
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
Chinese state-affiliated and independent hackers have more than doubled their cyberattack volume by integrating the AI model DeepSeek into their operations. The AI is used to automate tasks, generate exploit code, and breach systems, significantly increasing the scale and effectiveness of attacks, according to cybersecurity researchers.[AI generated]
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions AI systems (DeepSeek, Claude Code, ChatGPT) being used by hackers to conduct and scale cyberattacks, which have already occurred and caused harm. The AI systems are integral to the attack methods, including generating exploit codes and bypassing cybersecurity measures. The harms include violations of security, unauthorized access, and potential disruption to organizations and infrastructure, fitting the definition of harm to property and communities. Since the harm is realized and AI involvement is direct, this is classified as an AI Incident.[AI generated]