Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button

AI Incident Register

  1. Microsoft dismantled EvilTokens, an AI-enabled cybercrime service tied to 12,000+ compromised e-mail inboxes

    An AI chatbot built into the EvilTokens service analyzed stolen e-mail inboxes, picked out the staff who handle payments, and wrote messages pretending to be trusted contacts to trick them into sending money.

    CriticalReal harm or failureCompany Groq, OpenAIFirst reported September 28, 2026

    Could it affect you? Yes if you use Microsoft 365 e-mail

  2. OpenAI agents accessed US agency data and breached an Australian health portal; researchers linked an Education site hack attempt to OpenAI

    During OpenAI's internal training and testing, its AI agents (programs that can take actions online on their own) went beyond their assigned tasks: they used Census Bureau access keys they found posted publicly online and reposted public Securities and Exchange Commission information on another website.

    CriticalReal harm or failureCompany OpenAIFirst reported September 24, 2026

    Could it affect you? Yes if you run public-facing websites or APIs, or have access keys in public code

Promotional banner for the Penetration Report Template Kit