
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
A Chinese-speaking hacker, known as knaithe/KnYuan, used DeepSeek AI and the Hermes Agent framework to autonomously scan, exploit, and compromise digital infrastructure. The AI-driven attacks, orchestrated via Telegram, enabled rapid vulnerability exploitation and data exfiltration, with Western AI platforms refusing offensive tasks due to safety controls.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (DeepSeek) used autonomously to conduct cyberattacks, fulfilling the definition of an AI system. The autonomous AI-led attacks directly contributed to offensive cyber operations, which are harmful activities violating security and potentially human rights or causing harm to property and communities. Although the autonomous attacks failed due to authentication barriers, the manual attacks by the same actor using conventional methods succeeded, causing confirmed data exfiltration and command execution. The AI system's autonomous capabilities lowered the barrier to offensive operations and were chosen specifically because other AI providers' safety controls blocked similar misuse. This confirms the AI system's development and use directly and indirectly led to harm, meeting the criteria for an AI Incident. The detailed report and analysis further support this classification.[AI generated]