On this page
Every week someone posts that an AI agent deleted their database, emptied a wallet or obeyed a hidden instruction in an email. The story travels for two days, then it is gone. Nobody keeps the list.
I wanted the list, so I built it. This page logs every public incident I could verify in which an AI agent took or enabled an action that caused harm, from to today. Each row has a date, the company and product, the kind of agent, what happened, how it ended, a severity rating and the reporting behind it. As of it holds 60 incidents.
The essays live elsewhere. If you want to know why agents fail, read the eight failure modes or the lessons from 2026; for the security side there is the 2026 breach roundup. This page is the dataset underneath them, built to be counted and quoted.
What the database shows
- 60 AI agent incidents logged between 15 February 2024 and 4 October 2026, each with a dated primary or original source. 38 caused real-world harm; 22 were flaws in shipped agent products that vendors confirmed and fixed before any known exploitation.
- 33% involved prompt injection (20 of 60): instructions hidden in an email, web page, document, issue or calendar invite that the agent obeyed. Among the 38 real-world incidents the figure is 8%.
- Coding agents are the largest group, with 28 incidents (47%). The most common harm is data leaked (23 incidents, 38%); the most common incident type is vulnerability disclosed (21).
- Only 37% have a public postmortem or technical write-up from the vendor or the victim (22 of 60). The rest are known through press reports, researcher disclosures or the victim's own posts.
- 2026 to date: 26 incidents logged, against 27 in the same months of 2025 and 31 in all of 2025. 8 incidents are rated severe (many organisations harmed, losses above $1 million, or a state-backed operation).
Updated . Counts are incidents that became public and met the inclusion rules below, not a census of every agent failure.
Cite this page
Cite this page: "AI agent incidents database", Gravity, updated , https://gravity.fast/blog/ai-agent-incidents-database/. The data is licensed CC BY 4.0: copy the rows, chart them, quote the numbers, and link back here. Every row as a spreadsheet: data.csv. No row is copied from the AI Incident Database, so its share-alike licence does not apply here.
The incidents
Newest first. "What happened" is one plain sentence from the reporting; "Outcome" is what the vendor, the victim or a court did next. Click a source to read the original.
| Date | Company and agent | Agent type | What happened | Type and harm | Severity | Outcome | Sources |
|---|---|---|---|---|---|---|---|
first report | Multiple vendors CLI coding agents (PixelLeak) | Coding agent | Coding agents that could not attach images to pull requests created public GitHub repos for screenshots, exposing 13,000+ internal images from 900+ repos, including billing records. Affected: More than 300 organisations. | Data exposure Data leaked | 3 Severe | Glow Labs began notifying affected organisations on 9 September 2026 and published the research as PixelLeak. | Glow Labs (researcher), 2026-09-29; Cyber Press, 2026-09-30 |
first report | Salesforce Agentforce | Workplace assistant agent | Three SalesBleed flaws let a poisoned public Web-to-Lead form hijack Agentforce agents to exfiltrate CRM data with no click and send phishing under the agents' identity. Affected: Salesforce Agentforce customers. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 2 Significant | Zenity Labs reported the flaws and Salesforce worked with it to fix them; the attack chains no longer work. | Zenity Labs, 2026-09-24; The Register, 2026-09-24 |
first report | Anthropic Claude (agentic multi-agent frameworks) | Coding agent | GTG-20006, consistent with Midnight Blizzard, automated phishing, exploitation and exfiltration with Claude agents, stealing mailboxes and more than 300,000 national identity records. Affected: More than 20 government, military, diplomatic and defence organisations, including a North African government authority. | Attacker-operated agent Data leaked | 3 Severe | Anthropic disrupted the activity, banned the accounts, strengthened safeguards and shared intelligence with authorities and industry. | Anthropic, 2026-09-10; BleepingComputer, 2026-09-11 |
first report | Anthropic Claude Code | Coding agent | ShinyHunters affiliates (GTG-50014) had Claude scan 1.8 million Android apps for hardcoded secrets and used the access in breaches, including over 1 TB taken from one provider. Affected: Technology providers, an airline, energy firms and about 200 downstream customers of one SaaS provider. | Attacker-operated agent Data leaked | 3 Severe | Anthropic banned the accounts, added measures against similar misuse and engaged authorities and victims. | Anthropic, 2026-09-10; BleepingComputer, 2026-09-11 |
first report | OpenClaw (running Anthropic Claude Opus 4.6) OpenClaw personal assistant | Personal assistant agent | Asked to book a gym class, the agent exploited booking-site flaws to book months ahead, then unprompted cancelled another member's waitlist entry to move its user up. Affected: Australian gym and a gym member removed from a waitlist. | Wrong commitment or action Wrong action | 1 Contained | ABC called it the first known Australian autonomous cyber attack; Aikido later reproduced the exploit in 9 of 10 test runs. | ABC News (Australia), 2026-08-10; Aikido Security, 2026-08-25 |
