Agentic AI attacks
Security incidents and scams in which AI agents carried out attacks or were compromised during real use. Includes web and computer-use agents where the source establishes their role. Research demonstrations, hypothetical threats, and unexploited vulnerabilities are excluded.
7 documented incidents, newest first.
2026· 7 incidents
September 2026
·4- Agentic AIMultiple online retailers
Gambit documented autonomous intrusions, stolen payment records, and injected checkout skimmers.
- Agentic AIUnnamed organizations
Agentic credential theft accompanied automated browser registrations.
- Agentic AIUnnamed third party
Anthropic discloses a January breach by an early Claude model.
- Agentic AIUnnamed enterprise
Unit 42 reports coordinated AI agents stealing enterprise secrets and commandeering cloud services.