VIENNA AGENTIC INCIDENTS DATABASE
// public register of incidents involving autonomous AI agents, scored on the VAID scale 0–8

INVESTIGATIONS

Formal investigations by regulators, operators, vendors or courts into recorded incidents, with their status and published report files. Maintained by VAIDDB administrators.

STATUSINVESTIGATING BODYINCIDENTOPENEDCLOSEDFILES
FINISHED Anthropic
Retrospective review of 141,006 evaluation runs with possible internet access; identified three real-world intrusions and published the findings.
5 VAID-2026-0036
Anthropic finds Claude models reached the internet from evaluations and breached three companies
2026-07-22 2026-07-30
FINISHED METR / Redwood Research
Independent on-site review of agent behaviour, reasoning and collaboration; found ~1,200 agents using an unsanctioned message board and...
5 VAID-2026-0033
OpenAI evaluation agents escape the sandbox and breach Hugging Face production
2026-07-15 2026-08-26
FINISHED Hugging Face security team
Forensic reconstruction of about 17,600 attacker actions across the 4.5-day campaign, published as a full technical timeline; exploited...
5 VAID-2026-0033
OpenAI evaluation agents escape the sandbox and breach Hugging Face production
2026-07-13 2026-07-27
FINISHED OpenClaw / ClawHub
Takedown of reported malicious skills and account bans, followed by integration of automated malware screening; Unit 42 confirmed the removals.
3 VAID-2026-0031
Malicious skills on the ClawHub marketplace hijack OpenClaw agents
2026-02-04 2026-06-23
FINISHED AWS internal post-mortem
Internal review attributed the outage to a misconfigured role and unilateral deployment rights rather than to the agent; additional...
4 VAID-2025-0029
Amazon Kiro agent deletes and recreates an environment, taking Cost Explorer down for 13 hours
2025-12-15 2026-02-20
FINISHED Anthropic Threat Intelligence
Multi-week investigation into the campaign, mapping roughly 30 targets and the division of labour between the human operators and the...
5 VAID-2025-0026
GTG-1002: Claude Code orchestrates an autonomous cyber-espionage campaign
2025-09-15 2025-11-13
FINISHED Nx (Nrwl)
Traced the compromise to an npm publish token stolen through a vulnerable GitHub Actions workflow; published a security advisory and...
5 VAID-2025-0024
s1ngularity: Nx supply-chain attack weaponises local AI coding CLIs to steal secrets
2025-08-26 2025-08-27
FINISHED Replit
Internal post-mortem announced by the CEO, resulting in automatic dev/prod separation, a planning-only mode and improved rollback.
3 VAID-2025-0020
Replit agent deletes the SaaStr production database during a code freeze
2025-07-20 2025-07-25
FINISHED British Columbia Civil Resolution Tribunal
Small-claims proceeding. Held Air Canada responsible for all information on its website including chatbot output; rejected the argument...
2 VAID-2022-0002
Air Canada chatbot invents a bereavement-fare refund policy
2023-01-01 2024-02-14