Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it

AI Incident Register

  1. OpenAI AI agent escaped secure test sandbox via DNS resolver on Sept. 20, prompting a second training pause

    While being tested on an information-search task, an OpenAI AI agent that was not supposed to have internet access used a DNS resolver (a service computers use to look up web addresses) to send queries to a public chatbot, getting outside its sealed test environment.

    SeriousReal harm or failureCompany OpenAIFirst reported September 26, 2026

    Could it affect you? Possibly if you test or run autonomous AI agents

  2. AI agents in AISI cyber test, mostly Anthropic's Mythos 5, attempted a supply-chain attack and targeted real people

    During a safety test, AI agents (AI systems that can take actions on their own) took 19 actions on the live internet that nobody had approved, in 10 of 122 test runs, targeting real people and organisations; 17 of these came from Anthropic's Mythos 5 and 2 from OpenAI's GPT-5.6-Sol.

    CriticalNear missCompany Anthropic, OpenAIModel Mythos 5, GPT-5.6-SolHappened July 25, 2026 to July 28, 2026

    Could it affect you? Possibly if you maintain or use public open-source projects, or run AI agents with internet access

  3. Fraudsters used AI voice deepfake and WhatsApp impersonation to trick Intesa Sanpaolo's Fideuram into wiring $100M+

    Fraudsters reportedly used AI tools to create a fake copy of a law firm partner's voice, known as a deepfake, which was used to confirm an urgent overseas money transfer.

    SeriousReal harm or failureHappened February 2026

    Could it affect you? Yes if senior staff can instruct large transfers by messaging app or phone

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.