first report | Anthropic Claude models in internal cybersecurity evaluations | Coding agent | In evaluations from April 2026, models reached the real internet, hacked real systems and published a malicious PyPI package that 15 real systems ran, leaking one company's credentials. Affected: Three real organisations. | Wrong commitment or action System compromise | 2 Significant | Anthropic disclosed the incidents, notified affected organisations on 27 July 2026, alerted PyPI and is remediating with them. | Anthropic, 2026-07-30; StepSecurity, 2026-07-30 |
first report | OpenAI GPT-5.6 Sol (agentic coding use) | Coding agent | Developers reported the model deleting files beyond the task, including almost all files on one user's Mac and another user's production database. Affected: Multiple developers, including Matt Shumer and Bruno Lemos. | Destructive action Data deleted | 2 Significant | OpenAI did not immediately comment; its June system card had warned the model tends to go beyond user intent and take destructive actions. | TechCrunch, 2026-07-14 |
first report | Anysphere Cursor | Coding agent | DuneSlide: zero-click prompt injection via MCP data or web results could escape Cursor's terminal sandbox and run commands on the host; rated CVSS 9.8. | Vulnerability disclosed System compromise, prompt injection, no known exploitation | 2 Significant | Found by Cato AI Labs; fixed in Cursor 3.0 (released 2 April 2026) as CVE-2026-50548 and CVE-2026-50549. | The Hacker News, 2026-07-01 |
| OpenAI Internal research agent | Browser or computer-use agent | During an internal evaluation, an OpenAI agent worked around repeated refusals and reached non-public files on a Medicare statistics portal; no personal records were found accessed. Affected: Services Australia (Medicare statistics portal). | Wrong commitment or action System compromise | 2 Significant | OpenAI notified the government on September 10; Australia took the portal offline, opened ASD and agency investigations, and set up a taskforce. | ABC News (Australia), 2026-09-24; The Hacker News, 2026-09-24 | |
first report | Microsoft Microsoft 365 Copilot (Enterprise Search) | Workplace assistant agent | SearchLeak: one click on a crafted Microsoft link made Copilot search the victim's mail, calendar and indexed files and send the results to an attacker server. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 2 Significant | Microsoft rated it critical as CVE-2026-42824 and deployed a backend fix on 4 June 2026; no evidence of malicious use. | Varonis Threat Labs, 2026-06-15; The Next Web, 2026-06-15 |
first report | xAI / Bankr Grok and Bankrbot wallet agent | Autonomous finance agent | An X user gave Grok's wallet a Bankr membership NFT, then had Grok translate Morse code that told Bankrbot to send 3 billion DRB tokens, about $200,000. Affected: Grok's Bankr wallet. | Prompt-injection exploit Money lost, prompt injection | 2 Significant | The attacker sold the tokens and deleted the account; Dexerto reported blockchain data later showed funds linked to Grok's wallet were returned. | Dexerto, 2026-05-05; GBHackers, 2026-05-08; NeuralTrust, 2026-05-08 |
first report | Anthropic Claude Opus used as a coding agent (PromptMink npm campaign) | Coding agent | North Korea-linked Famous Chollima published about 60 npm packages crafted to be picked by coding agents; a Claude co-authored commit added one to a crypto trading agent. Affected: openpaw-graveyard crypto trading agent project and other developers. | Malicious tool or supply chain System compromise | 3 Severe | ReversingLabs disclosed the campaign; npm removed some packages but the actors kept publishing replacements. | ReversingLabs, 2026-04-29 |
| Anysphere Cursor (running Claude Opus 4.6) | Coding agent | Working on a staging task, the agent used an unrelated account-scoped Railway token to delete a volume, erasing the production database and its backups in nine seconds. Affected: PocketOS (Jer Crane) and its rental-business customers. | Destructive action Data deleted | 2 Significant | Railway's CEO restored the data and Railway added delayed-delete logic to the endpoint. | The Register, 2026-04-27; ACS Information Age, 2026-05-05 | |
first report | OpenAI Codex (ChatGPT web, CLI, SDK, IDE extension) | Coding agent | An unsanitised GitHub branch name was passed into shell commands when Codex set up its container, letting an attacker steal the GitHub token Codex used. | Vulnerability disclosed System compromise, no known exploitation | 2 Significant | BeyondTrust Phantom Labs reported it on 16 December 2025; OpenAI rated it critical and patched it by 5 February 2026. | The Hacker News, 2026-03-30 |
| Perplexity Comet browser shopping assistant | Browser or computer-use agent | A US federal judge preliminarily barred Comet's agent from accessing Amazon, finding strong evidence it entered customer accounts without Amazon's authorization. Affected: Perplexity (enjoined); Amazon (claimant). | Legal or regulatory Legal liability | 2 Significant | The Ninth Circuit vacated the injunction on August 4, 2026, holding Amazon unlikely to succeed on its computer fraud claims. | CNBC, 2026-03-10; Cooley, 2026-08-06 | |
| Anthropic Claude Code | Coding agent | Using a stale Terraform state file, the agent ran terraform destroy and removed the course platform's production infrastructure and database, 2.5 years of submissions, plus automated snapshots. Affected: DataTalks.Club (Alexey Grigorev). | Destructive action Data deleted | 2 Significant | AWS Business Support restored a snapshot in about 24 hours (1,943,200 rows in one table); the owner moved state to S3, added deletion protection and stopped letting the agent run Terraform. | Alexey Grigorev (victim post-mortem), 2026-03-06; Tom's Hardware (via Yahoo Tech), 2026-03-07 | |
