• Home  
  • AI Attack Tracker: Real-World Attacks on AI Systems

AI Attack Tracker: Real-World Attacks on AI Systems

Most writing about AI security is speculation about what might happen. This page tracks what already has. Every entry is a documented case from MITRE ATLAS, the adversarial-threat knowledge base for machine-learning systems, listing how the attack worked, what it targeted and who carried it out.

Entries marked In the wild are real incidents. The rest are documented red-team exercises against production systems, which are still worth reading: today’s exercise is usually next year’s incident. Where we have reported on a case, the last column links that coverage. Refreshed daily.

57Documented cases
17Real-world incidents
40Red-team exercises
19Since 2025

Our guides on defending AI systems

Date ATLAS ID Attack Target Type
2026-02-23 AML.CS0056 Model Distillation Campaigns Targeting Anthropic Claude
Anthropic uncovered campaigns to extract Claude’s capabilities carried out by the three Chinese AI Labs: DeepSeek, Moonshot, and MiniMax. Collectively, these campaigns used approximately 24,000 accounts and 16
Anthropic Claude In the wild
2026-02-03 AML.CS0051 OpenClaw Command & Control via Prompt Injection
Researchers at HiddenLayer demonstrated how a webpage can embed an indirect prompt injection that causes OpenClaw to silently execute a malicious script. Once executed, the script plants persistent malicious in
OpenClaw Exercise
2026-02-01 AML.CS0050 OpenClaw 1-Click Remote Code Execution
A security researcher demonstrated a 1-click remote code execution (RCE) vulnerability to the OpenClaw AI Agent via a malicious link containing a JavaScript script that only takes milliseconds to execute. This
OpenClaw Exercise
2026-01-26 AML.CS0049 Supply Chain Compromise via Poisoned ClawdBot Skill
A security researcher demonstrated a proof-of-concept supply chain attack using a poisoned ClawdBot Skill shared on ClawdHub, a Skill registry for agents. The poisoned Skill contained a prompt injection that ca
ClawdBot (now OpenClaw) Exercise
2026-01-25 AML.CS0048 Exposed ClawdBot Control Interfaces Leads to Credential Access and Execution
A security researcher identified hundreds of exposed ClawdBot control interfaces on the public internet. ClawdBot (now OpenClaw) “is a personal AI assistant you run on your own devices. It answers you on the ch
ClawdBot (now OpenClaw) Exercise
2025-09-01 AML.CS0053 Poisoned Postmark MCP Server Email Exfiltration
A bad actor successfully exfiltrated emails from users of the Postmark’s MCP server via a supply chain attack. Postmark is an email delivery service that allows organizations to send marketing and transactional
Postmark MCP Server In the wild
2025-07-13 AML.CS0047 Code to Deploy Destructive AI Agent Discovered in Amazon Q VS Code Extension
On July 13th, 2025, a malicious actor using the GitHub username "lkmanka58" used an inappropriately scoped GitHub token to make a commit containing malicious code to the Amazon Q Developer Visual Studio Code (V
Amazon Q VS Code Extension In the wild
2025-07-01 AML.CS0042 SesameOp: Novel backdoor uses OpenAI Assistants API for command and control
The Microsoft Incident Response – Detection and Response Team (DART) investigated a compromised system where a threat actor utilized SesameOp, a backdoor implant that abuses the OpenAI Assistants API as a cover
OpenAI Assistants API In the wild
2025-06-25 AML.CS0043 Malware Prototype with Embedded Prompt Injection
Check Point Research identified a prototype malware sample in the wild that contained a prompt injection, which appeared to be designed to manipulate LLM-based malware detectors and/or analysis tools. However,
LLM malware detectors, LLM malware analysis and reverse engineering to In the wild
2025-06-24 AML.CS0045 Data Exfiltration via an MCP Server used by Cursor
The Backslash Security Research Team demonstrated that a Model Context Protocol (MCP) tool can be used as a vector for an indirect prompt injection attack on Cursor, potentially leading to the execution of mali
Cursor Exercise
2025-06-19 AML.CS0039 Living Off AI: Prompt Injection via Jira Service Management
Researchers from Cato Networks demonstrated how adversaries can exploit AI-powered systems embedded in enterprise workflows to execute malicious actions with elevated privileges. This is achieved by crafting ma
Atlassian MCP, Jira Service Management Exercise
2025-06-03 AML.CS0044 LAMEHUG: Malware Leveraging Dynamic AI-Generated Commands
In July 2025, Ukrainian authorities reported the emergence of LAMEHUG, a new AI-powered malware attributed to the Russian state-backed threat actor [APT28](https://attack.mitre.org/groups/G0007/) (also tracked
Ukraine’s security and defense sector In the wild
2025-06-01 AML.CS0037 Data Exfiltration via Agent Tools in Copilot Studio
Researchers from Zenity demonstrated how an organization’s data can be exfiltrated via prompt injections that target an AI-powered customer service agent.

