Sev0AI security incidents, tracked

All incidents / Leaky AI product

McKinsey's internal AI platform Lilli exposed via SQL injection

McKinsey & Company, disclosed 9 Mar 2026. Leaky AI product Data exposed Medium

Security firm CodeWall pointed an autonomous offensive agent at McKinsey's Lilli AI platform and gained read and write access to its production database within about two hours via a blind SQL injection. The database held tens of millions of chat messages, hundreds of thousands of files and the platform's system prompts. McKinsey patched quickly and said forensics found no unauthorized third-party access to client data.

Disclosed
9 Mar 2026
Organization
McKinsey & Company
Vendor
Unknown
Product
Lilli
Kind of AI
Workplace copilot
AI's role
AI was the target
How it happened
Leaky AI product: App flaw
Harm
Data exposed
Data involved
Chat logs, Internal documents, Personal data
Reach
One organization
Records
57,000
Severity
Medium
Model at fault
No
Status
Confirmed

Sources

  1. https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform
  2. https://www.theregister.com/2026/03/09/mckinsey_ai_chatbot_hacked/
  3. https://incidentdatabase.ai/cite/1412

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "McKinsey's internal AI platform Lilli exposed via SQL injection", https://sev0.fyi/incidents/2026-03-09-mckinsey-lilli-sql-injection/