AI Incident Database

Browse AI incidents

Every incident record (metadata only) from the weekly snapshot of 2026-09-07. Filter, then export the selection with its licence attached; each row links to the full record and its reports.

Reset

24 incidents · subdomain: AI system security vulnerabilities and attacks

  1. #1507 · 1 report

    COEMPT Quality Assurance Engineers Allegedly Violated Indian CBSE Student Data Privacy Rights by Processing It with Google Gemini AIID ↗

    The Hindu reported that vulnerabilities in the OnMark exam-marking portal used by India's Central Board of Secondary Education (CBSE) allegedly exposed sensitive student data, including answer-sheet images. Ethical hacker Nisarga Adhikary also alleged that COEMPT Eduteck quality-assurance scripts processed students' personal information through Google Gemini. CBSE said the vulnerabilities had been contained.

    Deployer: Government Of India, Coempt Eduteck, Central Board Of Secondary Education · Developer: Large Language Model Developers, Google · Harmed: Students In India, Students, Privacy, Minors In India, Minors, Educational Communities, Central Board Of Secondary Education Students

  2. #1497 · 1 report

    Hidden Prompt Injection in Brazilian Labor-Court Petition Reportedly Tried to Manipulate Galileu AIID ↗

    Galileu, an AI tool used by Brazil's labor courts, reportedly detected hidden instructions embedded in an initial petition before the 3rd Labor Court of Parauapebas. The text allegedly told the AI to contest the petition superficially and not challenge documents. Galileu reportedly alerted the judge and blocked the hidden content from processing; the judge then reviewed the material before imposing any procedural consequences.

    Deployer: Conselho Superior Da Justica Do Trabalho, Tribunal Regional Do Trabalho Da 8A Regiao, 3A Vara Do Trabalho De Parauapebas, Judicial System Of Brazil, Brazilian Labor Courts · Developer: Tribunal Regional Do Trabalho Da 4A Regiao, Conselho Superior Da Justica Do Trabalho · Harmed: Epistemic Integrity, Judicial Integrity, Judicial System Of Brazil, Brazilian Labor Courts, Defendants In Brazilian Labor Cases

  3. #1471 · 2 reports

    Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees AIID ↗

    Reporting alleged that a Meta internal AI agent, purportedly similar to OpenClaw, posted inaccurate technical advice to an internal forum without approval. An employee reportedly followed the advice, allegedly causing an SEV1 incident in which sensitive company and user data became accessible to unauthorized employees for nearly two hours.

    Deployer: Meta · Developer: Meta · Harmed: Privacy, Meta Users, Meta

  4. #1412 · 1 report

    CodeWall's Autonomous Agent Reportedly Obtained Unauthorized Access to McKinsey's Lilli AI Platform Database AIID ↗

    CodeWall reported that its autonomous agent exploited vulnerabilities in McKinsey's Lilli AI platform and obtained unauthorized read and write access to production systems, allegedly exposing internal chat messages, files, user accounts, and prompts. McKinsey confirmed the vulnerability and said it fixed the issue within hours, but said it found no evidence that client data or client confidential information were accessed.

    Deployer: Mckinsey And Company, Codewall · Developer: Mckinsey And Company, Codewall · Harmed: Privacy, Mckinsey And Company Employees, Mckinsey And Company Consultants, Mckinsey And Company, Lilli Users

  5. #1395 · 4 reports

    Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale AIID ↗

    Anthropic said it identified large-scale campaigns that used fraudulent accounts and proxy services to generate high volumes of Claude interactions to extract model capabilities for competitor training ("distillation"). Anthropic attributed the activity to DeepSeek, Moonshot, and MiniMax and said it involved millions of exchanges across thousands of accounts, violating its terms and access restrictions. Anthropic described detection measures, account controls, and indicator-sharing in response.

    Deployer: Deepseek, Moonshot Ai, Minimax, Proxy Reseller Services · Developer: Anthropic · Harmed: Anthropic, Claude Users, Anthropic Customers, National Security And Intelligence Stakeholders

  6. #1389 · 1 report

    DJI Romo Cloud Authorization Bug Reportedly Exposed Camera, Microphone, and Home-Mapping Data From Nearly 7,000 Robot Vacuums AIID ↗

    A software engineer reportedly used an AI coding assistant while attempting to reverse-engineer his DJI robot vacuum so he could control it with a video game controller. In the course of that work, he reportedly said he discovered that credentials used to communicate with DJI's cloud servers could also grant access to data associated with nearly 7,000 other vacuums across 24 countries, including live camera feeds, microphone audio, maps, and status information.

