and vendor-sourced throughout: Anthropic, AWS, Sysdig, Hunt.io, CISA, UK AISI, arXiv.View the repository →

Source 2 · Narrative catalog

“The Receipts”

A narrative catalog of 32 incidents across 51 footnotes. It contributed coverage the timeline lacked entirely: the GTG-2002 extortion campaign, the five GTIG malware families that call an LLM at runtime, four deepfake-enabled fraud cases, synthetic-identity insider threat, postmark-mcp, and the fourteen-company Claude Code / Codex case. 22 entries here carry its contributions.

Where the two sources disagreed
Reconciliation

Where the two sources disagreed

  1. Mexican government records exfiltrated. 195 million via a secondary aggregator, against roughly 400 million in Check Point’s own report. Command and session counts match exactly, so both derive from the same research — the record counts are measuring different things. Neither figure should be cited bare.
  2. CyberStrikeAI / FortiGate. Secondary reporting says the models executed custom exploit paths. AWS documented no FortiGate CVE exploitation at all: it was brute-forcing exposed management ports. The AI contribution was scale, not exploitation.
  3. Step Finance. Secondary reporting attributes the $40M loss to agents transferring treasury without approval. The primary account puts initial access at an executive device compromise — agent overprivilege was the amplifier, not the entry point.
  4. Thailand Ministry of Finance. The secondary account dates it to June and adds a cross-platform backdoor that appears in no primary source. This ledger uses the July disclosure date and flags the backdoor as unconfirmed.
Known limits of the counts
Caveat · the counts

The curve tracks disclosure, not incidence.

Part of the 2026 climb is real escalation, and part is a research community that got much better at looking. CISA KEV additions, vendor threat reports, and coordinated disclosure all cluster, which pushes several incidents into the month they were published rather than the month they happened.

Six entries carry a year but no month in their sources. They are grouped as Undated in the timeline and given their own row in the table view, rather than being assigned a date the sources do not support.

Caveat · the citations

Where a claim’s authority actually comes from.

Six incidents in the narrative source cite one aggregator as “ibid.” — an aggregator itself summarizing Check Point, AWS, Hunt.io, Sysdig, OALABS, and Hugging Face. Here those claims are re-anchored to the underlying primary and vendor reporting, with the aggregator kept as corroboration rather than as the citation of record.

Provider-authored assessments are flagged in the entry itself — Anthropic’s 80–90% autonomy figure for GTG-1002, for example. They rest on a vendor’s visibility into its own service, and independent public validation is limited.

Ledger compiled 25 August 2026. All incident data is publicly reported and cited inline.