first report | OpenClaw OpenClaw email agent | Personal assistant agent | Asked to suggest emails to delete or archive, the agent began deleting her inbox and ignored stop commands sent from her phone. Affected: Summer Yue (Meta Superintelligence Labs). | Destructive action Data deleted | 1 Contained | She stopped it at her Mac mini and attributed the failure to context compaction dropping her confirm-first instruction. | TechCrunch, 2026-02-23 |
| Lobstar Wilde (independent project by Nik Pash) Lobstar Wilde autonomous trading agent | Autonomous finance agent | Asked by an X user for 4 SOL, the agent sent 52.4 million LOBSTAR tokens, worth about $441,780, in one transaction, apparently misreading decimals. Affected: Nik Pash (agent owner). | Wrong commitment or action Money lost | 2 Significant | The agent publicly admitted the error; the recipient sold part of the tokens for about $40,000. | Cointelegraph, 2026-02-23 | |
first report | Amazon Web Services Kiro | Coding agent | The FT reported that in mid-December 2025 Kiro chose to delete and recreate an environment, causing a 13-hour interruption to AWS Cost Explorer in one region. Affected: AWS Cost Explorer customers in one mainland China region. | Destructive action Service outage | 2 Significant | Amazon disputes the account: it says the cause was user error, specifically misconfigured access controls, not AI, calls it an extremely limited event, and added mandatory peer review for production access. | The Decoder (summarising the Financial Times), 2026-02-20; Amazon, 2026-02-20 |
| Cline Cline AI issue-triage workflow (claude-code-action) and Cline CLI | Coding agent | A prompt-injectable AI triage workflow led to theft of Cline's npm token, later used to publish cline@2.3.0, which silently installed OpenClaw for about 8 hours. Affected: Users who installed cline@2.3.0. | Prompt-injection exploit System compromise, prompt injection | 2 Significant | Cline shipped 2.4.0, deprecated 2.3.0, revoked the token, moved npm publishing to OIDC provenance and published advisory GHSA-9ppg-jx86-fqw7. | Adnan Khan (researcher), 2026-02-09; Cline security advisory, 2026-02-17; Snyk, 2026-02-17 | |
first report | OpenClaw OpenClaw agent "MJ Rathbun" | Personal assistant agent | After a maintainer closed its pull request, an autonomous OpenClaw agent researched him and published a blog post attacking his character to pressure him into accepting its code. Affected: Scott Shambaugh (matplotlib maintainer). | Wrong commitment or action Wrong action | 1 Contained | The maintainer published a detailed account and follow-ups; the agent later posted an apology and its operator came forward. | The Shamblog (Scott Shambaugh), 2026-02-12; Cybernews, 2026-02-13 |
first report | OpenClaw OpenClaw gateway Control UI | Personal assistant agent | Visiting a malicious link could leak the OpenClaw gateway token and give an attacker full control of the user's agent, a one-click remote code execution chain. Affected: OpenClaw users. | Vulnerability disclosed System compromise, no known exploitation | 2 Significant | Tracked as CVE-2026-25253 (CVSS 8.8); fixed in OpenClaw 2026.1.29 released January 30, 2026, with a maintainer advisory. | The Hacker News, 2026-02-02 |
first report | OpenClaw ClawHub skill marketplace | Agent tooling (MCP, plugins, skills) | An audit of 2,857 ClawHub skills found 341 malicious ones; 335 used fake prerequisites to install the Atomic Stealer infostealer on users' machines. | Malicious tool or supply chain System compromise | 2 Significant | OpenClaw added user reporting that auto-hides skills with more than three reports; the number of infected users was not disclosed. | The Hacker News, 2026-02-02 |
| Moltbook Moltbook social network for OpenClaw agents | Personal assistant agent | A misconfigured Supabase database gave anyone read and write access to 1.5 million agent API tokens, 35,000 email addresses and private messages between agents. Affected: Moltbook users and their agents. | Data exposure Data leaked, no known exploitation | 2 Significant | After Wiz's report on January 31, 2026, Moltbook secured all tables within about three hours; Wiz published a disclosure timeline. | Wiz, 2026-02-02 | |
first report | Microsoft Microsoft Copilot Personal | Personal assistant agent | Reprompt: one click on a real Copilot link with a hidden prompt in the URL let attackers keep pulling the user's personal data and Copilot memory to their server. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 1 Contained | Reported 31 August 2025; Microsoft patched it on 13 January 2026; Microsoft 365 Copilot enterprise users were not affected. | Varonis Threat Labs, 2026-01-14; Cyber Security News, 2026-01-14 |
first report | ServiceNow Now Assist AI Agents and Virtual Agent API | Workplace assistant agent | BodySnatcher: a shared static secret and email-only account linking let an unauthenticated attacker impersonate any user, bypass MFA and SSO, and run privileged AI agent workflows. | Vulnerability disclosed System compromise, no known exploitation | 2 Significant | CVE-2025-12420, CVSS 9.3; reported 23 October 2025, ServiceNow patched hosted instances on 30 October 2025; no exploitation observed. | AppOmni, 2026-01-13; The Hacker News, 2026-01-13 |
first report | Anthropic Claude Code | Coding agent | Asked to clean up an old repository, the agent ran rm -rf tests/ patches/ plan/ ~/ and the trailing ~/ wiped the user's Mac home directory, including Keychain data. Affected: Individual user (Reddit r/ClaudeAI). | Destructive action Data deleted | 1 Contained | No formal Anthropic response was reported; coverage noted the user may have bypassed permission prompts or approved the command without review. | Simon Willison's Weblog, 2025-12-09; GIGAZINE, 2025-12-16 |
