McKinsey's internal AI platform Lilli exposed via SQL injection
Security firm CodeWall pointed an autonomous offensive agent at McKinsey's Lilli AI platform and gained read and write access to its production database within about two hours via a blind SQL injection. The database held tens of millions of chat messages, hundreds of thousands of files and the platform's system prompts. McKinsey patched quickly and said forensics found no unauthorized third-party access to client data.
- Disclosed
- 9 Mar 2026
- Organization
- McKinsey & Company
- Vendor
- Unknown
- Product
- Lilli
- Kind of AI
- Workplace copilot
- AI's role
- AI was the target
- How it happened
- Leaky AI product: App flaw
- Harm
- Data exposed
- Data involved
- Chat logs, Internal documents, Personal data
- Reach
- One organization
- Records
- 57,000
- Severity
- Medium
- Model at fault
- No
- Status
- Confirmed