The target system is a customer service agent built by

Copilot Studio Customer Service Agent Exercise
2025-05-24 AML.CS0055 AI ClickFix: Hijacking Computer-Use Agents Using ClickFix
[Embrace the Red]( https://embracethered.com/) demonstrated that AI computer-use agents are vulnerable to social engineering attacks and can be manipulated into executing arbitrary code on a victim’s machine. T
Claude Computer-Use Agent Exercise
2025-04-01 AML.CS0054 Data Exfiltration via Remote Poisoned MCP Tool
Researchers at Invariant Labs demonstrated that AI agents configured with remote Model Context Protocol (MCP) Tools can be vulnerable to model poisoning attacks. They show that an MCP Tool can contain malicious
Model Context Protocol Exercise
2025-03-18 AML.CS0041 Rules File Backdoor: Supply Chain Attack on AI Coding Assistants
Pillar Security researchers demonstrated how adversaries can compromise AI-generated code by injecting malicious instructions into rules files used to configure AI coding assistants like Cursor and GitHub Copil
Cursor, GitHub Copilot Exercise
2025-02-27 AML.CS0052 LLMSmith: RCE Vulnerabilities in LLM-Integrated Applications
Researchers identified 20 remote code execution (RCE) vulnerabilities across 11 different LLM frameworks. They discovered applications deployed on the public internet built using these LLM frameworks and demons
LLM Integration Frameworks Exercise
2025-02-25 AML.CS0031 Malicious Models on Hugging Face
Researchers at ReversingLabs have identified malicious models containing embedded malware hosted on the Hugging Face model repository. The models were found to execute reverse shells when loaded, which grants t
Hugging Face users In the wild
2025-01-01 AML.CS0036 AIKatz: Attacking LLM Desktop Applications
Researchers at Lumia have demonstrated that it is possible to extract authentication tokens from the memory of LLM Desktop Applications. An attacker could then use those tokens to impersonate as the victim to t
LLM Desktop Applications (Claude, ChatGPT, Copilot) Exercise
2024-10-24 AML.CS0046 Data Destruction via Indirect Prompt Injection Targeting Claude Computer-Use
Security researchers at HiddenLayer demonstrated that an indirect prompt injection targeting Claude’s Computer Use AI can lead to execution of shell commands on the victim system and destruction of user data.