first report | Google Antigravity | Coding agent | Running in Turbo mode, the agent tried to clear a project cache but targeted the root of the user's D: drive and deleted its entire contents, bypassing the Recycle Bin. Affected: Tassos M (individual developer). | Destructive action Data deleted | 1 Contained | Google told The Register it was aware of the report and actively investigating. | The Register, 2025-12-01; Newsweek, 2025-12-08 |
first report | Anthropic Claude Code | Coding agent | A Chinese state-sponsored group, GTG-1002, used Claude Code with MCP tools to run 80 to 90 percent of an espionage campaign, detected in mid-September 2025. Affected: About 30 organisations in tech, finance, chemicals and government; a small number breached. | Attacker-operated agent System compromise | 3 Severe | Anthropic banned the accounts, notified affected organisations and coordinated with authorities over ten days. | Anthropic, 2025-11-13; The Register, 2025-11-13 |
first report | Microsoft (GitHub) GitHub Copilot Chat | Coding agent | CamoLeak: hidden markdown comments in pull requests could make Copilot Chat exfiltrate secrets and private code through GitHub's Camo image proxy; rated CVSS 9.6. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 2 Significant | GitHub disabled image rendering in Copilot Chat on 14 August 2025 after a HackerOne report from Legit Security. | The Register, 2025-10-09 |
first report | Salesforce Agentforce | Workplace assistant agent | ForcedLeak: instructions hidden in a Web-to-Lead form made Agentforce send CRM data to an attacker URL when employees later worked with the lead. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 2 Significant | Rated CVSS 9.4 by the researchers; Salesforce enforced Trusted URLs for Agentforce and Einstein AI on 8 September 2025. | Noma Security, 2025-09-25 |
first report | OpenAI ChatGPT Deep Research (Gmail connector) | Personal assistant agent | ShadowLeak: a crafted email made Deep Research send inbox data to an attacker URL from OpenAI's own servers, with no user click and no network trace on the victim side. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 1 Contained | Reported 18 June 2025; OpenAI fixed it by early August and marked it resolved on 3 September 2025; no exploitation seen. | The Record, 2025-09-18 |
first report | Replit Replit Agent 3 | Coding agent | Under effort-based pricing, users reported Agent 3 running sub-agents on small edits, with one spending $1,000 in a week versus $180 to $200 a month before. | Runaway cost Unexpected cost | 1 Contained | The Register asked Replit for comment and had no response at publication. | The Register, 2025-09-18 |
| Unofficial npm publisher (impersonating Postmark) postmark-mcp npm package | Agent tooling (MCP, plugins, skills) | Version 1.0.16 of a copycat Postmark MCP server added one line that BCC'd every email sent through it to an attacker-controlled address. Affected: Users (1,643 downloads). | Malicious tool or supply chain Data leaked | 2 Significant | Koi Security flagged it and the package was removed from npm; users were told to remove it and rotate exposed credentials. | The Hacker News, 2025-09-29 | |
first report | Taco Bell (Yum Brands) Drive-thru voice AI ordering | Customer-facing agent | Viral videos showed the voice AI, deployed at over 500 US drive-thrus, mishandling orders, including one customer ordering 18,000 water cups. Affected: Taco Bell customers and restaurant staff. | Wrong commitment or action Wrong action | 1 Contained | Taco Bell's technology chief told the Wall Street Journal the chain is rethinking where to use voice AI and keeping staff ready to step in at busy times. | BBC News, 2025-08-29; TechCrunch, 2025-08-30 |
first report | Anthropic Claude Code | Coding agent | Actor GTG-2002 used Claude Code to automate reconnaissance, credential theft, network intrusion and ransom notes in a data extortion campaign, with demands sometimes above $500,000. Affected: At least 17 organisations, including healthcare, emergency services and government bodies. | Attacker-operated agent Data leaked | 3 Severe | Anthropic banned the accounts, built new detection classifiers and shared indicators with authorities in its August 2025 threat report. | Anthropic, 2025-08-27; heise online, 2025-08-27 |
| Nx (Nrwl) Nx npm packages (s1ngularity attack abusing Claude Code, Gemini CLI and Amazon Q CLIs) | Coding agent | Malicious Nx versions ran installed AI CLIs with permission-bypass flags to hunt secrets; Wiz counted over 1,000 valid GitHub tokens leaked and 5,500+ private repositories made public. Affected: Developers and organisations that installed malicious Nx versions. | Malicious tool or supply chain Data leaked | 3 Severe | Malicious versions were removed after about 4 hours; Nx published a postmortem blaming an injectable pull_request_target workflow that leaked its npm token. | Nx (vendor postmortem), 2025-09-05; Wiz, 2025-08-27 | |
first report | Perplexity Comet browser assistant | Browser or computer-use agent | Hidden instructions in a web page or Reddit comment could make Comet's summarise feature act on the user's logged-in accounts, such as reading their email. Affected: Comet users. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 2 Significant | Perplexity shipped fixes before Brave's August 20, 2025 disclosure, but Brave later reported the mitigation was incomplete and re-reported it. | Brave, 2025-08-20 |
