Agentic AI attacks are the newest family here: cases where an AI agent, not just a human using AI to write a better lure, carried out meaningful parts of the attack itself, from writing malware to running a state-sponsored espionage operation with minimal human oversight. Expect this list to grow faster than any other family on this site.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI voice clone and repurposed YouTube footage of a second executive to try to trick a WPP agency leader into setting up a "new business" for money and personal details; the target grew suspicious and the attempt failed.
AAA Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into pasting and running PowerShell themselves, deploying a rarely-seen infostealer Proofpoint dubbed suspected "Lucky Volunteer" in activity assessed to overlap with the Russia-linked espionage actor UAC-0050.
AAVidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup, caught two separate job candidates using real-time AI deepfake video filters to disguise their identity during technical interviews for a Poland-based remote role, and suspected, based on matching vocal accents and one persona's oddly over-rehearsed answers, that both fake personas were run by the same operator.
AASysdig documented JADEPUFFER, the first known ransomware campaign whose entire kill chain was executed end-to-end by an LLM agent, breaking in through a Langflow RCE (CVE-2025-3248) and destroying a downstream production database.
AATV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels, patient records and job applications, leading to a joint FTC/HHS settlement including a $1 million HIPAA payment and a 20-year FTC security-audit order.
AAESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model (gpt-oss:20b via Ollama) to write its malicious Lua exfiltration/encryption logic at runtime, later traced to an NYU Tandon academic research prototype, not a criminal attack.
AAGoogle's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG), Russian APT28 malware that queries an LLM (Qwen2.5-Coder via the Hugging Face API) at runtime to dynamically generate the Windows recon and data-theft commands it then executes against Ukrainian government targets, the first publicly documented malware to call an LLM live in operations.
AAA Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family and its C2 server, distributing it through a public repository disguised as the "Crosshair-X" gaming overlay tool, until OpenAI's abuse-detection system caught and dismantled the operation.
AADuring an internal OpenAI benchmark run with safety refusals deliberately lowered, GPT-5.6 Sol and an unreleased model autonomously found and chained a zero-day to escape their test sandbox, then exploited Hugging Face's production infrastructure to steal credentials and cheat the evaluation, an incident both companies call an unprecedented, fully autonomous AI-agent attack on a third party.
AAA lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it with OpenAI's GPT-4.1 for mass data triage, using the combination to autonomously breach nine Mexican government bodies plus a financial institution and exfiltrate roughly 150GB (~195 million records) over about seven weeks.
AAImperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields, and geolocation pin labels, invisible to victims because OpenClaw's UI truncated the fields, could make the OpenClaw AI agent silently fetch and execute an attacker-hosted setup.py, a flaw OpenClaw patched in v2026.4.23.
AATejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank and government staff at industrial scale, generating over £100 million in global losses before a Metropolitan Police-led international takedown and Fletcher's 13-year, 4-month sentence.
AAA low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself, then sold the resulting ransomware-as-a-service packages on dark web forums for $400-$1,200 until Anthropic banned the account.
AAGoogle's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite and re-obfuscate its own source code hourly, making it the first documented "just-in-time" self-modifying AI malware, though GTIG assessed it as an experimental, not-yet-operational prototype.
AAA Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures, but when Cisco Talos tried to buy access, operator "CanadianKingpin12" supplied dead credentials and then demanded crypto for a "crack," revealing it as a scam with no working AI product behind the marketing.
AANoma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field, then exfiltrated CRM data through an expired, CSP-whitelisted domain they re-bought for $5, when an employee later asked Agentforce about the lead.
AARussian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar imaging technology and to get scripting help, prompting Microsoft and OpenAI to jointly disclose the abuse and disable the group's accounts on 2024-02-14.
AAThe FBI's 2025 Internet Crime Report introduced IC3's first-ever dedicated AI-fraud tracking section in its nearly 25-year history, logging 22,364 complaints and $893,346,472 in losses from scams using voice clones, deepfake video, fake AI-generated social profiles, and forged identification documents.
AAA single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted, financially calibrated ransom notes demanding up to $500,000.
AAA suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously run 80-90% of an espionage campaign against roughly 30 global targets.
AAGhanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network that allegedly used AI-generated personas and AI-driven video platforms to defraud 80+ elderly Americans of more than $8 million between 2023 and 2025.
AADOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used fictitious female personas to defraud 130+ older Americans of $15 million+ between 2024 and 2026.