Skip to Content
logologo
AI Incident Database
Open TwitterOpen RSS FeedOpen FacebookOpen LinkedInOpen GitHub
Open Menu
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Discover
Submit
  • Welcome to the AIID
  • Discover Incidents
  • Spatial View
  • Table View
  • List view
  • Entities
  • Taxonomies
  • Submit Incident Reports
  • Submission Leaderboard
  • Blog
  • AI News Digest
  • Risk Checklists
  • Random Incident
  • Sign Up
Collapse
Entities

Unknown generative AI developers

Incidents involved as Developer

Incident 97113 Report
Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

2023-05-02

The Iranian state-sponsored group Cotton Sandstorm, linked to the IRGC, has integrated generative AI into cyber influence operations. In December 2023, it launched Operation “For Humanity," using AI-crafted messaging to hijack a U.S.-based IPTV streaming service with propaganda about the Israel-Hamas conflict. The group also engages in election-related reconnaissance, which suggests they used AI-enhanced influence efforts ahead of the 2024 U.S. election.

More

Incident 9992 Report
Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

2025-03-12

A phishing campaign has reportedly been impersonating Meta support using a fake chatbot interface to hijack Instagram Business accounts. Victims received emails claiming ad violations and were directed to a fraudulent site mimicking Meta's support. There, a simulated chatbot instructed users to add the attacker’s Authenticator app as a secure login method, enabling account takeover. It remains unclear whether the chatbot used AI or was human-operated via a bot-like interface. See editor's note.

More

Incident 9911 Report
Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

2025-03-14

Scammers have allegedly been using AI-generated imposter websites and phishing emails to impersonate the IRS. They have reportedly been tricking taxpayers into providing personal and financial information. There has been a reported surge in tax-related AI scams leading up to Tax Day 2025, with fraudulent domains mimicking IRS services, along with fake websites, emails, and text messages. The IRS has warned taxpayers to verify official sites and avoid unsolicited links.

More

Incident 10171 Report
Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

2025-04-07

Spanish police arrested six individuals allegedly behind a €19M ($20.9M) global investment scam powered by AI. The operation used deepfake ads featuring national celebrities to deceive victims, many of whom were selected through targeting algorithms. Scammers posed as financial advisors and fake officials, cycling through romance baiting, investment fraud, and recovery scams. AI-generated content amplified trust and engagement.

More

Related Entities
Other entities that are related to the same incident. For example, if the developer of an incident is this entity but the deployer is another entity, they are marked as related entities.
 

Entity

Islamic Revolutionary Guard Corps (IRGC)

Incidents involved as both Developer and Deployer
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Government of Iran

Incidents involved as both Developer and Deployer
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Cotton Sandstorm

Incidents involved as both Developer and Deployer
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

U.S. elections

Incidents Harmed By
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

political candidates

Incidents Harmed By
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Media organizations

Incidents Harmed By
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

General public of the United States

Incidents Harmed By
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Electoral integrity

Incidents Harmed By
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Democracy

Incidents Harmed By
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

American voters

Incidents Harmed By
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Voicemod

Incidents implicated systems
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Unknown generative AI tools

Incidents implicated systems
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Social media platforms

Incidents implicated systems
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Remini AI Photo Enhancer

Incidents implicated systems
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

News media systems

Incidents implicated systems
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Murf AI

Incidents implicated systems
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

IPTV streaming service

Incidents implicated systems
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Election-related websites

Incidents implicated systems
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

Appy Pie

Incidents implicated systems
  • Incident 971
    13 Reports

    Iranian Hacker Group Cotton Sandstorm Integrating AI into Cyber Influence Operations

More
Entity

scammers

Incidents involved as Deployer
  • Incident 999
    2 Reports

    Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Fraudsters

Incidents involved as Deployer
  • Incident 999
    2 Reports

    Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Phishers

Incidents involved as Deployer
  • Incident 999
    2 Reports

    Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Scammers impersonating the IRS

Incidents involved as Deployer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Cyber criminals

Incidents involved as Deployer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Black-box AI developers

Incidents involved as Developer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Generative AI fraud tools

Incidents involved as Developer
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Taxpayers in the United States

Incidents Harmed By
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

U.S. citizens

Incidents Harmed By
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Identity theft victims

Incidents Harmed By
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

IRS

Incidents Harmed By
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

AI-powered phishing kits

Incidents implicated systems
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

SMS phishing networks

Incidents implicated systems
  • Incident 991
    1 Report

    Alleged AI-Generated IRS Scam Websites Used to Defraud U.S. Taxpayers

More
Entity

Scammers impersonating Meta support

Incidents involved as Deployer
  • Incident 999
    2 Reports

    Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

More
Entity

Meta users

Incidents Harmed By
  • Incident 999
    2 Reports

    Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

More
Entity

Instagram users

Incidents Harmed By
  • Incident 999
    2 Reports

    Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

More
Entity

Instagram Business users

Incidents Harmed By
  • Incident 999
    2 Reports

    Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

More
Entity

Unknown chatbot interface

Incidents implicated systems
  • Incident 999
    2 Reports

    Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

More
Entity

Instagram

Incidents implicated systems
  • Incident 999
    2 Reports

    Attackers Reportedly Deployed Simulated AI Support Chatbot to Trick Instagram Business Users into Adding Malicious 2FA Login

More
Entity

Unnamed criminal group in Spain

Incidents involved as Deployer
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

Individuals arrested in Granada and Alicante

Incidents involved as Deployer
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

Unknown deepfake technology developers

Incidents involved as Developer
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

General public

Incidents Harmed By
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

General public of Spain

Incidents Harmed By
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

Global victims targeted by scams

Incidents Harmed By
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

Individuals who lost money through scam investment platforms

Incidents Harmed By
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

AI-generated deepfake video systems

Incidents implicated systems
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

Algorithmic targeting tools

Incidents implicated systems
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

Fake investment platforms

Incidents implicated systems
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

Identity spoofing and impersonation tools

Incidents implicated systems
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More
Entity

Unknown deepfake apps

Incidents implicated systems
  • Incident 1017
    1 Report

    Alleged Deepfake Investment Scam in Spain Defrauds 208 Victims of €19 million ($20.9 million)

More

Research

  • Defining an “AI Incident”
  • Defining an “AI Incident Response”
  • Database Roadmap
  • Related Work
  • Download Complete Database

Project and Community

  • About
  • Contact and Follow
  • Apps and Summaries
  • Editor’s Guide

Incidents

  • All Incidents in List Form
  • Flagged Incidents
  • Submission Queue
  • Classifications View
  • Taxonomies

2023 - AI Incident Database

  • Terms of use
  • Privacy Policy
  • Open twitterOpen githubOpen rssOpen facebookOpen linkedin
  • 30ebe76