AI Incident Database - Incident 1015
Source evidence cited by public records. This page shows where the source is used, its trust tier, and when it was last checked in the seed.
Records using this source
- cybercriminals
entity | 4 July 2026 | 70%
cybercriminals - organisation named in the AI Incident Database harm index.
- general-public
entity | 29 June 2026 | 70%
general-public - organisation named in the AI Incident Database harm index.
- unknown-malicious-actors
entity | 15 Mar 2026 | 70%
unknown-malicious-actors - organisation named in the AI Incident Database harm index.
- critical-infrastructure-systems
entity | 8 Apr 2025 | 70%
critical-infrastructure-systems - organisation named in the AI Incident Database harm index.
- darknet-forum-users
entity | 8 Apr 2025 | 70%
darknet-forum-users - organisation named in the AI Incident Database harm index.
- enterprise-it-systems
entity | 8 Apr 2025 | 70%
enterprise-it-systems - organisation named in the AI Incident Database harm index.
- unknown-black-hat-ai-developers
entity | 8 Apr 2025 | 70%
unknown-black-hat-ai-developers - organisation named in the AI Incident Database harm index.
- victims-of-automated-cybercrime
entity | 8 Apr 2025 | 70%
victims-of-automated-cybercrime - organisation named in the AI Incident Database harm index.
- victims-of-malware-attacks
entity | 8 Apr 2025 | 70%
victims-of-malware-attacks - organisation named in the AI Incident Database harm index.
- victims-of-phishing-attacks
entity | 8 Apr 2025 | 70%
victims-of-phishing-attacks - organisation named in the AI Incident Database harm index.
- xanthorox-ai-creators
entity | 8 Apr 2025 | 70%
xanthorox-ai-creators - organisation named in the AI Incident Database harm index.
- Reported Darknet Launch of Xanthorox AI Introduces Autonomous Cyberattack Platform
event | 8 Apr 2025 | 82%
Xanthorox AI is a malicious, modular AI system released on darknet forums in early 2025. Designed from scratch for offensive cyber operations, it runs on private infrastructure and includes models for code generation, phishing, malware, social engineering, and real-time voice/image input. Its release represents a deliberate deployment of an autonomous attack platform.