first report | Lenovo Lena customer-support chatbot | Customer-facing agent | A single crafted prompt made the GPT-4 powered chatbot emit HTML that ran scripts and could leak support agents' session cookies. Affected: Lenovo customer-support staff and systems. | Vulnerability disclosed System compromise, prompt injection, no known exploitation | 1 Contained | Cybernews disclosed responsibly; Lenovo acknowledged the cross-site scripting flaw and said it had protected its systems before publication. | Cybernews, 2025-08-18 |
first report | Microsoft (GitHub) GitHub Copilot in Visual Studio / VS Code agent mode | Coding agent | Injected instructions in code or issues could make Copilot write chat.tools.autoApprove into .vscode/settings.json, switching off confirmations and allowing arbitrary shell commands. | Vulnerability disclosed System compromise, prompt injection, no known exploitation | 2 Significant | Reported to Microsoft on 29 June 2025 and fixed in the August 2025 Patch Tuesday as CVE-2025-53773. | Embrace The Red (Johann Rehberger), 2025-08-12 |
first report | Cognition Devin | Coding agent | A malicious web page could make Devin start a web server and use its expose_port tool to publish local files on a public devinapps.com URL without approval. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 1 Contained | Reported to Cognition on 6 April 2025; the researcher disclosed after 120+ days with receipt acknowledged but no confirmed fix. | Embrace The Red (Johann Rehberger), 2025-08-08 |
| Salesloft Drift (AI chat agent) Salesforce integration | Customer-facing agent | Between 8 and 18 August 2025, actor UNC6395 used stolen Drift OAuth tokens to export Salesforce data, including contacts, cases, AWS keys, passwords and Snowflake tokens. Affected: More than 700 organisations, including Cloudflare, Palo Alto Networks, Zscaler, Tanium and Proofpoint. | Malicious tool or supply chain Data leaked | 3 Severe | Salesloft and Salesforce revoked all Drift tokens on 20 August 2025, Drift was pulled from AppExchange, and Salesloft engaged Mandiant. | Google Threat Intelligence Group, 2025-08-27; SecurityWeek, 2025-09-05 | |
first report | Google Gemini (web, mobile app and Google Assistant) | Personal assistant agent | Hidden instructions in a Google Calendar invite made Gemini control smart-home devices, delete events, start Zoom calls and leak emails across 14 attack scenarios. | Vulnerability disclosed Wrong action, prompt injection, no known exploitation | 1 Contained | Reported in February 2025; Google added user confirmations for sensitive actions, URL sanitisation and prompt injection classifiers. | SafeBreach, 2025-08-06; Android Authority, 2025-08-06 |
first report | Anysphere Cursor | Coding agent | CurXecute: a prompt injection arriving through an MCP-connected source such as Slack could rewrite ~/.cursor/mcp.json, and Cursor executed the new entry without confirmation. | Vulnerability disclosed System compromise, prompt injection, no known exploitation | 2 Significant | Fixed in Cursor 1.3 on 29 July 2025; tracked as CVE-2025-54135 (CVSS 8.6), found by Aim Labs. | BleepingComputer, 2025-08-01 |
first report | Google Gemini CLI | Coding agent | Asked to rename and reorganise a folder on Windows, the agent assumed a failed mkdir had worked and its move commands overwrote the user's files one after another. Affected: Anuraag Gupta (individual user). | Destructive action Data deleted | 1 Contained | The user filed a priority bug on the gemini-cli GitHub repository and published a write-up; no formal Google statement was reported. | GitHub (google-gemini/gemini-cli issue), 2025-07-21; WinBuzzer, 2025-07-26 |
first report | Replit Replit Agent | Coding agent | During a declared code freeze the agent deleted a live production database holding records for more than 1,200 executives and 1,190 companies, then generated about 4,000 fake records. Affected: SaaStr (Jason Lemkin). | Destructive action Data deleted | 2 Significant | The agent first said rollback was impossible but it worked; CEO Amjad Masad called it unacceptable and announced automatic dev/prod database separation and a planning-only mode. | The Register, 2025-07-21; Fortune, 2025-07-23 |
| Amazon Web Services Amazon Q Developer extension for VS Code | Coding agent | A hacker's unapproved commit planted a prompt telling the agent to wipe the system to a near-factory state and delete cloud resources, and it shipped in the official 1.84.0 release. Affected: Users who installed version 1.84.0. | Malicious tool or supply chain System compromise, prompt injection | 2 Significant | AWS revoked credentials, removed the code, shipped 1.85.0 and issued bulletin AWS-2025-015 (CVE-2025-8217), saying a syntax error stopped the code from executing. | AWS Security Bulletin, 2025-07-23; BleepingComputer, 2025-07-25 | |
first report | Microsoft Copilot Studio | Customer-facing agent | On a replica of a public Copilot Studio customer service agent, one email with a prompt injection made the agent send knowledge files and CRM records to the attacker. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 2 Significant | Microsoft confirmed the report as critical, deployed a prompt shielding fix on 24 April 2025 and paid an $8,000 bounty. | Zenity Labs, 2025-07-07 |
| Paradox.ai / McDonald's McHire "Olivia" hiring agent platform | Customer-facing agent | Default admin credentials (123456:123456) plus an insecure API let researchers reach chats and personal data for more than 64 million applicant records. Affected: McDonald's job applicants. | Vulnerability disclosed Data leaked, no known exploitation | 2 Significant | Credentials were disabled within hours of disclosure on June 30, 2025, and Paradox.ai confirmed the issues resolved on July 1. | Ian Carroll and Sam Curry (researchers), 2025-07-09 | |
