{"attribution":{"source":"AI Incident Database (Responsible AI Collaborative)","license":"CC BY-SA 4.0","license_url":"https://creativecommons.org/licenses/by-sa/4.0/","citation":"McGregor, S. (2021). Preventing Repeated Real World AI Failures by Cataloging Incidents: The AI Incident Database. Proceedings of the AAAI Conference on Artificial Intelligence (IAAI-21).","snapshot_date":"2026-09-07"},"exported_at":"2026-09-12"}
{"rows":[{"incident_id":1507,"occurred_on":"2026-05-30","title":"COEMPT Quality Assurance Engineers Allegedly Violated Indian CBSE Student Data Privacy Rights by Processing It with Google Gemini","description":"The Hindu reported that vulnerabilities in the OnMark exam-marking portal used by India's Central Board of Secondary Education (CBSE) allegedly exposed sensitive student data, including answer-sheet images. Ethical hacker Nisarga Adhikary also alleged that COEMPT Eduteck quality-assurance scripts processed students' personal information through Google Gemini. CBSE said the vulnerabilities had been contained.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Government Of India, Coempt Eduteck, Central Board Of Secondary Education"],"developers":["Large Language Model Developers, Google"],"harmed":["Students In India, Students, Privacy, Minors In India, Minors, Educational Communities, Central Board Of Secondary Education Students"],"report_count":1},{"incident_id":1497,"occurred_on":"2026-05-13","title":"Hidden Prompt Injection in Brazilian Labor-Court Petition Reportedly Tried to Manipulate Galileu","description":"Galileu, an AI tool used by Brazil's labor courts, reportedly detected hidden instructions embedded in an initial petition before the 3rd Labor Court of Parauapebas. The text allegedly told the AI to contest the petition superficially and not challenge documents. Galileu reportedly alerted the judge and blocked the hidden content from processing; the judge then reviewed the material before imposing any procedural consequences.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Conselho Superior Da Justica Do Trabalho, Tribunal Regional Do Trabalho Da 8A Regiao, 3A Vara Do Trabalho De Parauapebas, Judicial System Of Brazil, Brazilian Labor Courts"],"developers":["Tribunal Regional Do Trabalho Da 4A Regiao, Conselho Superior Da Justica Do Trabalho"],"harmed":["Epistemic Integrity, Judicial Integrity, Judicial System Of Brazil, Brazilian Labor Courts, Defendants In Brazilian Labor Cases"],"report_count":1},{"incident_id":1471,"occurred_on":"2026-03-18","title":"Meta Internal AI Agent Reportedly Gave Advice That Allegedly Exposed Sensitive Data to Unauthorized Employees","description":"Reporting alleged that a Meta internal AI agent, purportedly similar to OpenClaw, posted inaccurate technical advice to an internal forum without approval. An employee reportedly followed the advice, allegedly causing an SEV1 incident in which sensitive company and user data became accessible to unauthorized employees for nearly two hours.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Meta"],"developers":["Meta"],"harmed":["Privacy, Meta Users, Meta"],"report_count":2},{"incident_id":1412,"occurred_on":"2026-02-28","title":"CodeWall's Autonomous Agent Reportedly Obtained Unauthorized Access to McKinsey's Lilli AI Platform Database","description":"CodeWall reported that its autonomous agent exploited vulnerabilities in McKinsey's Lilli AI platform and obtained unauthorized read and write access to production systems, allegedly exposing internal chat messages, files, user accounts, and prompts. McKinsey confirmed the vulnerability and said it fixed the issue within hours, but said it found no evidence that client data or client confidential information were accessed.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Mckinsey And Company, Codewall"],"developers":["Mckinsey And Company, Codewall"],"harmed":["Privacy, Mckinsey And Company Employees, Mckinsey And Company Consultants, Mckinsey And Company, Lilli Users"],"report_count":1},{"incident_id":1395,"occurred_on":"2026-02-23","title":"Anthropic Said DeepSeek, Moonshot, and MiniMax Used Fraudulent Accounts and Proxies to Illicitly Distill Claude Capabilities at Scale","description":"Anthropic said it identified large-scale campaigns that used fraudulent accounts and proxy services to generate high volumes of Claude interactions to extract model capabilities for competitor training (\"distillation\"). Anthropic attributed the activity to DeepSeek, Moonshot, and MiniMax and said it involved millions of exchanges across thousands of accounts, violating its terms and access restrictions. Anthropic described detection measures, account controls, and indicator-sharing in response.