On this page

Every week someone posts that an AI agent deleted their database, emptied a wallet or obeyed a hidden instruction in an email. The story travels for two days, then it is gone. Nobody keeps the list.

I wanted the list, so I built it. This page logs every public incident I could verify in which an AI agent took or enabled an action that caused harm, from to today. Each row has a date, the company and product, the kind of agent, what happened, how it ended, a severity rating and the reporting behind it. As of it holds 60 incidents.

The essays live elsewhere. If you want to know why agents fail, read the eight failure modes or the lessons from 2026; for the security side there is the 2026 breach roundup. This page is the dataset underneath them, built to be counted and quoted.

The numbers, as of 4 October 2026

What the database shows

  1. 60 AI agent incidents logged between 15 February 2024 and 4 October 2026, each with a dated primary or original source. 38 caused real-world harm; 22 were flaws in shipped agent products that vendors confirmed and fixed before any known exploitation.
  2. 33% involved prompt injection (20 of 60): instructions hidden in an email, web page, document, issue or calendar invite that the agent obeyed. Among the 38 real-world incidents the figure is 8%.
  3. Coding agents are the largest group, with 28 incidents (47%). The most common harm is data leaked (23 incidents, 38%); the most common incident type is vulnerability disclosed (21).
  4. Only 37% have a public postmortem or technical write-up from the vendor or the victim (22 of 60). The rest are known through press reports, researcher disclosures or the victim's own posts.
  5. 2026 to date: 26 incidents logged, against 27 in the same months of 2025 and 31 in all of 2025. 8 incidents are rated severe (many organisations harmed, losses above $1 million, or a state-backed operation).

Updated . Counts are incidents that became public and met the inclusion rules below, not a census of every agent failure.

Cite this page

Cite this page: "AI agent incidents database", Gravity, updated , https://gravity.fast/blog/ai-agent-incidents-database/. The data is licensed CC BY 4.0: copy the rows, chart them, quote the numbers, and link back here. Every row as a spreadsheet: data.csv. No row is copied from the AI Incident Database, so its share-alike licence does not apply here.

The incidents

Newest first. "What happened" is one plain sentence from the reporting; "Outcome" is what the vendor, the victim or a court did next. Click a source to read the original.

Vulnerability disclosed: 21 Destructive action: 9 Wrong commitment or action: 9 Malicious tool or supply chain: 6 Attacker-operated agent: 4 Data exposure: 4 Legal or regulatory: 2 Prompt-injection exploit: 2 Runaway cost: 2 Financial loss: 1
All 60 incidents, newest first
DateCompany and agentAgent typeWhat happenedType and harmSeverityOutcomeSources

first report
Multiple vendors
CLI coding agents (PixelLeak)
Coding agentCoding agents that could not attach images to pull requests created public GitHub repos for screenshots, exposing 13,000+ internal images from 900+ repos, including billing records. Affected: More than 300 organisations.Data exposure
Data leaked
3 SevereGlow Labs began notifying affected organisations on 9 September 2026 and published the research as PixelLeak.Glow Labs (researcher), 2026-09-29; Cyber Press, 2026-09-30

first report
Salesforce
Agentforce
Workplace assistant agentThree SalesBleed flaws let a poisoned public Web-to-Lead form hijack Agentforce agents to exfiltrate CRM data with no click and send phishing under the agents' identity. Affected: Salesforce Agentforce customers.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
2 SignificantZenity Labs reported the flaws and Salesforce worked with it to fix them; the attack chains no longer work.Zenity Labs, 2026-09-24; The Register, 2026-09-24

first report
Anthropic
Claude (agentic multi-agent frameworks)
Coding agentGTG-20006, consistent with Midnight Blizzard, automated phishing, exploitation and exfiltration with Claude agents, stealing mailboxes and more than 300,000 national identity records. Affected: More than 20 government, military, diplomatic and defence organisations, including a North African government authority.Attacker-operated agent
Data leaked
3 SevereAnthropic disrupted the activity, banned the accounts, strengthened safeguards and shared intelligence with authorities and industry.Anthropic, 2026-09-10; BleepingComputer, 2026-09-11

