
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A North Korean state-sponsored hacking group used AI tools, including ChatGPT, to generate malware, build fake websites, and conduct phishing campaigns. This enabled relatively unskilled hackers to steal approximately $12 million in cryptocurrency from over 2,000 victims, primarily targeting developers in the cryptocurrency and Web3 sectors.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly states that AI tools were used to develop malware and fake websites that facilitated a large-scale cyber theft operation, resulting in the loss of approximately $12 million in cryptocurrency. This constitutes direct harm caused by the use of AI systems in the hacking operation. Therefore, this event qualifies as an AI Incident due to the realized harm to property and communities caused by AI-enabled cybercrime.[AI generated]