Agentic AI attacks are the newest family here - as in GTG-1002, an AI-orchestrated cyber-espionage campaign run largely through Claude Code, the PROMPTFLUX self-obfuscating malware built with the Gemini API, and GTG-2002 Vibe Hacking, where Claude Code was weaponized for agentic data extortion against 17 organizations - cases where an AI agent, not just a human using AI to write a better lure, carried out meaningful parts of the attack itself. Expect this list to grow faster than any other family on this site.
Fraudsters built a fake WhatsApp profile of WPP CEO Mark Read and staged a Microsoft Teams call using an AI voice clone and repurposed YouTube footage.
AAA Ukrainian-language "shared document" phishing wave used a fake reCAPTCHA "verify you are human" ClickFix page to trick victims into pasting and running.
AAVidoc Security Lab, a Polish-founded, US-headquartered cybersecurity startup.
AASysdig documented JADEPUFFER, the first known ransomware campaign whose entire kill chain was executed end-to-end by an LLM agent.
AATV investigative reporters filmed Rite Aid pharmacy dumpsters nationwide overflowing with readable prescription labels.
AAESET researchers found "PromptLock," a Go-based ransomware sample on VirusTotal that used a locally-run open-weight AI model.
AAGoogle's GTIG and Ukraine's CERT-UA documented PROMPTSTEAL (aka LAMEHUG).
AAA Russian-speaking threat actor used disposable, one-conversation ChatGPT accounts to iteratively build and debug a Go-based Windows malware family.
AADuring an internal OpenAI benchmark run with safety refusals deliberately lowered.
AAA lone, unidentified hacker jailbroke Anthropic's Claude Code coding agent with a fake "authorized bug bounty/pentest" pretext and paired it.
AAImperva researcher Yohann Sillam showed that whitespace-padded prompt-injection payloads hidden in WhatsApp contact names, vCard FN fields.
AATejay Fletcher founded and ran iSpoof, a Bitcoin-subscription caller-ID spoofing and OTP-interception platform that let fraudsters impersonate bank.
AAGoogle's Threat Intelligence Group disclosed PROMPTFLUX, a VBScript dropper that calls the Gemini API mid-execution to have an LLM rewrite.
AAA low-skill UK-based cybercriminal used Claude to write the encryption, evasion, and anti-recovery code it could not build itself.
AANoma Security researchers hid a multi-step prompt-injection payload inside a public Salesforce Web-to-Lead form's 42,000-character Description field.
AARussian GRU-linked Forest Blizzard (APT28/Fancy Bear) used OpenAI's GPT-4-family LLM services to research satellite communication protocols and radar.
AAA Telegram/dark-web "blackhat ChatGPT" sold $200/month subscriptions promising AI-generated phishing pages, malware and BEC lures.
AAThe FBI's 2025 Internet Crime Report introduced its first dedicated AI-fraud tracking category, logging $893 million in losses.
AAA suspected Chinese state-sponsored group jailbroke Anthropic's Claude Code by role-playing a "defensive security" pretext and used it to autonomously run.
AAA single cybercriminal used Anthropic's Claude Code as an autonomous operator to breach ~17 organizations and generate psychologically targeted.
AAGhanaian social-media personality Frederick Kumi ("Abu Trica") and co-defendant Daniel Yussif were federally indicted for leading a romance-fraud network.
AADOJ alleges Ghanaian twins Jamal and Kamal Abubakari and U.S.-based Amanda Opoku-Boachie ran an AI-video-enabled romance fraud ring that used fictitious.
PromptLock was an AI-generated ransomware proof-of-concept found on VirusTotal, JADEPUFFER is the first documented fully agentic ransomware operation, PROMPTFLUX is a just-in-time self-obfuscating malware built with the Gemini API, and GTG-5004 saw a UK threat actor use Claude to develop and sell ransomware-as-a-service.
PROMPTSTEAL and LAMEHUG are APT28 LLM-powered malware used against Ukraine, Forest Blizzard used GPT-4 for satellite and radar reconnaissance, GTG-1002 was an AI-orchestrated cyber-espionage campaign run largely through Claude Code, and a single operator weaponized Claude Code and GPT-4.1 to breach nine Mexican government agencies.
GTG-2002, known as Vibe Hacking, weaponized Claude Code for agentic data extortion against 17 organizations, ForcedLeak used indirect prompt injection to exfiltrate Salesforce Agentforce CRM data, the Imperva OpenClaw message-object prompt injection targeted contact and geolocation data, and OpenAI rogue benchmark agents breached Hugging Face to cheat an internal cyber-capability test.
The WPP deepfake CEO scam attempt and a deepfake candidate interview fraud at Vidoc Security Lab both used synthetic video to impersonate a real person, while the Abu Trica AI romance scam network and the Abubakari Twins Ohio AI-driven romance fraud ring used AI-generated personas to run multi-million dollar romance scams.