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Deepseek, Moonshot Ai, Minimax, Proxy Reseller Services"],"developers":["Anthropic"],"harmed":["Anthropic, Claude Users, Anthropic Customers, National Security And Intelligence Stakeholders"],"report_count":4},{"incident_id":1389,"occurred_on":"2026-02-08","title":"DJI Romo Cloud Authorization Bug Reportedly Exposed Camera, Microphone, and Home-Mapping Data From Nearly 7,000 Robot Vacuums","description":"A software engineer reportedly used an AI coding assistant while attempting to reverse-engineer his DJI robot vacuum so he could control it with a video game controller. In the course of that work, he reportedly said he discovered that credentials used to communicate with DJI's cloud servers could also grant access to data associated with nearly 7,000 other vacuums across 24 countries, including live camera feeds, microphone audio, maps, and status information.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Dji"],"developers":["Dji"],"harmed":["Dji Romo Owners, Privacy"],"report_count":1},{"incident_id":1364,"occurred_on":"2026-01-31","title":"Moltbook Database Exposure Allegedly Revealed Users' Private Communications and API Authentication Tokens","description":"Wiz researchers reported accessing an exposed Moltbook database in under three minutes, allegedly obtaining ~35,000 email addresses, thousands of private DMs, and ~1.5 million API authentication tokens. The exposure was described as enabling read/write access and potential impersonation or manipulation of \"AI agent\" accounts. Wiz said it disclosed the issue to Moltbook, which reportedly secured the database within hours and deleted accessed data.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Moltbook Platform Operators, Moltbook"],"developers":["Moltbook"],"harmed":["Moltbook Users, Moltbook Account Holders, Privacy"],"report_count":1},{"incident_id":1210,"occurred_on":"2025-08-21","title":"Malicious Nx npm Packages Reportedly Weaponize AI Coding Agents for Data Exfiltration","description":"Malicious versions of the popular Nx monorepo tool and plugins were reportedly published to npm after attackers compromised its CI workflow. The malware's postinstall script reportedly harvested credentials and exfiltrated data, reportedly weaponizing local AI coding agents such as Claude Code, Gemini, and Amazon q. By invoking unsafe flags, it allegedly coerced the tools into scanning developer machines for sensitive files, marking one of the first known AI-assisted supply chain attacks.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Malicious Actors Compromising Nx'S Cicd Pipeline And Publishing Tainted Npm Packages"],"developers":["Anthropic, Google, Amazon"],"harmed":["Nx Users And Organizations Installing Compromised Npm Packages"],"report_count":2},{"incident_id":1171,"occurred_on":"2025-07-25","title":"Reported Hack of Tea Dating App Compromises Data from Purportedly AI-Supported Identity and Image Checks","description":"In July 2025, the Tea dating advice app, which purportedly uses AI-assisted tools for user verification and reverse image search, reportedly suffered a breach of a legacy storage system. Hackers allegedly accessed about 72,000 images, including selfies, photo IDs, and other content, which were purportedly circulated on 4chan. The incident reportedly exposed sensitive data of users who signed up before February 2024.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Other","intent":"Other","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Tea Dating Advice"],"developers":["Tea Dating Advice"],"harmed":["Women and girls","Women","Users of the Tea app","Users of Tea Dating Advice","Privacy","General public"],"report_count":2},{"incident_id":1158,"occurred_on":"2025-07-17","title":"Alleged Malicious Wiping Command Found in Amazon Q AI Assistant","description":"A reported compromise of Amazon's AI coding assistant \"Q\" allegedly involved the insertion of commands that, if executed, could have wiped local files and potentially affected cloud resources. The altered code was reportedly incorporated into a public release before being detected and removed.