Claude Computer Use Agent Exercise
2024-10-09 AML.CS0034 ProKYC: Deepfake Tool for Account Fraud Attacks
Cato CTRL security researchers have identified ProKYC, a deepfake tool being sold to cybercriminals as a method to bypass Know Your Customer (KYC) verification on financial service applications such as cryptocu
KYC verification services In the wild
2024-10-01 AML.CS0033 Live Deepfake Image Injection to Evade Mobile KYC Verification
Facial biometric authentication services are commonly used by mobile applications for user onboarding, authentication, and identity verification for KYC requirements. The iProov Red Team demonstrated a face-swa
Mobile facial authentication service Exercise
2024-08-20 AML.CS0035 Data Exfiltration from Slack AI via Indirect Prompt Injection
[PromptArmor](https://promptarmor.substack.com) demonstrated that private data can be exfiltrated from Slack AI via indirect prompt injections. The attack relied on Slack AI ingesting a malicious prompt from a
Slack AI Exercise
2024-08-08 AML.CS0026 Financial Transaction Hijacking with M365 Copilot as an Insider
Researchers from Zenity conducted a red teaming exercise in August 2024 that successfully manipulated Microsoft 365 Copilot.[<sup>\[1\]</sup>][1] The attack abused the fact that Copilot ingests received emails
Microsoft 365 Copilot Exercise
2024-06-06 AML.CS0025 Web-Scale Data Poisoning: Split-View Attack
Many recent large-scale datasets are distributed as a list of URLs pointing to individual datapoints. The researchers show that many of these datasets are vulnerable to a "split-view" poisoning attack. The atta
10 web-scale datasets Exercise
2024-06-01 AML.CS0022 ChatGPT Package Hallucination
Researchers identified that large language models such as ChatGPT can hallucinate fake software package names that are not published to a package repository. An attacker could publish a malicious package under
ChatGPT users Exercise
2024-05-06 AML.CS0030 LLM Jacking
The Sysdig Threat Research Team discovered that malicious actors utilized stolen credentials to gain access to cloud-hosted large language models (LLMs). The actors covertly gathered information about which mod
Cloud-Based LLM Services In the wild
2024-03-05 AML.CS0024 Morris II Worm: RAG-Based Attack
Researchers developed Morris II, a zero-click worm designed to attack generative AI (GenAI) ecosystems and propagate between connected GenAI systems. The worm uses an adversarial self-replicating prompt which u
RAG-based e-mail assistant Exercise
2024-02-01 AML.CS0038 Planting Instructions for Delayed Automatic AI Agent Tool Invocation
[Embrace the Red](https://embracethered.com/blog/) demonstrated that Google Gemini is susceptible to automated tool invocation by delaying the execution to the next conversation turn. This bypasses a security c
Google Gemini Exercise
2024-02-01 AML.CS0040 Hacking ChatGPT’s Memories with Prompt Injection
[Embrace the Red](https://embracethered.com/blog/) demonstrated that ChatGPT’s memory feature is vulnerable to manipulation via prompt injections. To execute the attack, the researcher hid a prompt injection in
OpenAI ChatGPT Exercise
2023-11-23 AML.CS0029 Google Bard Conversation Exfiltration
[Embrace the Red](https://embracethered.com/blog/) demonstrated that Bard users’ conversations could be exfiltrated via an indirect prompt injection. To execute the attack, a threat actor shares a Google Doc co
Google Bard Exercise
2023-09-26 AML.CS0028 AI Model Tampering via Supply Chain Attack
Researchers at Trend Micro, Inc. used service indexing portals and web searching tools to identify over 8,000 misconfigured private container registries exposed on the internet. Approximately 70% of the registr
Private Container Registries Exercise
2023-09-05 AML.CS0023 ShadowRay
Ray is an open-source Python framework for scaling production AI workflows. Ray’s Job API allows for arbitrary remote execution by design. However, it does not offer authentication, and the default configuratio
Multiple systems In the wild
2023-08-23 AML.CS0027 Organization Confusion on Hugging Face
[threlfall_hax](https://5stars217.github.io/), a security researcher, created organization accounts on Hugging Face, a public model repository, that impersonated real organizations. These false Hugging Face org
Hugging Face users Exercise
2023-07-01 AML.CS0019 PoisonGPT
Researchers from Mithril Security demonstrated how to poison an open-source pre-trained large language model (LLM) to return a false fact. They then successfully uploaded the poisoned model back to HuggingFace,
HuggingFace Users Exercise
2023-05-01 AML.CS0021 ChatGPT Conversation Exfiltration
[Embrace the Red](https://embracethered.com/blog/) demonstrated that ChatGPT users’ conversations can be exfiltrated via an indirect prompt injection. To execute the attack, a threat actor uploads a malicious p
OpenAI ChatGPT Exercise
2023-01-28 AML.CS0016 Achieving Code Execution in MathGPT via Prompt Injection
The publicly available Streamlit application [MathGPT](https://mathgpt.streamlit.app/) uses GPT-3, a large language model (LLM), to answer user-generated math questions.

Recent studies and experiments have sho

MathGPT (https://mathgpt.streamlit.app/) Exercise
2023-01-01 AML.CS0020 Indirect Prompt Injection Threats: Bing Chat Data Pirate
Whenever interacting with Microsoft’s new Bing Chat LLM Chatbot, a user can allow Bing Chat permission to view and access currently open websites throughout the chat session. Researchers demonstrated the abilit
Microsoft Bing Chat Exercise
2022-12-25 AML.CS0015 Compromised PyTorch Dependency Chain
Linux packages for PyTorch’s pre-release version, called Pytorch-nightly, were compromised from December 25 to 30, 2022 by a malicious binary uploaded to the Python Package Index (PyPI) code repository. The ma
PyTorch In the wild
2022-12-01 AML.CS0032 Attempted Evasion of ML Phishing Webpage Detection System
Adversaries create phishing websites that appear visually similar to legitimate sites. These sites are designed to trick users into entering their credentials, which are then sent to the bad actor. To combat th
Commercial ML Phishing Webpage Detector In the wild
2022-07-01 AML.CS0018 Arbitrary Code Execution with Google Colab
Google Colab is a Jupyter Notebook service that executes on virtual machines. Jupyter Notebooks are often used for ML and data science research and experimentation, containing executable snippets of Python cod
Google Colab Exercise
2021-06-23 AML.CS0014 Confusing Antimalware Neural Networks
Cloud storage and computations have become popular platforms for deploying ML malware detectors.
In such cases, the features for models are built on users’ systems and then sent to cybersecurity company servers
Kaspersky’s Antimalware ML Model Exercise
2021-01-18 AML.CS0013 Backdoor Attack on Deep Learning Models in Mobile Apps
Deep learning models are increasingly used in mobile applications as critical components.
Researchers from Microsoft Research demonstrated that many deep learning models deployed in mobile apps are vulnerable t
ML-based Android Apps Exercise
2020-10-01 AML.CS0017 Bypassing ID.me Identity Verification
An individual filed at least 180 false unemployment claims in the state of California from October 2020 to December 2021 by bypassing ID.me’s automated identity verification system. Dozens of fraudulent claims
California Employment Development Department In the wild
2020-04-30 AML.CS0005 Attack on Machine Translation Services
Machine translation services (such as Google Translate, Bing Translator, and Systran Translate) provide public-facing UIs and APIs.
A research group at UC Berkeley utilized these public endpoints to create a re
Google Translate, Bing Translator, Systran Translate Exercise
2020-04-16 AML.CS0006 ClearviewAI Misconfiguration
Clearview AI makes a facial recognition tool that searches publicly available photos for matches. This tool has been used for investigative purposes by law enforcement agencies and other parties.