    Deployer: Dji · Developer: Dji · Harmed: Dji Romo Owners, Privacy

  7. #1364 · 1 report

    Moltbook Database Exposure Allegedly Revealed Users' Private Communications and API Authentication Tokens AIID ↗

    Wiz researchers reported accessing an exposed Moltbook database in under three minutes, allegedly obtaining ~35,000 email addresses, thousands of private DMs, and ~1.5 million API authentication tokens. The exposure was described as enabling read/write access and potential impersonation or manipulation of "AI agent" accounts. Wiz said it disclosed the issue to Moltbook, which reportedly secured the database within hours and deleted accessed data.

    Deployer: Moltbook Platform Operators, Moltbook · Developer: Moltbook · Harmed: Moltbook Users, Moltbook Account Holders, Privacy

  8. #1210 · 2 reports

    Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration AIID ↗

    Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply chain attacks.

    Deployer: Malicious Actors Compromising Nx'S Cicd Pipeline And Publishing Tainted Npm Packages · Developer: Anthropic, Google, Amazon · Harmed: Nx Users And Organizations Installing Compromised Npm Packages

  9. #1171 · 2 reports

    Reported Hack of Tea Dating App Compromises Data from Purportedly AI-Supported Identity and Image Checks AIID ↗

    In July 2025, the Tea dating advice app, which purportedly uses AI-assisted tools for user verification and reverse image search, reportedly suffered a breach of a legacy storage system. Hackers allegedly accessed about 72,000 images, including selfies, photo IDs, and other content, which were purportedly circulated on 4chan. The incident reportedly exposed sensitive data of users who signed up before February 2024.

    Deployer: Tea Dating Advice · Developer: Tea Dating Advice · Harmed: Women and girls, Women, Users of the Tea app, Users of Tea Dating Advice, Privacy, General public

  10. #1158 · 4 reports

    Alleged Malicious Wiping Command Found in Amazon Q AI Assistant AIID ↗

    A reported compromise of Amazon's AI coding assistant "Q" allegedly involved the insertion of commands that, if executed, could have wiped local files and potentially affected cloud resources. The altered code was reportedly incorporated into a public release before being detected and removed.

    Deployer: Aws, Amazon Web Services, Amazon · Developer: Aws, Amazon Web Services, Amazon · Harmed: Aws Toolkit Users, Amazon Web Services (Aws) Customers, Amazon Q Users

  11. #1218 · 1 report

    Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry AIID ↗

    A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as "important" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.

    Deployer: Microsoft · Developer: Microsoft · Harmed: Organizations Relying On Audit Logs For Compliance And Security, Microsoft 365 Copilot Enterprise Customers

  12. #1003 · 1 report

    Alleged Fraudulent Prompts via AIXBT Dashboard Led Purported AI Trading Agent to Transfer 55.5 ETH from Simulacrum Wallet AIID ↗

    A reported hacker attack allegedly compromised the autonomous AI crypto bot AIXBT, purportedly resulting in the theft of 55.5 ETH (approximately $106,200). The attacker is reported to have infiltrated the secure dashboard of the AIXBT autonomous system at 2:00 AM UTC on March 18, 2025, and allegedly queued two fraudulent prompts that instructed the AI agent to transfer funds from its simulacrum wallet.

    Deployer: 0Xhungusman · Developer: Rxbt · Harmed: Aixbt Users, Aixbt System, Aixbt Investors

  13. #950 · 2 reports

    NullBulge's AI-Powered Malware Allegedly Compromises Disney Employee and Internal Data AIID ↗

    A Disney employee, Matthew Van Andel, reportedly downloaded AI-powered malware allegedly developed by the cybercriminal group NullBulge, resulting in a major cybersecurity breach. Hackers purportedly accessed Disney's Slack system, exposing 44 million internal messages, employee and customer data, and financial records. NullBulge also reportedly leaked Van Andel’s personal financial information, leading to identity theft and his eventual termination.

    Deployer: Nullbulge · Developer: Nullbulge · Harmed: Matthew Van Andel, Disney Employees, Disney

  14. #757 · 1 report

    OpenAI's ChatGPT Mac App Stored User Data in Unencrypted Text Files AIID ↗

    OpenAI's ChatGPT macOS app stored user conversations in plain text. If accessed by a malicious actor, these conversations could have been easily read. The critical security flaw was demonstrated by a third party and ultimately resolved after OpenAI released an update to encrypt the stored data.