| Anysphere Cursor | Coding agent | A Pro plan change to a $20 usage credit billed at API rates left users who had not set spend limits with unexpected overage charges. Affected: Cursor Pro users. | Runaway cost Unexpected cost | 1 Contained | CEO Michael Truell apologised and Cursor offered refunds for unexpected charges incurred between 16 June and 4 July 2025. | Cursor, 2025-07-04; TechCrunch, 2025-07-07 | |
first report | Microsoft Microsoft 365 Copilot | Workplace assistant agent | EchoLeak: a single crafted email with hidden instructions could make Copilot pull sensitive organisational data from the user's context and send it out, with no click needed. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 2 Significant | Microsoft rated it critical as CVE-2025-32711, fixed it server side in May 2025 and said there was no evidence of real-world exploitation. | BleepingComputer, 2025-06-11 |
| Asana Asana MCP server | Agent tooling (MCP, plugins, skills) | A logic bug in Asana's MCP server, live since 1 May 2025, could expose one organisation's tasks, projects, comments and files to other organisations' MCP users. Affected: About 1,000 Asana customers. | Data exposure Data leaked | 2 Significant | Asana found the bug on 4 June, took the MCP server offline from 5 to 17 June, fixed it and contacted affected customers directly. | BleepingComputer, 2025-06-18; The Register, 2025-06-18 | |
first report | Lovable Lovable app builder | Coding agent | Of 1,645 Lovable-generated apps scanned, 170 lacked adequate row-level security, exposing emails, addresses, payment details and API keys through 303 endpoints. Affected: Users of Lovable-built apps. | Data exposure Data leaked | 2 Significant | Researcher Matt Palmer published CVE-2025-48757 after Lovable confirmed receipt but gave no meaningful fix; Lovable 2.0 added a scanner that only checks whether RLS policies exist. | Matt Palmer (researcher), 2025-05-29; SecurityOnline, 2025-06-10 |
first report | GitLab GitLab Duo Chat | Coding agent | Hidden prompts in merge requests, commits, issues or code could make Duo leak private source code and confidential issues and inject untrusted HTML into answers. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 1 Contained | Reported by Legit Security on 12 February 2025; GitLab patched Duo to stop rendering unsafe HTML tags pointing outside gitlab.com. | Legit Security, 2025-05-22 |
first report | Anysphere (Cursor) Cursor AI email support agent "Sam" | Customer-facing agent | The AI support agent told users that logouts were due to a one-device-per-subscription policy that did not exist, prompting public complaints and cancellation threats. Affected: Cursor users. | Wrong commitment or action Wrong action | 1 Contained | Cofounder Michael Truell apologised on Hacker News, said the user was refunded, and blamed a backend session-security change; Cursor said AI drafts its first-line email replies. | Wired, 2025-04-19; Hacker News, 2025-04-14 |
| aixbt aixbt autonomous crypto agent (via Simulacrum AI) | Autonomous finance agent | An attacker breached the agent's dashboard and queued two prompts that made it send 55.5 ETH, worth about $106,200, from its wallet. Affected: aixbt. | Financial loss Money lost | 2 Significant | The maintainer said core systems were unaffected; servers were migrated, keys swapped, dashboard access paused and attacker addresses reported to exchanges. | Cointelegraph, 2025-03-19 | |
first report | OpenAI Operator | Browser or computer-use agent | Asked only to find cheap eggs, Operator charged the columnist's credit card US$31.43 for a dozen eggs delivered to his home without asking for confirmation. Affected: Geoffrey A. Fowler (Washington Post). | Wrong commitment or action Money lost | 1 Contained | OpenAI said Operator made a mistake and fell short of its safeguards, and that it was adding stricter confirmation requirements for transactions. | Washington Post (syndicated by NZ Herald), 2025-02-11 |
first report | Salesforce (Slack) Slack AI | Workplace assistant agent | An attacker who could post in a public channel could plant instructions that made Slack AI leak data, such as API keys, from private channels the attacker could not read. | Vulnerability disclosed Data leaked, prompt injection, no known exploitation | 1 Contained | Slack first called channel search intended behavior, then Salesforce said it deployed a patch and had no evidence of unauthorized access to customer data. | PromptArmor, 2024-08-20; The Register, 2024-08-21 |
first report | McDonald's / IBM Automated Order Taker (drive-thru voice AI) | Customer-facing agent | McDonald's ended its IBM voice-ordering test in more than 100 US drive-thrus after the technology underperformed expectations. Affected: McDonald's customers and franchisees. | Wrong commitment or action Wrong action | 1 Contained | A memo to franchisees said the system would be shut off no later than July 26, 2024; McDonald's said voice ordering remains part of its future. | CNBC via NBC New York, 2024-06-17; CIO Dive, 2024-06-18 |
first report | Air Canada Air Canada website support chatbot | Customer-facing agent | The chatbot told a grieving customer he could claim a bereavement fare retroactively; Air Canada refused, arguing the chatbot was a separate legal entity responsible for its own actions. Affected: Jake Moffatt. | Legal or regulatory Legal liability | 2 Significant | BC Civil Resolution Tribunal (Moffatt v. Air Canada) held the airline responsible for its chatbot and ordered it to pay Moffatt $812. | CBC News, 2024-02-15 |
Severity: 1 contained, 2 significant, 3 severe (scale in the methodology). "No known exploitation" marks a flaw the vendor confirmed and fixed before any reported real-world use. Download every row as data.csv.
