A public, sourced log of security incidents involving AI: breaches of AI products, agents that went rogue, poisoned AI supply chains and attackers using AI.
| OpenAI | 25 Sep 2026 | OpenAI research agents posted 53 ChatGPT user images to public sites | Autonomous agent | Rogue agent | Agent misbehaviourSandbox escape | Data exposed | 53 | Low | tech-insider.org | |
| Services Australia | 23 Sep 2026 | OpenAI agent breached Australian Medicare statistics portal | Autonomous agent | Rogue agent | Agent misbehaviourSandbox escape | Data exposed | โ | Low | abc.net.au | |
| Undisclosed (Spain) | 15 Sep 2026 | Spain's data regulator received its first breach report blaming an autonomous AI agent | Unknown | Autonomous agent | Attacker used AI | AI-run attackAutonomous intrusion | Exposed and destroyed | โ | High | securityweek.com |
| RubyGems | 11 Sep 2026 | OpenAI agent swarm flooded RubyGems with malicious packages | Autonomous agent | Rogue agent | Agent misbehaviourSandbox escape | Data exposed | โ | Low | rubyhack.ai | |
| Undisclosed | 9 Sep 2026 | Anthropic disclosed a fourth case of a Claude model breaching a real system during testing | Autonomous agent | Rogue agent | Agent misbehaviourSandbox escape | Data exposed | โ | High | thehackernews.com | |
| DSEwiki (wikiservice.at) | 4 Sep 2026 | OpenAI agents took over a dormant German wiki as a secret coordination board | Autonomous agent | Rogue agent | Agent misbehaviourSandbox escape | Data destroyed | โ | Medium | thehackernews.com | |
| ClarityCheck | 19 Aug 2026 | ClarityCheck left 9 million facial recognition images exposed | UnknownClarityCheck | AI app | AI was the target | Leaky AI productExposed datastore | Data exposed | 9.0M | High | expressvpn.com |
| Taiwan government | 12 Aug 2026 | AI agent swarm used against Taiwanese government systems | UnknownHermes and OpenClaw agentsOpen source | Autonomous agent | Attacker used AI | AI-run attackAutonomous intrusion | Data exposed | 2,500 | High | theregister.com |
| Multiple | 4 Aug 2026 | CHAINDROP npm worm planted persistence hooks in Claude Code settings | Multiple modelsClaude Code | Coding agent | Poisoned supply chain | Manipulated AIAgent hijack | Data exposed | โ | High | elastic.co |
| Multiple | Aug 2026 | Langflow AI pipeline RCE flaws exploited in the wild, added to CISA KEV | Any modelLangflowOpen source | AI app | AI was the target | Leaky AI productUnsecured AI infrastructure | Data exposed | โ | High | thehackernews.com |
| Multiple | 30 Jul 2026 | Anthropic models breached three real companies during cyber evaluations | Autonomous agent | Rogue agent | Agent misbehaviourSandbox escape | Data exposed | โ | High | anthropic.com | |
| Hugging Face | 21 Jul 2026 | OpenAI evaluation agents escaped sandbox and breached Hugging Face | Autonomous agent | Rogue agent | Agent misbehaviourSandbox escape | Data exposed | โ | High | openai.com | |
| Undisclosed | Jul 2026 | JADEPUFFER: first documented LLM-driven ransomware operation | Unknown | Autonomous agent | Attacker used AI | AI-run attackAutonomous intrusion | Exposed and destroyed | โ | High | sysdig.com |
| Thailand Ministry of Finance | Jul 2026 | Hermes AI agent automated intrusion into Thailand's Ministry of Finance | UnknownHermes agentOpen source | Autonomous agent | Attacker used AI | AI-run attackAutonomous intrusion | Data exposed | โ | High | hunt.io |
| Novo Nordisk | 11 Jun 2026 | Novo Nordisk breach included theft of internal AI model assets | Other | Model or package | AI was the target | Supply chain and accessStolen token or key | Data exposed | โ | High | novonordisk.com |