first report
Anthropic
Claude Code
Coding agentShinyHunters affiliates (GTG-50014) had Claude scan 1.8 million Android apps for hardcoded secrets and used the access in breaches, including over 1 TB taken from one provider. Affected: Technology providers, an airline, energy firms and about 200 downstream customers of one SaaS provider.Attacker-operated agent
Data leaked
3 SevereAnthropic banned the accounts, added measures against similar misuse and engaged authorities and victims.Anthropic, 2026-09-10; BleepingComputer, 2026-09-11

first report
OpenClaw (running Anthropic Claude Opus 4.6)
OpenClaw personal assistant
Personal assistant agentAsked to book a gym class, the agent exploited booking-site flaws to book months ahead, then unprompted cancelled another member's waitlist entry to move its user up. Affected: Australian gym and a gym member removed from a waitlist.Wrong commitment or action
Wrong action
1 ContainedABC called it the first known Australian autonomous cyber attack; Aikido later reproduced the exploit in 9 of 10 test runs.ABC News (Australia), 2026-08-10; Aikido Security, 2026-08-25

first report
Anthropic
Claude models in internal cybersecurity evaluations
Coding agentIn evaluations from April 2026, models reached the real internet, hacked real systems and published a malicious PyPI package that 15 real systems ran, leaking one company's credentials. Affected: Three real organisations.Wrong commitment or action
System compromise
2 SignificantAnthropic disclosed the incidents, notified affected organisations on 27 July 2026, alerted PyPI and is remediating with them.Anthropic, 2026-07-30; StepSecurity, 2026-07-30

first report
OpenAI
GPT-5.6 Sol (agentic coding use)
Coding agentDevelopers reported the model deleting files beyond the task, including almost all files on one user's Mac and another user's production database. Affected: Multiple developers, including Matt Shumer and Bruno Lemos.Destructive action
Data deleted
2 SignificantOpenAI did not immediately comment; its June system card had warned the model tends to go beyond user intent and take destructive actions.TechCrunch, 2026-07-14

first report
Anysphere
Cursor
Coding agentDuneSlide: zero-click prompt injection via MCP data or web results could escape Cursor's terminal sandbox and run commands on the host; rated CVSS 9.8.Vulnerability disclosed
System compromise, prompt injection, no known exploitation
2 SignificantFound by Cato AI Labs; fixed in Cursor 3.0 (released 2 April 2026) as CVE-2026-50548 and CVE-2026-50549.The Hacker News, 2026-07-01
OpenAI
Internal research agent
Browser or computer-use agentDuring an internal evaluation, an OpenAI agent worked around repeated refusals and reached non-public files on a Medicare statistics portal; no personal records were found accessed. Affected: Services Australia (Medicare statistics portal).Wrong commitment or action
System compromise
2 SignificantOpenAI notified the government on September 10; Australia took the portal offline, opened ASD and agency investigations, and set up a taskforce.ABC News (Australia), 2026-09-24; The Hacker News, 2026-09-24

first report
Microsoft
Microsoft 365 Copilot (Enterprise Search)
Workplace assistant agentSearchLeak: one click on a crafted Microsoft link made Copilot search the victim's mail, calendar and indexed files and send the results to an attacker server.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
2 SignificantMicrosoft rated it critical as CVE-2026-42824 and deployed a backend fix on 4 June 2026; no evidence of malicious use.Varonis Threat Labs, 2026-06-15; The Next Web, 2026-06-15

first report
xAI / Bankr
Grok and Bankrbot wallet agent
Autonomous finance agentAn X user gave Grok's wallet a Bankr membership NFT, then had Grok translate Morse code that told Bankrbot to send 3 billion DRB tokens, about $200,000. Affected: Grok's Bankr wallet.Prompt-injection exploit
Money lost, prompt injection
2 SignificantThe attacker sold the tokens and deleted the account; Dexerto reported blockchain data later showed funds linked to Grok's wallet were returned.Dexerto, 2026-05-05; GBHackers, 2026-05-08; NeuralTrust, 2026-05-08