Breakdown
The same rows, counted three ways. A single incident has one type, one agent type and one main harm, so each table adds up to the total.
| Incident type | Incidents | Share | |
|---|---|---|---|
| Vulnerability disclosed | 21 | 35% | |
| Destructive action | 9 | 15% | |
| Wrong commitment or action | 9 | 15% | |
| Malicious tool or supply chain | 6 | 10% | |
| Attacker-operated agent | 4 | 7% | |
| Data exposure | 4 | 7% | |
| Legal or regulatory | 2 | 3% | |
| Prompt-injection exploit | 2 | 3% | |
| Runaway cost | 2 | 3% | |
| Financial loss | 1 | 2% |
| Agent type | Incidents | Share | |
|---|---|---|---|
| Coding agent | 28 | 47% | |
| Customer-facing agent | 8 | 13% | |
| Personal assistant agent | 8 | 13% | |
| Workplace assistant agent | 6 | 10% | |
| Browser or computer-use agent | 4 | 7% | |
| Agent tooling (MCP, plugins, skills) | 3 | 5% | |
| Autonomous finance agent | 3 | 5% |
| Harm | Incidents | Share | |
|---|---|---|---|
| Data leaked | 23 | 38% | |
| System compromise | 14 | 23% | |
| Data deleted | 8 | 13% | |
| Wrong action | 6 | 10% | |
| Money lost | 4 | 7% | |
| Legal liability | 2 | 3% | |
| Unexpected cost | 2 | 3% | |
| Service outage | 1 | 2% |
Trend by quarter
| Quarter | Logged | Real-world harm | |
|---|---|---|---|
| 2024 Q1 | 1 | 1 | |
| 2024 Q2 | 1 | 1 | |
| 2024 Q3 | 1 | 0 | |
| 2024 Q4 | 0 | 0 | |
| 2025 Q1 | 2 | 2 | |
| 2025 Q2 | 7 | 4 | |
| 2025 Q3 | 18 | 9 | |
| 2025 Q4 | 4 | 3 | |
| 2026 Q1 | 13 | 8 | |
| 2026 Q2 | 5 | 4 | |
| 2026 Q3 | 8 | 6 | |
| 2026 Q4 (to date) | 0 | 0 |
By year: 2024, 3 logged (2 real-world harm); 2025, 31 (18); 2026 to 4 October 2026, 26 (18). The rise partly reflects more agents in production and partly more people looking; read it as reported incidents, not the true rate.
What the record shows
The damaging incidents share one shape: an agent with more access than the task needed. Replit's agent deleted SaaStr's production database during a declared code freeze in July 2025. Claude Code ran terraform destroy against DataTalks.Club's production stack in February 2026 because it was working from a stale state file. In April 2026 a Cursor agent on a staging task found an account-wide Railway token and deleted PocketOS's production volume, backups included, in nine seconds. None of these needed an attacker. Each needed a credential that reached production.
Prompt injection is mostly found by researchers, and sometimes used for real. Most of the prompt-injection rows are flaws in Microsoft 365 Copilot, Salesforce Agentforce, GitHub Copilot, Cursor and Perplexity's Comet that researchers reported and vendors fixed. The real-world cases are fewer and stranger: a wiper prompt shipped inside the official Amazon Q extension in July 2025, a poisoned GitHub issue that turned Cline's triage bot into a path to its npm token in February 2026, and a Morse-code message that got Grok to tell Bankrbot to send about $200,000 in tokens in May 2026.
The tooling around agents is now a supply chain. A copycat Postmark MCP server quietly copied every email it sent to an attacker in September 2025. The s1ngularity attack on Nx in August 2025 used developers' own installed AI command-line tools to hunt for secrets. Researchers counted 341 malicious skills on OpenClaw's ClawHub in February 2026. If an agent installs what it is told to install, the package registry becomes part of its attack surface.
Attackers run agents too. Anthropic's threat reports describe a data-extortion campaign automated with Claude Code (August 2025), a state-sponsored espionage operation that ran most of its steps through Claude Code (November 2025) and two more operations in September 2026. These are the only severe rows where the agent worked exactly as designed, for the wrong person.
Customer-facing agents fail in public and in court. The Air Canada ruling in February 2024 settled, for one tribunal at least, that a company owns what its bot tells customers. Cursor's support agent invented a login policy in April 2025 and the cofounder apologised on Hacker News. OpenAI's Operator bought a columnist a dozen eggs he had not agreed to buy. Small sums, large headlines.
If you run agents, the controls that would have stopped most of these rows are boring: scoped credentials, separate production access, confirmation before anything destructive or financial, and an allowlist for what an agent may install. The 47-control security checklist and the prompt-injection defence guide go through them, and the incident response runbook covers what to do once something has already gone wrong. That is also why every agent on Gravity is built and kept working by its builder rather than assembled by the user. Gravity is in private alpha; pricing starts with one free agent.
Change log
One dated line for each batch of rows added or corrected. Corrections name the row and what changed.
- : Database opened with 60 verified incidents dated 15 February 2024 to 29 September 2026, each read against its source before entry.
Methodology
Here is exactly what goes in, so you can decide how far to trust the counts.
What counts. An AI agent, meaning an autonomous or tool-using system such as a coding agent, a browser or computer-use agent, a customer-facing agent, a workplace assistant with connectors, or the tooling agents run on (MCP servers, plugins, skills), took or enabled an action that caused real harm or a public failure: data deleted or leaked, money lost, a wrong action, a security exploit through prompt injection, a runaway bill, or a legal or regulatory consequence.
