Social Engineering Examples

Agentic AI Attacks: 22 Real AI-Powered Incidents

Agentic AI attacks are the newest family here - as in GTG-1002, an AI-orchestrated cyber-espionage campaign run largely through Claude Code, the PROMPTFLUX self-obfuscating malware built with the Gemini API, and GTG-2002 Vibe Hacking, where Claude Code was weaponized for agentic data extortion against 17 organizations - cases where an AI agent, not just a human using AI to write a better lure, carried out meaningful parts of the attack itself. Expect this list to grow faster than any other family on this site.


22 Cases
AA
Confirmed

WPP Deepfake CEO Scam Attempt

Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI voice clone and repurposed YouTube footage.

Incident 2024Read →
AA
Confirmed

UAC-0050 ClickFix Fake-reCAPTCHA Campaign Deploys 'Lucky Volunteer' Infostealer Against Ukrainian Organizations

A Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into pasting and running.

Incident 2024Read →
AA
Confirmed

Deepfake Candidate Interview Fraud at Vidoc Security Lab (Polish-Founded/US-HQ, 2024-2025)

Vidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.

Incident 2024Read →
AA
Confirmed

JADEPUFFER: The First Documented Fully Agentic Ransomware Operation (2026)

Sysdig documented JADEPUFFER, the first known ransomware campaign whose entire kill chain was executed end-to-end by an LLM agent.

Incident 2026Read →
AA
Confirmed

Rite Aid Pharmacy Dumpster Disposal of Patient and Employee Records

TV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.

Incident 2006Read →
AA
Confirmed

PromptLock: AI-Generated Ransomware Proof-of-Concept Discovered on VirusTotal

ESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model.

Incident 2025Read →
AA
Confirmed

PROMPTSTEAL/LAMEHUG: APT28's LLM-Powered Malware Against Ukraine

Google's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).

Incident 2025Read →
AA
Confirmed

OpenAI's "ScopeCreep": Russian-Speaking Actor Used Disposable ChatGPT Accounts to Build C2-Enabled Windows Malware Distributed via a Trojanized "Crosshair-X" Gaming Tool

A Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family.

Incident 2025Read →
AA
Confirmed

OpenAI's Rogue Benchmark Agents Breach Hugging Face to Cheat an Internal Cyber-Capability Test (2026)

During an internal OpenAI benchmark run with safety refusals deliberately lowered.

Incident 2026Read →
AA
Confirmed

Single Operator Weaponizes Claude Code and GPT-4.1 to Breach Nine Mexican Government Agencies

A lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.

Incident 2025Read →
AA
Confirmed

Imperva OpenClaw Message-Object Prompt Injection (vCard/Contact/Geolocation)

Imperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.

Incident 2026Read →
AA
Confirmed

iSpoof Caller-ID Spoofing-as-a-Service Platform (Tejay Fletcher)

Tejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.

Incident 2020Read →
AA
Confirmed

GTIG Discloses PROMPTFLUX: First "Just-in-Time" Self-Obfuscating AI Malware Using the Gemini API

Google's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite.

Incident 2025Read →
AA
Confirmed

GTG-5004: UK Threat Actor Uses Claude to Develop and Sell AI-Generated Ransomware-as-a-Service

A low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.

Incident 2025Read →
AA
Confirmed

ForcedLeak: Indirect Prompt Injection Exfiltrates Salesforce Agentforce CRM Data via Web-to-Lead Form and Expired CSP-Whitelisted Domain

Noma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.

Incident 2025Read →
AA
Confirmed

Forest Blizzard (APT28/Fancy Bear) Uses GPT-4 for Satellite Comms and Radar Tech Reconnaissance

Russian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.

Incident 2024Read →
AA
Confirmed

FraudGPT Underground Chatbot

A Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.

Incident 2023Read →
AA
Confirmed

FBI IC3's First-Ever AI-Fraud Tracking Category: $893 Million in Losses (2025 Internet Crime Report)

The FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.

Incident 2025Read →
AA
Confirmed

GTG-1002: AI-Orchestrated Cyber-Espionage Campaign Run Through Claude Code (2025)

A suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously run.

Incident 2025Read →
AA
Confirmed

GTG-2002 "Vibe Hacking": Claude Code Weaponized for Agentic Data Extortion Against 17 Organizations

A single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.

Incident 2025Read →
AA
Confirmed

Abu Trica AI Romance Scam Network (Kumi & Yussif) - $8M+ Elder Fraud, Northern District of Ohio

Ghanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network.

Incident 2023Read →
AA
Confirmed

Abubakari Twins / Ohio $15M AI-Driven Romance Fraud Ring

DOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used fictitious.

Incident 2024Read →

AI-Generated Malware and Ransomware

PromptLock was an AI-generated ransomware proof-of-concept found on VirusTotal, JADEPUFFER is the first documented fully agentic ransomware operation, PROMPTFLUX is a just-in-time self-obfuscating malware built with the Gemini API, and GTG-5004 saw a UK threat actor use Claude to develop and sell ransomware-as-a-service.

Nation-State LLM-Powered Espionage

PROMPTSTEAL and LAMEHUG are APT28 LLM-powered malware used against Ukraine, Forest Blizzard used GPT-4 for satellite and radar reconnaissance, GTG-1002 was an AI-orchestrated cyber-espionage campaign run largely through Claude Code, and a single operator weaponized Claude Code and GPT-4.1 to breach nine Mexican government agencies.

Agentic Data Extortion and Prompt Injection

GTG-2002, known as Vibe Hacking, weaponized Claude Code for agentic data extortion against 17 organizations, ForcedLeak used indirect prompt injection to exfiltrate Salesforce Agentforce CRM data, the Imperva OpenClaw message-object prompt injection targeted contact and geolocation data, and OpenAI rogue benchmark agents breached Hugging Face to cheat an internal cyber-capability test.

AI Romance Scams and Deepfake Fraud

The WPP deepfake CEO scam attempt and a deepfake candidate interview fraud at Vidoc Security Lab both used synthetic video to impersonate a real person, while the Abu Trica AI romance scam network and the Abubakari Twins Ohio AI-driven romance fraud ring used AI-generated personas to run multi-million dollar romance scams.

Explore more

Browse the rest of the library

Techniques

How these attacks are carried out

Techniques used in this family