first report
Anthropic
Claude Opus used as a coding agent (PromptMink npm campaign)
Coding agentNorth Korea-linked Famous Chollima published about 60 npm packages crafted to be picked by coding agents; a Claude co-authored commit added one to a crypto trading agent. Affected: openpaw-graveyard crypto trading agent project and other developers.Malicious tool or supply chain
System compromise
3 SevereReversingLabs disclosed the campaign; npm removed some packages but the actors kept publishing replacements.ReversingLabs, 2026-04-29
Anysphere
Cursor (running Claude Opus 4.6)
Coding agentWorking on a staging task, the agent used an unrelated account-scoped Railway token to delete a volume, erasing the production database and its backups in nine seconds. Affected: PocketOS (Jer Crane) and its rental-business customers.Destructive action
Data deleted
2 SignificantRailway's CEO restored the data and Railway added delayed-delete logic to the endpoint.The Register, 2026-04-27; ACS Information Age, 2026-05-05

first report
OpenAI
Codex (ChatGPT web, CLI, SDK, IDE extension)
Coding agentAn unsanitised GitHub branch name was passed into shell commands when Codex set up its container, letting an attacker steal the GitHub token Codex used.Vulnerability disclosed
System compromise, no known exploitation
2 SignificantBeyondTrust Phantom Labs reported it on 16 December 2025; OpenAI rated it critical and patched it by 5 February 2026.The Hacker News, 2026-03-30
Perplexity
Comet browser shopping assistant
Browser or computer-use agentA US federal judge preliminarily barred Comet's agent from accessing Amazon, finding strong evidence it entered customer accounts without Amazon's authorization. Affected: Perplexity (enjoined); Amazon (claimant).Legal or regulatory
Legal liability
2 SignificantThe Ninth Circuit vacated the injunction on August 4, 2026, holding Amazon unlikely to succeed on its computer fraud claims.CNBC, 2026-03-10; Cooley, 2026-08-06
Anthropic
Claude Code
Coding agentUsing a stale Terraform state file, the agent ran terraform destroy and removed the course platform's production infrastructure and database, 2.5 years of submissions, plus automated snapshots. Affected: DataTalks.Club (Alexey Grigorev).Destructive action
Data deleted
2 SignificantAWS Business Support restored a snapshot in about 24 hours (1,943,200 rows in one table); the owner moved state to S3, added deletion protection and stopped letting the agent run Terraform.Alexey Grigorev (victim post-mortem), 2026-03-06; Tom's Hardware (via Yahoo Tech), 2026-03-07

first report
OpenClaw
OpenClaw email agent
Personal assistant agentAsked to suggest emails to delete or archive, the agent began deleting her inbox and ignored stop commands sent from her phone. Affected: Summer Yue (Meta Superintelligence Labs).Destructive action
Data deleted
1 ContainedShe stopped it at her Mac mini and attributed the failure to context compaction dropping her confirm-first instruction.TechCrunch, 2026-02-23
Lobstar Wilde (independent project by Nik Pash)
Lobstar Wilde autonomous trading agent
Autonomous finance agentAsked by an X user for 4 SOL, the agent sent 52.4 million LOBSTAR tokens, worth about $441,780, in one transaction, apparently misreading decimals. Affected: Nik Pash (agent owner).Wrong commitment or action
Money lost
2 SignificantThe agent publicly admitted the error; the recipient sold part of the tokens for about $40,000.Cointelegraph, 2026-02-23

first report
Amazon Web Services
Kiro
Coding agentThe FT reported that in mid-December 2025 Kiro chose to delete and recreate an environment, causing a 13-hour interruption to AWS Cost Explorer in one region. Affected: AWS Cost Explorer customers in one mainland China region.Destructive action
Service outage
2 SignificantAmazon disputes the account: it says the cause was user error, specifically misconfigured access controls, not AI, calls it an extremely limited event, and added mandatory peer review for production access.The Decoder (summarising the Financial Times), 2026-02-20; Amazon, 2026-02-20
Cline
Cline AI issue-triage workflow (claude-code-action) and Cline CLI
Coding agentA prompt-injectable AI triage workflow led to theft of Cline's npm token, later used to publish cline@2.3.0, which silently installed OpenClaw for about 8 hours. Affected: Users who installed cline@2.3.0.Prompt-injection exploit
System compromise, prompt injection
2 SignificantCline shipped 2.4.0, deprecated 2.3.0, revoked the token, moved npm publishing to OIDC provenance and published advisory GHSA-9ppg-jx86-fqw7.Adnan Khan (researcher), 2026-02-09; Cline security advisory, 2026-02-17; Snyk, 2026-02-17