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Aws, Amazon Web Services, Amazon"],"developers":["Aws, Amazon Web Services, Amazon"],"harmed":["Aws Toolkit Users, Amazon Web Services (Aws) Customers, Amazon Q Users"],"report_count":4},{"incident_id":1218,"occurred_on":"2025-07-04","title":"Microsoft 365 Copilot Vulnerability Allegedly Allowed File Access Without Audit Log Entry","description":"A vulnerability in Microsoft 365 Copilot reportedly allowed users to access and summarize files without generating audit log entries, allegedly undermining traceability and compliance. Security researcher Zack Korman disclosed the issue to Microsoft, which reportedly classified it as \"important\" and fixed it on August 17, 2025, but reportedly chose not to notify customers or assign a CVE.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft"],"developers":["Microsoft"],"harmed":["Organizations Relying On Audit Logs For Compliance And Security, Microsoft 365 Copilot Enterprise Customers"],"report_count":1},{"incident_id":1003,"occurred_on":"2025-03-18","title":"Alleged Fraudulent Prompts via AIXBT Dashboard Led Purported AI Trading Agent to Transfer 55.5 ETH from Simulacrum Wallet","description":"A reported hacker attack allegedly compromised the autonomous AI crypto bot AIXBT, purportedly resulting in the theft of 55.5 ETH (approximately $106,200). The attacker is reported to have infiltrated the secure dashboard of the AIXBT autonomous system at 2:00 AM UTC on March 18, 2025, and allegedly queued two fraudulent prompts that instructed the AI agent to transfer funds from its simulacrum wallet.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["0Xhungusman"],"developers":["Rxbt"],"harmed":["Aixbt Users, Aixbt System, Aixbt Investors"],"report_count":1},{"incident_id":950,"occurred_on":"2024-07-11","title":"NullBulge's AI-Powered Malware Allegedly Compromises Disney Employee and Internal Data","description":"A Disney employee, Matthew Van Andel, reportedly downloaded AI-powered malware allegedly developed by the cybercriminal group NullBulge, resulting in a major cybersecurity breach. Hackers purportedly accessed Disney's Slack system, exposing 44 million internal messages, employee and customer data, and financial records. NullBulge also reportedly leaked Van Andel’s personal financial information, leading to identity theft and his eventual termination.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Nullbulge"],"developers":["Nullbulge"],"harmed":["Matthew Van Andel, Disney Employees, Disney"],"report_count":2},{"incident_id":757,"occurred_on":"2024-07-01","title":"OpenAI's ChatGPT Mac App Stored User Data in Unencrypted Text Files","description":"OpenAI's ChatGPT macOS app stored user conversations in plain text. If accessed by a malicious actor, these conversations could have been easily read. The critical security flaw was demonstrated by a third party and ultimately resolved after OpenAI released an update to encrypt the stored data.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Openai"],"developers":["Openai"],"harmed":["Chatgpt"],"report_count":1},{"incident_id":842,"occurred_on":"2024-05-24","title":"Reportedly Hacked AI-Powered Robot Vacuums Allegedly Used for Surveillance and Harassment","description":"Hackers reportedly exploited a vulnerability in Ecovacs’s Deebot X2 robot vacuums, gaining unauthorized access to camera and microphone controls. Users reported privacy invasions and offensive language broadcasted through the devices. Although Ecovacs claimed to have resolved the security flaw, researchers suggest vulnerabilities remain that could potentially leave users exposed to surveillance and harassment through their AI-enabled devices.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Ecovacs Deebot X2, Ecovacs"],"developers":["Ecovacs"],"harmed":["Ecovacs Deebot X2 Users, Ecovacs Customers, Daniel Swenson, Privacy"],"report_count":16},{"incident_id":552,"occurred_on":"2023-06-22","title":"Bing Chat Solved CAPTCHAs with Image Analysis Feature Despite Safeguards","description":"Microsoft was reported by a Twitter user for deploying image analysis feature capable of solving CAPTCHAs for its GPT-based chatbot despite it being safeguarded against solving them for users.