
The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.
SpyCloud's 2026 Identity Threat Report reveals that compromised AI agents and other non-human identities are now the primary route for attackers into enterprises, causing widespread security breaches, account takeovers, and fraud. Despite high perceived visibility, most organizations fail to adequately monitor these AI-driven risks.[AI generated]
Why's our monitor labelling this an incident or hazard?
The event explicitly involves AI systems in the form of AI agents that serve as non-human identities connecting to internal systems. The report documents that attackers exploit compromised NHIs, including AI agents, to gain unauthorized access, leading to identity-based security incidents such as account takeovers and fraud, which constitute harm to organizations and their communities. The harms are realized and ongoing, not merely potential. The AI systems' use and lack of governance contribute directly to these harms. Hence, this qualifies as an AI Incident under the framework because the AI system's use and misuse have directly led to significant harm (security breaches, fraud, and operational disruption).[AI generated]