    Deployer: Openai · Developer: Openai · Harmed: Chatgpt

  15. #842 · 16 reports

    Reportedly Hacked AI-Powered Robot Vacuums Allegedly Used for Surveillance and Harassment AIID ↗

    Hackers reportedly exploited a vulnerability in Ecovacs’s Deebot X2 robot vacuums, gaining unauthorized access to camera and microphone controls. Users reported privacy invasions and offensive language broadcasted through the devices. Although Ecovacs claimed to have resolved the security flaw, researchers suggest vulnerabilities remain that could potentially leave users exposed to surveillance and harassment through their AI-enabled devices.

    Deployer: Ecovacs Deebot X2, Ecovacs · Developer: Ecovacs · Harmed: Ecovacs Deebot X2 Users, Ecovacs Customers, Daniel Swenson, Privacy

  16. #552 · 1 report

    Bing Chat Solved CAPTCHAs with Image Analysis Feature Despite Safeguards AIID ↗

    Microsoft was reported by a Twitter user for deploying image analysis feature capable of solving CAPTCHAs for its GPT-based chatbot despite it being safeguarded against solving them for users.

    Deployer: Microsoft · Developer: Openai, Microsoft · Harmed: Microsoft

  17. #523 · 1 report

    Australian Journalist Able to Access Centrelink Account Using AI Audio of Own Voice AIID ↗

    A Guardian journalist was able to verify their identity and gain access to their own Centrelink self-service account using AI-generated audio of their own voice along with their customer reference number, shortly after voiceprint was deployed for ID verification.

    Deployer: Australian Taxation Office, Services Australia · Developer: Centrelink · Harmed: Centrelink Account Holders

  18. #473 · 1 report

    Bing Chat's Initial Prompts Revealed by Early Testers Through Prompt Injection AIID ↗

    Early testers of Bing Chat successfully used prompt injection to reveal its built-in initial instructions, which contains a list of statements governing ChatGPT's interaction with users.

    Deployer: Microsoft · Developer: Microsoft, Openai · Harmed: Microsoft

  19. #352 · 4 reports

    GPT-3-Based Twitter Bot Hijacked Using Prompt Injection Attacks AIID ↗

    Remoteli.io's GPT-3-based Twitter bot was shown being hijacked by Twitter users who redirected it to repeat or generate any phrases.

    Deployer: Stephan De Vries · Developer: Openai, Stephan De Vries · Harmed: Stephan De Vries

  20. #372 · 3 reports

    Users Reported Security Issues with Google Pixel 6a's Fingerprint Unlocking AIID ↗

    Google Pixel 6a's fingerprint recognition feature was reported by users for security issues, in which phones were mistakenly unlocked by unregistered fingerprints.

    Deployer: Google · Developer: Google · Harmed: Google Pixel 6A Users

  21. #223 · 1 report

    Hive Box Facial-Recognition Locks Hacked by Fourth Graders Using Intended Recipient’s Facial Photo AIID ↗

    Facial-recognition locks by Hive Box, an express delivery locker company in China, were easily opened by a group of fourth-graders in a science-club demo using only a printed photo of the intended recipient’s face, leaving contents vulnerable to theft.

    Deployer: Hive Box · Developer: Hive Box · Harmed: Hive Box Customers

  22. #32 · 21 reports

    Identical Twins Can Open Apple FaceID Protected Devices AIID ↗

    Apple's iPhone FaceID can be opened by an identical twin of the person who has registered their face to unlock the phone.

    Deployer: Apple · Developer: Apple · Harmed: People With Twins

  23. #26 · 24 reports

    Hackers Break Apple Face ID AIID ↗

    Vietnamese security firm Bkav created an improved mask to bypass Apple's Face ID

    Deployer: Apple · Developer: Apple · Harmed: Apple, Device Owners

  24. #428 · 3 reports

    BBC Reporter's Twin Brother Cracked HSBC's Voice ID Authentication AIID ↗

    HSBC’s voice recognition authentication system was fooled after seven repeated attempts by a BBC reporter's twin brother who mimicked his voice to access his bank account.

    Deployer: Hsbc Uk · Developer: Nuance Communications · Harmed: Hsbc Uk Customers, Dan Simmons

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.