Chinese Hackers Use AI to Automate and Conceal Cyberattacks

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Google reports that Chinese state-linked hackers are using AI models on compromised networks to automate cyber intrusions and evade detection. These attacks target North American academic, medical, and military organizations, leading to intellectual property violations and security breaches. Authorities in Yongfeng County also addressed AI-generated misinformation about natural disasters.[AI generated]

Why's our monitor labelling this an incident or hazard?

The article explicitly mentions the use of AI models by hackers to avoid detection and automate cyber intrusions, which are unauthorized and harmful activities. The AI system's use directly contributes to the harm by enabling more efficient and stealthy attacks on sensitive networks, leading to violations of intellectual property and breaches of security. This fits the definition of an AI Incident as the AI system's use has directly led to harm (violation of intellectual property rights and harm to property). The event is not merely a potential risk but an ongoing harmful activity documented by Google, thus not an AI Hazard or Complementary Information. It is not Beneficial Use or Unrelated as the AI is used maliciously causing harm.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Government, security, and defenceHealthcare, drugs, and biotechnology

Affected stakeholders
BusinessGovernment

Harm types
Economic/PropertyHuman or fundamental rightsPublic interest

Business function:
Other

AI system task:
Event/anomaly detectionContent generation


Articles about this incident or hazard