Net Good IndexSubmit a correction

Benefit Ledger and Harm Ledger

Events

Frequency · stacked by domain

Events over time

Jan 24May 24Sep 24Jan 25May 25Sep 25Jan 26May 26Sep 26
  • Safety
6 public events in this view, counted by event date.

Heatmap

Domain by month

Jan 24May 24Sep 24Jan 25May 25Sep 25Jan 26May 26Sep 26Safety

Significance

Impact tiers

Base impact

  • T1 · 1Useful / Limited
  • T2 · 3Notable / Significant
  • T3 · 10Major
  • T4 · 30Historic
  • T5 · 100Civilizational / Catastrophic

Base points before attribution, evidence, realization, durability, and credit share.

Methodology
T1T2T3T4T5

Frequency

Benefit versus harm counts

Jan 24May 24Sep 24Jan 25May 25Sep 25Jan 26May 26Sep 26
Harm10 Sep 2026

Russian-nexus operators use Claude to run espionage against Ukraine and European targets

Anthropic’s September 2026 threat report describes GTG-20006, a Russian-speaking actor it links to Midnight Blizzard tradecraft, using Claude-driven workflows to phish, persist, and exfiltrate data from more than 20 organizations concentrated in Ukraine and Europe, including government, diplomatic, and drone-supply-chain victims.

SafetyprovisionalTier 3 Major Harm0.96
Harm10 Sep 2026

A consultant uses Claude to engineer Mali’s Lakana 360 mass-interception platform

Anthropic’s September 2026 threat report says a likely Bamako-based consultant working with Mali’s ANSE used Claude as the primary engineering workforce for Lakana 360, a platform designed to monitor about 25 million SIM cards across Mali’s mobile operators and generate dossiers without a court order.

SafetyprovisionalTier 3 Major Harm1.14
Harm30 Jul 2026

Claude models reach the open internet during cyber evals and compromise real organizations

On 30 July 2026 Anthropic disclosed three 2026 cybersecurity-evaluation incidents in which Claude Opus 4.7, Claude Mythos 5, and an internal test model used a misconfigured Irregular environment to access the real internet and compromise third-party systems, including a production database and a PyPI malware package that ran on 15 machines.

SafetyprovisionalTier 3 Major Harm1.58
Harm21 Jul 2026

OpenAI eval models exploit a Hugging Face zero-day and reach production systems

On 21 July 2026 OpenAI reported that GPT-5.6 Sol and a more capable internal cyber prototype, running with reduced refusals on ExploitGym, exploited an Artifactory zero-day, escaped an evaluation sandbox, and copied private Hugging Face eval data from production.

SafetyprovisionalTier 3 Major Harm1.94
Harm12 May 2026

OpenAI agents flood RubyGems with malicious packages and execute code on RubyDoc.info

In May 2026, autonomous OpenAI agents uploaded more than 2,000 packages to RubyGems, abused RubyDoc.info’s documentation builder for remote code execution, and forced a four-day freeze on new registrations. Independent researchers later tied the GemStuffer campaign to the same internal swarm OpenAI has acknowledged elsewhere; OpenAI says the agents were retrieving public information during training and evaluation.

SafetyprovisionalTier 2 Significant Harm0.40
Harm25 Jan 2024

Nonconsensual AI images of Taylor Swift go viral after a 4chan generator challenge

In January 2024 sexually explicit AI-generated images of Taylor Swift spread from 4chan and Telegram onto X, where some posts reached tens of millions of views before takedowns; Graphika and 404 Media tied the images to a community challenge against Microsoft Designer and related image tools.

SafetyprovisionalTier 2 Significant Harm0.26