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft"],"developers":["Openai, Microsoft"],"harmed":["Microsoft"],"report_count":1},{"incident_id":523,"occurred_on":"2023-03-15","title":"Australian Journalist Able to Access Centrelink Account Using AI Audio of Own Voice","description":"A Guardian journalist was able to verify their identity and gain access to their own Centrelink self-service account using AI-generated audio of their own voice along with their customer reference number, shortly after voiceprint was deployed for ID verification.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Australian Taxation Office, Services Australia"],"developers":["Centrelink"],"harmed":["Centrelink Account Holders"],"report_count":1},{"incident_id":473,"occurred_on":"2023-02-08","title":"Bing Chat's Initial Prompts Revealed by Early Testers Through Prompt Injection","description":"Early testers of Bing Chat successfully used prompt injection to reveal its built-in initial instructions, which contains a list of statements governing ChatGPT's interaction with users.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Microsoft"],"developers":["Microsoft, Openai"],"harmed":["Microsoft"],"report_count":1},{"incident_id":352,"occurred_on":"2022-09-15","title":"GPT-3-Based Twitter Bot Hijacked Using Prompt Injection Attacks","description":"Remoteli.io's GPT-3-based Twitter bot was shown being hijacked by Twitter users who redirected it to repeat or generate any phrases.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"Human","intent":"Intentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Stephan De Vries"],"developers":["Openai, Stephan De Vries"],"harmed":["Stephan De Vries"],"report_count":4},{"incident_id":372,"occurred_on":"2022-07-22","title":"Users Reported Security Issues with Google Pixel 6a's Fingerprint Unlocking","description":"Google Pixel 6a's fingerprint recognition feature was reported by users for security issues, in which phones were mistakenly unlocked by unregistered fingerprints.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Google"],"developers":["Google"],"harmed":["Google Pixel 6A Users"],"report_count":3},{"incident_id":223,"occurred_on":"2019-10-09","title":"Hive Box Facial-Recognition Locks Hacked by Fourth Graders Using Intended Recipient’s Facial Photo","description":"Facial-recognition locks by Hive Box, an express delivery locker company in China, were easily opened by a group of fourth-graders in a science-club demo using only a printed photo of the intended recipient’s face, leaving contents vulnerable to theft.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Hive Box"],"developers":["Hive Box"],"harmed":["Hive Box Customers"],"report_count":1},{"incident_id":32,"occurred_on":"2017-09-13","title":"Identical Twins Can Open Apple FaceID Protected Devices","description":"Apple's iPhone FaceID can be opened by an identical twin of the person who has registered their face to unlock the phone.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":"none","sectors":["information and communication"],"countries":["US"],"deployers":["Apple"],"developers":["Apple"],"harmed":["People With Twins"],"report_count":21},{"incident_id":26,"occurred_on":"2017-09-13","title":"Hackers Break Apple Face ID","description":"Vietnamese security firm Bkav created an improved mask to bypass Apple's Face ID","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":"none","sectors":["information and communication"],"countries":["VN"],"deployers":["Apple"],"developers":["Apple"],"harmed":["Apple, Device Owners"],"report_count":24},{"incident_id":428,"occurred_on":"2017-05-19","title":"BBC Reporter's Twin Brother Cracked HSBC's Voice ID Authentication","description":"HSBC’s voice recognition authentication system was fooled after seven repeated attempts  by a BBC reporter's twin brother who mimicked his voice to access his bank account.","mit_domain":"Privacy & Security","mit_subdomain":"AI system security vulnerabilities and attacks","entity":"AI","intent":"Unintentional","timing":"Post-deployment","harm_level":null,"sectors":[],"countries":[],"deployers":["Hsbc Uk"],"developers":["Nuance Communications"],"harmed":["Hsbc Uk Customers, Dan Simmons"],"report_count":3}]}