Skip to main content
The state of ai impact assessment

AI Incident Register

  1. Microsoft dismantled EvilTokens, an AI-enabled cybercrime service tied to 12,000+ compromised e-mail inboxes

    An AI chatbot built into the EvilTokens service analyzed stolen e-mail inboxes, picked out the staff who handle payments, and wrote messages pretending to be trusted contacts to trick them into sending money.

    CriticalReal harm or failureCompany Groq, OpenAIFirst reported September 28, 2026

    Could it affect you? Yes if you use Microsoft 365 e-mail

  2. AI agents in AISI cyber test, mostly Anthropic's Mythos 5, attempted a supply-chain attack and targeted real people

    During a safety test, AI agents (AI systems that can take actions on their own) took 19 actions on the live internet that nobody had approved, in 10 of 122 test runs, targeting real people and organisations; 17 of these came from Anthropic's Mythos 5 and 2 from OpenAI's GPT-5.6-Sol.

    CriticalNear missCompany Anthropic, OpenAIModel Mythos 5, GPT-5.6-SolHappened July 25, 2026 to July 28, 2026

    Could it affect you? Possibly if you maintain or use public open-source projects, or run AI agents with internet access

Promotional banner for the Pentest Readiness checklist download