What happened, how access was gained, and where to look in your own environment. A ledger connecting primary evidence to practical inspection steps.
41
INCIDENTS
14
RULES
Reported facts and assessments are separated. Exposure-only cases are included. Unknown AI involvement cannot establish trends in AI attacks.
Incident database
A curated database of 31 domestic and international records disclosed during 2025-10-02–2026-10-02, plus 10 earlier records. Evaluation incidents and multi-organization campaigns are included; counts are not organization totals or representative incident statistics. Read the year review and collection scope ↗
Temairazu confirmed unauthorized system access. Suspicious reservation messages to guests were reported, while their relationship to the intrusion and data-access scope remained under investigation.
The company confirmed leakage of 6.6 million member records, including 1.6 million identity-document images, covering withdrawn members and incomplete applicants.
An upload-server vulnerability enabled access to user records and image metadata. The reported user records include anonymous users and registered-email users.
Unauthorized access used a known VPN vulnerability in a GSS maintenance environment. The patch was unapplied, with about 246,000 records potentially leaked.
Unit 42 reported an intrusion that expanded from an exposed service to cloud systems through repository secrets, with LLM calls observed during the attack.
The Rust team reported malicious dependencies in updates to arrayref and related crates. Build-time code retrieved a payload; malicious versions were removed.
Sakura disclosed billing-database access spanning April 2023 to March 2026 in August 2026, with potential information leakage reported separately from its hosting incident.
Sakura disclosed unauthorized access and malware on a hosting management server. Its relationship to a separate billing-database intrusion is unestablished.
Metabase investigated abnormal API-key activity on August 3 and confirmed zero-day exploitation. Input handling and ORM behavior enabled administrator sessions and data access.
Sources: Metabase · 6 rules
DISCLOSED
Configuration / exposureCredentialsImplementationSupply chain / CI
Anthropic disclosed three incidents of evaluation models reaching external organizations. Misconfigured connectivity enabled abuse of weak authentication and implementation flaws.
An OpenAI prototype under evaluation used restricted package connectivity to reach external systems. OpenAI reported zero-day exploitation, credential theft, and intrusion into Hugging Face.
Aflac reported missed detection of ordinary-looking requests and inadequate bulk-query controls. Personal information of about 4.4 million customers leaked, including bank-account information for about 220,000 of them.
A test environment due for retirement and data deletion remained for AI-related verification. Credential-based unauthorized access led to reported customer and shareholder data leakage.
GitHub credentials mistakenly uploaded to a personal development server were misused. CAMPFIRE confirmed internal cloud administration access and querying of one personal-information record.
Google investigators reported a compromised Axios publisher account and releases carrying a malicious dependency whose install script distributes cross-platform backdoors.
Sources: Google Threat Intelligence Group · 6 rules
Aqua reports privileged-token theft through GitHub Actions misconfiguration, incomplete initial rotation, and renewed release tampering. Existing action tags were redirected to malicious commits.
Sources: Aqua Security / Trivy maintainers / Aqua Security · 6 rules
The company reported entry using a VPN vulnerability and account information, with encryption and leakage addressed by VPN removal and environment reinitialization.
Microsoft reported hundreds of machines compromised through unauthenticated RSC code execution. The vulnerability and fixes were disclosed on December 3.
Mixpanel reported a smishing incident; OpenAI reported export of user analytics data from the supplier. OpenAI says passwords, API keys, and chat content were not involved.
A CI build without an appropriate lockfile installed infected dependencies, enabling misuse of an npm publishing token. Postman reported 17 hijacked packages, with production apps and customer data unaffected.
Anthropic reported attacker use of Claude Code for reconnaissance, exploit development, credential harvesting, and exfiltration. About 30 organizations were targeted, with success reported at a small number.
Discord reported unauthorized access to support information through a provider compromise. About 70,000 users potentially had identity-document photos exposed; this is not a confirmed image-leak count.