AIPolicyTracker

AI incident ·

Threat Actor Reportedly Used LLM Agent to Exfiltrate Internal Database After Compromising marimo Python Notebook

3 news reports Synced from source · record last edited 4 Sep 2026

In brief

An AI system built by Large language model developers and AI agent system developers and deployed by Threat actors, hackers and 3 others allegedly harmed Victims of automated cybercrime, Privacy and 3 others.

Risk domain
Not classified
Occurred
Coverage
3 reportsMay 2026

What happened

An unidentified attacker reportedly used an LLM agent during a May 10 intrusion after exploiting a vulnerable marimo Python notebook. The agent reportedly reused harvested AWS credentials to obtain an SSH key, then pivoted through a bastion host and exfiltrated the schema and contents of an internal PostgreSQL database. Sysdig attributed the post-compromise command stream to real-time agent execution rather than a prebuilt script.

Laws that address this harm

No recorded instrument yet addresses this use case where it happened. See the open queue.

Matched from the record's risk domain and country to the instruments recorded here. A reviewer can correct the match in the repository (data/external/incident_overrides.yaml).

News reports (3)

Titles link to the original publisher; report text is not reproduced here.

Who was involved

Alleged harmed party
Victims of automated cybercrime Privacy Information security Enterprise IT systems Amazon Web Services (AWS) customers

AI systems implicated

marimoLarge language modelsAmazon Web Services (AWS) cloud infrastructureAmazon Web Services (AWS)AI agent systems

Classification (MIT AI Risk Repository taxonomy)

Risk domain
—
Risk subdomain
—
Causal entity
—
Intent
—
Timing
—
Harm level
—
Sectors
—
Countries
—

Other incidents involving Threat actors

Source record: incident #1670 on the AI Incident Database · all 3 reports