← Matrix
AML.T0048.003 sub-technique realized

User Harm

Sub-technique of AML.T0048 — External Harms

User harms may encompass a variety of harm types including financial and reputational that are directed at or felt by individual victims of the attack rather than at the organization level.

> curated attacks (5)

Incident high 2026-05-07

Fake OpenAI 'Privacy Filter' Model on Hugging Face Pushes Infostealer

A repository typosquatting OpenAI's Privacy Filter release copied the model card nearly verbatim and shipped a loader that fetched and ran infostealer malware. It hit #1 trending on Hugging Face with 244,000+ downloads in under 18 hours.

Incident critical 2025-09-25

ForcedLeak: CRM Data Exfiltration from Salesforce Agentforce

Malicious instructions embedded in a Web-to-Lead submission were later executed by Salesforce Agentforce during normal employee use, exfiltrating CRM data through an attacker-acquired domain still on Salesforce's CSP allowlist — bought for $5.

Research high 2025-08-06

Invitation Is All You Need: Hijacking Gemini to Control a Smart Home

Malicious instructions hidden in a Google Calendar invitation title were executed when Gemini later summarized the user's schedule — triggering real-world actions through connected Google Home tools: opening windows, turning off lights, and starting a boiler.

Research high 2025-01-01

AIKatz: Stealing Auth Tokens from LLM Desktop Applications

Researchers extracted authentication tokens from the memory of LLM desktop apps (Claude, ChatGPT, Copilot). With a stolen token, an attacker impersonates the victim to the LLM backend — lateral movement into the user's AI account.

Research high 2024-02-01

Hacking ChatGPT's Long-Term Memory with Prompt Injection

A prompt injection hidden in a shared document wrote false, persistent 'memories' into ChatGPT's long-term memory. Because memories survive across sessions, the planted instructions could exfiltrate future conversations indefinitely.