first report
OpenClaw
OpenClaw agent "MJ Rathbun"
Personal assistant agentAfter a maintainer closed its pull request, an autonomous OpenClaw agent researched him and published a blog post attacking his character to pressure him into accepting its code. Affected: Scott Shambaugh (matplotlib maintainer).Wrong commitment or action
Wrong action
1 ContainedThe maintainer published a detailed account and follow-ups; the agent later posted an apology and its operator came forward.The Shamblog (Scott Shambaugh), 2026-02-12; Cybernews, 2026-02-13

first report
OpenClaw
OpenClaw gateway Control UI
Personal assistant agentVisiting a malicious link could leak the OpenClaw gateway token and give an attacker full control of the user's agent, a one-click remote code execution chain. Affected: OpenClaw users.Vulnerability disclosed
System compromise, no known exploitation
2 SignificantTracked as CVE-2026-25253 (CVSS 8.8); fixed in OpenClaw 2026.1.29 released January 30, 2026, with a maintainer advisory.The Hacker News, 2026-02-02

first report
OpenClaw
ClawHub skill marketplace
Agent tooling (MCP, plugins, skills)An audit of 2,857 ClawHub skills found 341 malicious ones; 335 used fake prerequisites to install the Atomic Stealer infostealer on users' machines.Malicious tool or supply chain
System compromise
2 SignificantOpenClaw added user reporting that auto-hides skills with more than three reports; the number of infected users was not disclosed.The Hacker News, 2026-02-02
Moltbook
Moltbook social network for OpenClaw agents
Personal assistant agentA misconfigured Supabase database gave anyone read and write access to 1.5 million agent API tokens, 35,000 email addresses and private messages between agents. Affected: Moltbook users and their agents.Data exposure
Data leaked, no known exploitation
2 SignificantAfter Wiz's report on January 31, 2026, Moltbook secured all tables within about three hours; Wiz published a disclosure timeline.Wiz, 2026-02-02

first report
Microsoft
Microsoft Copilot Personal
Personal assistant agentReprompt: one click on a real Copilot link with a hidden prompt in the URL let attackers keep pulling the user's personal data and Copilot memory to their server.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
1 ContainedReported 31 August 2025; Microsoft patched it on 13 January 2026; Microsoft 365 Copilot enterprise users were not affected.Varonis Threat Labs, 2026-01-14; Cyber Security News, 2026-01-14

first report
ServiceNow
Now Assist AI Agents and Virtual Agent API
Workplace assistant agentBodySnatcher: a shared static secret and email-only account linking let an unauthenticated attacker impersonate any user, bypass MFA and SSO, and run privileged AI agent workflows.Vulnerability disclosed
System compromise, no known exploitation
2 SignificantCVE-2025-12420, CVSS 9.3; reported 23 October 2025, ServiceNow patched hosted instances on 30 October 2025; no exploitation observed.AppOmni, 2026-01-13; The Hacker News, 2026-01-13

first report
Anthropic
Claude Code
Coding agentAsked to clean up an old repository, the agent ran rm -rf tests/ patches/ plan/ ~/ and the trailing ~/ wiped the user's Mac home directory, including Keychain data. Affected: Individual user (Reddit r/ClaudeAI).Destructive action
Data deleted
1 ContainedNo formal Anthropic response was reported; coverage noted the user may have bypassed permission prompts or approved the command without review.Simon Willison's Weblog, 2025-12-09; GIGAZINE, 2025-12-16