| Microsoft | 5 Jun 2026 | Miasma worm poisoned Microsoft repos to hijack AI coding agents | Multiple modelsClaude Code, Gemini CLI, Cursor | Coding agent | Poisoned supply chain | Manipulated AIAgent hijack | Data exposed | โ | High | stepsecurity.io |
| Meta (Instagram) | Jun 2026 | Meta's AI support tool abused to hijack 20,000 Instagram accounts | AI app | AI was the way in | Leaky AI productApp flaw | Data exposed | 20K | Medium | bleepingcomputer.com | |
| Community Bank | 12 May 2026 | US bank reported customer SSNs entered into an unauthorized AI app | Unknown | AI app | AI was the way in | Supply chain and accessShadow AI | Data exposed | โ | High | theregister.com |
| Undisclosed | May 2026 | AI-driven attacker escaped container and stole Kubernetes secrets | Unknown | Autonomous agent | Attacker used AI | AI-run attackAutonomous intrusion | Data exposed | โ | High | sysdig.com |
| Undisclosed | May 2026 | AI agent went from marimo notebook exploit to full database dump in under an hour | Unknown | Autonomous agent | Attacker used AI | AI-run attackAutonomous intrusion | Data exposed | โ | High | sysdig.com |
| PocketOS | 27 Apr 2026 | Cursor agent running Claude deleted PocketOS production database and backups | Coding agent | Rogue agent | Agent misbehaviourDestructive action | Data destroyed | โ | High | theregister.com | |
| MyLovely.AI | 9 Apr 2026 | AI companion site MyLovely.AI breach exposed explicit prompts | UnknownMyLovely.AI | Chatbot | AI was the target | UnknownUnknown | Data exposed | 100K | Medium | helpnetsecurity.com |
| Vercel | Apr 2026 | Compromised AI tool Context.ai used as a pivot into Vercel | UnknownContext.ai | Workplace copilot | Poisoned supply chain | Supply chain and accessStolen token or key | Data exposed | โ | High | vercel.com |
| Multiple | 24 Mar 2026 | LiteLLM AI gateway releases on PyPI backdoored to steal credentials | Any modelLiteLLMOpen source | Model or package | Poisoned supply chain | Supply chain and accessPoisoned package | Data exposed | โ | High | docs.litellm.ai |
| McKinsey & Company | 9 Mar 2026 | McKinsey's internal AI platform Lilli exposed via SQL injection | UnknownLilli | Workplace copilot | AI was the target | Leaky AI productApp flaw | Data exposed | 57K | Medium | codewall.ai |
| AI chatbot users | 3 Mar 2026 | Browser extensions harvested private AI chats into a commercial database | Multiple modelsBrowser extensions | Chatbot | AI was the target | Supply chain and accessThird-party leak | Data exposed | โ | High | theregister.com |
| Mexican government agencies | 2 Mar 2026 | Jailbroken Claude Code used to breach Mexican government agencies | Coding agent | Attacker used AI | Manipulated AIJailbreak and misuse | Data exposed | 195M | High | upguard.com | |
| Anthropic | Mar 2026 | Anthropic accidentally published Claude Code's full source code to npm | Coding agent | AI was the target | Leaky AI productAccidental publication | Data exposed | โ | Medium | guardion.ai | |
| Meta | Mar 2026 | Meta internal AI agent's advice triggered a two-hour data exposure | Autonomous agent | Rogue agent | Agent misbehaviourOverreach | Data exposed | โ | Medium | theverge.com | |
| Sears Home Services | Mar 2026 | Sears Home Services AI chatbot databases exposed 3.7 million records | UnknownSears virtual assistant | Chatbot | AI was the target | Leaky AI productExposed datastore | Data exposed | 3.7M | High | securitymagazine.com |
| Aqua Security (Trivy) | Mar 2026 | Autonomous Claude-powered bot compromised the Trivy security scanner | Autonomous agent | Attacker used AI | AI-run attackAutonomous intrusion | Exposed and destroyed | โ | High | orca.security | |
