Sev0AI security incidents, tracked

All incidents / Supply chain and access

Supply chain and access: AI security incidents

11 AI security incidents classed as supply chain and access since January 2025, covering poisoned package, shadow ai, stolen token or key, third-party leak.

11 Jun 2026Novo Nordisk breach included theft of internal AI model assets
Novo Nordisk
Supply chain and accessHigh
12 May 2026US bank reported customer SSNs entered into an unauthorized AI app
Community Bank
Supply chain and accessHigh
Apr 2026Compromised AI tool Context.ai used as a pivot into Vercel
Vercel
Supply chain and accessHigh
24 Mar 2026LiteLLM AI gateway releases on PyPI backdoored to steal credentials
Multiple
Supply chain and accessHigh
3 Mar 2026Browser extensions harvested private AI chats into a commercial database
AI chatbot users
Supply chain and accessHigh
Feb 2026Hundreds of malicious OpenClaw skills spread info-stealer malware
OpenClaw users
Supply chain and accessMedium
26 Nov 2025Analytics vendor breach exposed names and emails of OpenAI API users
OpenAI (via Mixpanel)
Supply chain and accessMedium
25 Sep 2025First malicious MCP server found secretly copying every email to an attacker
postmark-mcp users
Supply chain and accessHigh
20 Aug 2025Stolen tokens from Drift's AI chat agent used to raid 700+ companies' Salesforce data
Salesloft (Drift)
Supply chain and accessHigh
23 Jul 2025Wiper prompt slipped into Amazon Q's official VS Code extension
Amazon Web Services
Supply chain and accessLow
1 May 2025xAI employee leaked an API key to private Grok models on GitHub
xAI
Supply chain and accessHigh