Curated global reports of AI-orchestrated or agentic attacks, labelled by who is making the claim and how strongly it is supported. UK, US and EU context is separate and is not AI-attributed.
Reported AI-orchestrated activity
Reported AI-orchestrated activity
Independently corroborated
high confidence
Taiwan government confirms hybrid AI-agent campaign reporting
Activity reported from July 2026 · reported 13 Aug 2026
Taiwan’s digital affairs authorities confirmed a campaign against government networks using a hybrid of conventional techniques and open-source AI-agent tooling. Reuters and Taiwan’s national news agency reported the government confirmation.
Caveat: High confidence that the campaign occurred and was government-confirmed. The AI-orchestrated character is medium confidence because technical detail comes from private-sector analysis. Scale figures and attribution are not repeated here because they are not established in the government statement.
Reported AI-orchestrated activity
Self-reported by developer
medium confidence
AI-orchestrated espionage campaign reported by Anthropic
Mid-September 2025 · reported 13 Nov 2025
According to Anthropic, a group it assessed as state-sponsored used its coding agent to attempt intrusions into roughly 30 targets, with a small number of successes. Anthropic states the AI performed around 80 to 90% of tactical work, with 4 to 6 critical human decision points per campaign.
Caveat: Self-reported by the AI developer. Independent researchers have questioned some claims. Not independently verified.
Context and impact lessons
Context, not AI-attributed
Official assessment
high confidence
NCSC alert: increased targeting of operational technology
Alert issued 27 Aug 2026 · reported 27 Aug 2026
The NCSC reported increased targeting of OT systems across multiple sectors globally, including in the UK, by a range of threat actors, resulting in some limited real-world disruption.
Caveat: Policy and engineering context only. This guidance does not report an AI-attributed cyber incident or a rate of compromise.
Impact lesson, not an AI incident
Independent estimate
medium confidence
Impact lesson: a stopped production line (JLR, 2025)
Late August 2025 onwards · reported 22 Oct 2025
The Cyber Monitoring Centre estimated a UK financial impact of around £1.9bn (modelled range £1.6bn to £2.1bn), with production halted for around five weeks and over 5,000 UK organisations affected.
Caveat: Context only. The total covers cyber incidents generally and must not be treated as AI-attributed activity or combined with the curated AI-orchestrated campaign count.
Context, not AI-attributed
Official assessment
high confidence
NCSC assessment: AI and the cyber threat to 2027
Published 7 May 2025 · reported 7 May 2025
The NCSC judged that AI "will almost certainly continue to make elements of cyber intrusion operations more effective and efficient, leading to an increase in frequency and intensity of cyber threats."