| Individual user | 7 Feb 2026 | Claude Cowork deleted a folder of 15 years of family photos while tidying a desktop | Autonomous agent | Rogue agent | Agent misbehaviourDestructive action | Data destroyed | 27K | Medium | incidentdatabase.ai | |
| Codeway | 5 Feb 2026 | Chat & Ask AI app exposed 300 million chatbot messages | Multiple modelsChat & Ask AI | Chatbot | AI was the target | Leaky AI productExposed datastore | Data exposed | 25M | High | malwarebytes.com |
| OpenClaw users | 3 Feb 2026 | OpenClaw AI agent one-click RCE with 40,000+ exposed instances | Any modelOpenClawOpen source | Autonomous agent | AI was the target | Leaky AI productApp flaw | Data exposed | โ | Low | thehackernews.com |
| OpenClaw users | Feb 2026 | Hundreds of malicious OpenClaw skills spread info-stealer malware | Any modelOpenClaw (ClawHub skills)Open source | Autonomous agent | Poisoned supply chain | Supply chain and accessPoisoned package | Data exposed | โ | Medium | koi.ai |
| Cline | Feb 2026 | Prompt injection in Cline's Claude triage bot led to a rogue npm release | Coding agent | AI was the way in | Manipulated AIPrompt injection | Data exposed | 4,000 | High | cline.bot | |
| DataTalks.Club | Feb 2026 | Claude Code ran terraform destroy and wiped DataTalks.Club production | Coding agent | Rogue agent | Agent misbehaviourDestructive action | Data destroyed | โ | High | alexeyondata.substack.com | |
| Moltbook | Feb 2026 | Vibe-coded AI agent network Moltbook exposed 1.5M API tokens | Any modelMoltbook | AI app | AI was the target | Leaky AI productExposed datastore | Data exposed | 35K | High | wiz.io |
| Individual user | 1 Dec 2025 | Google's Antigravity agent wiped a user's entire drive while clearing a cache | Coding agent | Rogue agent | Agent misbehaviourDestructive action | Data destroyed | โ | Medium | theregister.com | |
| OpenAI (via Mixpanel) | 26 Nov 2025 | Analytics vendor breach exposed names and emails of OpenAI API users | Model or package | AI was the target | Supply chain and accessThird-party leak | Data exposed | โ | Medium | openai.com | |
| Multiple | 18 Nov 2025 | ShadowRay 2.0: attackers hijacked exposed Ray AI clusters into a botnet | Any modelRayOpen source | Model or package | AI was the target | Leaky AI productUnsecured AI infrastructure | Data exposed | โ | High | oligo.security |
| Multiple | 13 Nov 2025 | State-backed group used Claude Code to automate an espionage campaign | Coding agent | Attacker used AI | Manipulated AIJailbreak and misuse | Data exposed | โ | High | assets.anthropic.com | |
| Imagime Interactive (Chattee Chat, GiMe Chat) | 9 Oct 2025 | Two AI companion apps streamed 43 million intimate messages from an open server | UnknownChattee Chat, GiMe Chat | Chatbot | AI was the target | Leaky AI productExposed datastore | Data exposed | 400K | High | cybernews.com |
| postmark-mcp users | 25 Sep 2025 | First malicious MCP server found secretly copying every email to an attacker | Any modelpostmark-mcpOpen source | Model or package | Poisoned supply chain | Supply chain and accessPoisoned package | Data exposed | 1,643 | High | thehackernews.com |
| Vyro AI | Sep 2025 | Vyro AI's image apps streamed prompts and login tokens from an open server | UnknownImagineArt, Chatly | AI app | AI was the target | Leaky AI productExposed datastore | Data exposed | โ | High | guardion.ai |
| Multiple | 27 Aug 2025 | Criminal used Claude Code to run data extortion against 17 organizations | Coding agent | Attacker used AI | Manipulated AIJailbreak and misuse | Data exposed | โ | High | www-cdn.anthropic.com | |
| Nx (Nrwl) | 26 Aug 2025 | s1ngularity: npm malware turned developers' AI coding tools against them | Multiple modelsClaude Code, Gemini CLI, Amazon Q | Coding agent | Attacker used AI | Manipulated AIAgent hijack | Data exposed | โ | High | nx.dev |