Clearview AI

Clearview AI facial recognition tool In the wild
2020-02-01 AML.CS0011 Microsoft Edge AI Evasion
The Azure Red Team performed a red team exercise on a new Microsoft product designed for running AI workloads at the edge. This exercise was meant to use an automated system to continuously manipulate a target
New Microsoft AI Product Exercise
2020-01-01 AML.CS0000 Evasion of Deep Learning Detector for Malware C&C Traffic
The Palo Alto Networks Security AI research team tested a deep learning model for malware command and control (C&C) traffic detection in HTTP traffic.
Based on the publicly available [paper by Le et al.](https:
Palo Alto Networks malware detection system Exercise
2020-01-01 AML.CS0001 Botnet Domain Generation Algorithm (DGA) Detection Evasion
The Palo Alto Networks Security AI research team was able to bypass a Convolutional Neural Network based botnet Domain Generation Algorithm (DGA) detector using a generic domain name mutation technique.
It is a
Palo Alto Networks ML-based DGA detection module Exercise
2020-01-01 AML.CS0002 VirusTotal Poisoning
McAfee Advanced Threat Research noticed an increase in reports of a certain ransomware family that was out of the ordinary. Case investigation revealed that many samples of that particular ransomware family wer
VirusTotal In the wild
2020-01-01 AML.CS0004 Camera Hijack Attack on Facial Recognition System
This type of camera hijack attack can evade the traditional live facial recognition authentication model and enable access to privileged systems and victim impersonation.

Two individuals in China used this att

Shanghai government tax office’s facial recognition service In the wild
2020-01-01 AML.CS0010 Microsoft Azure Service Disruption
The Microsoft AI Red Team performed a red team exercise on an internal Azure service with the intention of disrupting its service. This operation had a combination of traditional ATT&CK enterprise techniques su
Internal Microsoft Azure Service Exercise
2020-01-01 AML.CS0012 Face Identification System Evasion via Physical Countermeasures
MITRE’s AI Red Team demonstrated a physical-domain evasion attack on a commercial face identification service with the intention of inducing a targeted misclassification.
This operation had a combination of tra
Commercial Face Identification Service Exercise
2019-09-09 AML.CS0008 ProofPoint Evasion
Proof Pudding (CVE-2019-20634) is a code repository that describes how ML researchers evaded ProofPoint’s email protection system by first building a copy-cat email protection ML model, and using the insights t
ProofPoint Email Protection System Exercise
2019-09-07 AML.CS0003 Bypassing Cylance’s AI Malware Detection
Researchers at Skylight were able to create a universal bypass string that evades detection by Cylance’s AI Malware detector when appended to a malicious file.
CylancePROTECT, Cylance Smart Antivirus Exercise
2019-08-22 AML.CS0007 GPT-2 Model Replication
OpenAI built GPT-2, a language model capable of generating high quality text samples. Over concerns that GPT-2 could be used for malicious purposes such as impersonating others, or generating misleading news ar
OpenAI GPT-2 Exercise
2016-03-23 AML.CS0009 Tay Poisoning
Microsoft created Tay, a Twitter chatbot designed to engage and entertain users.
While previous chatbots used pre-programmed scripts
to respond to prompts, Tay’s machine learning capabilities allowed it to be
d
Microsoft’s Tay AI Chatbot In the wild

Source: MITRE ATLAS case studies (version 5.6.0). Last updated 22 August 2026, 05:35 UTC. ATLAS is maintained by MITRE and documents adversarial tactics against AI-enabled systems; case details and references are on the linked ATLAS pages.

About AI Post Daily

Independent coverage of artificial intelligence, machine learning, cybersecurity, and the technology shaping our future.

Contact: Get in touch

Known Exploited Vulnerabilities Tracker·AI Attack Tracker — updated daily

Security Guides

We use cookies to personalize content and ads, and to analyze traffic. By using this site, you agree to our Privacy Policy.