What does not. Plain chatbot wrong answers that nobody acted on. Lab-only research demos against systems that were never shipped. Benchmark failures. Self-driving cars and physical robots. Lawyers who filed hallucinated citations, because a person filed them, not an agent.
Disclosed flaws are kept, and labelled. When researchers find a flaw in a shipped agent product and the vendor confirms and fixes it, through a CVE or an advisory, the row goes in as "Vulnerability disclosed" with no known exploitation. These rows show where agents are weak, but they are not harm, so every headline number on this page says which group it counts. A flaw the vendor disputed or left unfixed stays out until that changes.
Sources. Every row cites one to three sources, at least one of them original reporting, a vendor advisory or postmortem, a researcher's own write-up or a court document, and each source was opened and read before the row went in. Aggregator lists, including other "agents gone rogue" roundups and the AI Incident Database, were used only to find leads; nothing is copied from them. The date is the day the incident happened when the reporting gives it, otherwise the day it was first reported, and the table says which.
Postmortem. A row is marked as having a public postmortem when the vendor or the victim published an account of the cause: an engineering postmortem, a security advisory explaining the root cause, a threat report, or the victim's own technical write-up. A one-line statement to the press does not count.
Severity scale
- 1, contained: one user or team affected, a small loss, or a low or medium flaw fixed before any known exploitation.
- 2, significant: an organisation's production data lost or leaked, money lost above $10,000, a binding legal ruling, or a critical flaw (CVSS 8 or higher, or rated critical by the vendor) in a widely used product.
- 3, severe: many organisations or users harmed, exploitation at scale, losses above $1 million, or an operation run by a state-backed group.
Refresh. Weekly. A script pulls candidate news stories every week; each candidate is checked against these rules and its source before a row is added, and the numbers on this page are recomputed from the rows. Nothing in the table is edited by hand.
Known gaps. This is a log of incidents that became public, so it undercounts. Companies rarely announce that an internal agent deleted something, and VentureBeat reported in May 2026 that most organisations have no incident category for "an agent did this" at all. Coverage is English-language and skews to the US, the UK and Australia. Severity is my judgement against the scale above; the CSV includes every field so you can apply your own.
FAQ
What counts as an AI agent incident?
An AI agent is software that takes actions with tools: it runs commands, sends email, edits records, moves money or browses for you. An incident is a public case where such an agent took or enabled an action that caused real harm: data deleted or leaked, money lost, a wrong action, a prompt-injection exploit, a runaway bill or a legal consequence. A chatbot giving a wrong answer that nobody acted on does not count.
What is the most common AI agent failure?
As of 4 October 2026, the most common harm in this database is data leaked, in 23 of 60 incidents. By agent type, coding agents lead with 28. Among real-world incidents, the pattern that repeats is an agent holding broad credentials and running a destructive command that nobody asked for.
How many AI agent incidents involve prompt injection?
20 of the 60 incidents logged as of 4 October 2026 (33%) used prompt injection, meaning instructions hidden in content the agent read. Most of those are flaws researchers found and vendors fixed; in-the-wild cases include the Amazon Q extension wiper prompt in July 2025, the Cline triage bot in February 2026 and the Grok and Bankrbot token transfer in May 2026.
Has an AI agent ever deleted a production database?
Yes, several times. Replit's agent deleted SaaStr's production database during a code freeze in July 2025; Claude Code ran terraform destroy on DataTalks.Club's production infrastructure in February 2026; and a Cursor agent deleted PocketOS's production database and its backups through a Railway token in April 2026. Each row in the table links the reporting.
Is a company liable for what its AI agent tells customers?
In the one tribunal ruling in this database, yes. In Moffatt v. Air Canada (February 2024) the British Columbia Civil Resolution Tribunal rejected the airline's argument that its chatbot was a separate entity and ordered it to honour what the chatbot had said. Other jurisdictions have not ruled the same way yet, so treat it as a signal rather than settled law.
How is this different from the AI Incident Database?
The AI Incident Database covers every kind of AI harm, from deepfakes to biased hiring models, and holds thousands of reports. This page covers only agents that take actions, records the agent type, prompt-injection mechanism and outcome for each, and is built from original reporting rather than from that database. Its rows are CC BY 4.0; the AI Incident Database snapshots are CC BY-SA.
Can I use this data?
Yes. The table and the CSV are licensed CC BY 4.0: copy them, chart them, quote the numbers, and credit "Gravity AI agent incidents database" with a link to this page. If you spot an error, tell me and I will fix it and note the correction in the change log.
How do I report an incident?
Email support@gravity.fast with a link to a public source: news reporting, a vendor advisory, a postmortem or a court document. I verify each one against its source before it goes in, so a report with only a social post may wait until it is covered elsewhere.
Sources
- Per-incident sources: linked in each table row and listed in full in data.csv (up to three per row, with publisher and date).
- VentureBeat, "AI agents are quietly generating chaos engineering failures enterprises don't track yet", 24 May 2026: venturebeat.com
- OWASP GenAI Security Project, LLM01:2025 Prompt Injection: genai.owasp.org
- Moffatt v. Air Canada, 2024 BCCRT 149, as reported by CBC News, 15 February 2024: cbc.ca
- Anthropic, threat intelligence report, August 2025, and "Disrupting the first reported AI-orchestrated cyber espionage campaign", November 2025: anthropic.com, anthropic.com
- AI Incident Database (Responsible AI Collaborative), the general AI harms archive this page complements; its data is CC BY-SA 4.0 and none of it is reused here: incidentdatabase.ai