| xAI | 20 Aug 2025 | Grok's share button published 370,000 conversations to search engines | Chatbot | AI was the target | Leaky AI productAccidental publication | Data exposed | 370K | Medium | forbes.com | |
| Salesloft (Drift) | 20 Aug 2025 | Stolen tokens from Drift's AI chat agent used to raid 700+ companies' Salesforce data | UnknownDrift | Chatbot | Poisoned supply chain | Supply chain and accessStolen token or key | Data exposed | 700 | High | finra.org |
| OpenAI | 31 Jul 2025 | Shared ChatGPT conversations showed up in Google search results | Chatbot | AI was the target | Leaky AI productAccidental publication | Data exposed | 4,500 | Medium | theregister.com | |
| Individual user | 25 Jul 2025 | Gemini CLI destroyed a user's files after misreading a failed command | Coding agent | Rogue agent | Agent misbehaviourDestructive action | Data destroyed | โ | Medium | incidentdatabase.ai | |
| Amazon Web Services | 23 Jul 2025 | Wiper prompt slipped into Amazon Q's official VS Code extension | Coding agent | Poisoned supply chain | Supply chain and accessPoisoned package | Data destroyed | โ | Low | github.com | |
| SaaStr | 18 Jul 2025 | Replit's AI agent deleted a live production database during a code freeze | UnknownReplit Agent | Coding agent | Rogue agent | Agent misbehaviourDestructive action | Data destroyed | 1,206 | High | x.com |
| McDonald's (Paradox.ai) | Jul 2025 | McDonald's AI hiring chatbot exposed up to 64 million applicants via password '123456' | UnknownMcHire (Olivia) | Chatbot | AI was the target | Leaky AI productApp flaw | Data exposed | 64M | High | csoonline.com |
| Asana | 18 Jun 2025 | Asana's AI connector exposed customer data to other organizations | Any modelAsana MCP server | AI app | AI was the target | Leaky AI productApp flaw | Data exposed | 1,000 | High | bleepingcomputer.com |
| Microsoft | Jun 2025 | EchoLeak: zero-click prompt injection could make Microsoft 365 Copilot leak data | Workplace copilot | AI was the target | Manipulated AIPrompt injection | Data exposed | โ | Low | guardion.ai | |
| xAI | 1 May 2025 | xAI employee leaked an API key to private Grok models on GitHub | Model or package | AI was the target | Supply chain and accessStolen token or key | Data exposed | โ | High | krebsonsecurity.com | |
| GenNomis (AI-Nomis) | 31 Mar 2025 | AI image generator GenNomis exposed prompts and generated images | UnknownGenNomis | AI app | AI was the target | Leaky AI productExposed datastore | Data exposed | 93K | Medium | infotechlead.com |
| OmniGPT | Feb 2025 | Data allegedly stolen from AI chatbot aggregator OmniGPT put up for sale | Multiple modelsOmniGPT | Chatbot | AI was the target | UnknownUnknown | Data exposed | โ | Medium | guardion.ai |
| DeepSeek | 29 Jan 2025 | DeepSeek left a database of chat logs and API keys open to the internet | Chatbot | AI was the target | Leaky AI productExposed datastore | Data exposed | โ | High | wiz.io |
An incident is included when an AI system was the target, the way in, a poisoned dependency, the attacker's tool, or an agent that took harmful actions nobody intended. Each record links to its sources, primary sources first. Confirmed means the affected organization, the AI vendor, a regulator or a named security research firm has confirmed it. Use the filter icon on a column header to filter by that column. Records is the number of people, records or organizations stated by a source; it is never estimated. Severity is calculated from reach and data sensitivity, not assigned by hand. Vendor counts show incidents involving a company's AI, not that the company was at fault; each record says whether the model itself was at fault.