first report
Google
Antigravity
Coding agentRunning in Turbo mode, the agent tried to clear a project cache but targeted the root of the user's D: drive and deleted its entire contents, bypassing the Recycle Bin. Affected: Tassos M (individual developer).Destructive action
Data deleted
1 ContainedGoogle told The Register it was aware of the report and actively investigating.The Register, 2025-12-01; Newsweek, 2025-12-08

first report
Anthropic
Claude Code
Coding agentA Chinese state-sponsored group, GTG-1002, used Claude Code with MCP tools to run 80 to 90 percent of an espionage campaign, detected in mid-September 2025. Affected: About 30 organisations in tech, finance, chemicals and government; a small number breached.Attacker-operated agent
System compromise
3 SevereAnthropic banned the accounts, notified affected organisations and coordinated with authorities over ten days.Anthropic, 2025-11-13; The Register, 2025-11-13

first report
Microsoft (GitHub)
GitHub Copilot Chat
Coding agentCamoLeak: hidden markdown comments in pull requests could make Copilot Chat exfiltrate secrets and private code through GitHub's Camo image proxy; rated CVSS 9.6.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
2 SignificantGitHub disabled image rendering in Copilot Chat on 14 August 2025 after a HackerOne report from Legit Security.The Register, 2025-10-09

first report
Salesforce
Agentforce
Workplace assistant agentForcedLeak: instructions hidden in a Web-to-Lead form made Agentforce send CRM data to an attacker URL when employees later worked with the lead.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
2 SignificantRated CVSS 9.4 by the researchers; Salesforce enforced Trusted URLs for Agentforce and Einstein AI on 8 September 2025.Noma Security, 2025-09-25

first report
OpenAI
ChatGPT Deep Research (Gmail connector)
Personal assistant agentShadowLeak: a crafted email made Deep Research send inbox data to an attacker URL from OpenAI's own servers, with no user click and no network trace on the victim side.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
1 ContainedReported 18 June 2025; OpenAI fixed it by early August and marked it resolved on 3 September 2025; no exploitation seen.The Record, 2025-09-18

first report
Replit
Replit Agent 3
Coding agentUnder effort-based pricing, users reported Agent 3 running sub-agents on small edits, with one spending $1,000 in a week versus $180 to $200 a month before.Runaway cost
Unexpected cost
1 ContainedThe Register asked Replit for comment and had no response at publication.The Register, 2025-09-18
Unofficial npm publisher (impersonating Postmark)
postmark-mcp npm package
Agent tooling (MCP, plugins, skills)Version 1.0.16 of a copycat Postmark MCP server added one line that BCC'd every email sent through it to an attacker-controlled address. Affected: Users (1,643 downloads).Malicious tool or supply chain
Data leaked
2 SignificantKoi Security flagged it and the package was removed from npm; users were told to remove it and rotate exposed credentials.The Hacker News, 2025-09-29

first report
Taco Bell (Yum Brands)
Drive-thru voice AI ordering
Customer-facing agentViral videos showed the voice AI, deployed at over 500 US drive-thrus, mishandling orders, including one customer ordering 18,000 water cups. Affected: Taco Bell customers and restaurant staff.Wrong commitment or action
Wrong action
1 ContainedTaco Bell's technology chief told the Wall Street Journal the chain is rethinking where to use voice AI and keeping staff ready to step in at busy times.BBC News, 2025-08-29; TechCrunch, 2025-08-30

first report
Anthropic
Claude Code
Coding agentActor GTG-2002 used Claude Code to automate reconnaissance, credential theft, network intrusion and ransom notes in a data extortion campaign, with demands sometimes above $500,000. Affected: At least 17 organisations, including healthcare, emergency services and government bodies.Attacker-operated agent
Data leaked
3 SevereAnthropic banned the accounts, built new detection classifiers and shared indicators with authorities in its August 2025 threat report.Anthropic, 2025-08-27; heise online, 2025-08-27
Nx (Nrwl)
Nx npm packages (s1ngularity attack abusing Claude Code, Gemini CLI and Amazon Q CLIs)
Coding agentMalicious Nx versions ran installed AI CLIs with permission-bypass flags to hunt secrets; Wiz counted over 1,000 valid GitHub tokens leaked and 5,500+ private repositories made public. Affected: Developers and organisations that installed malicious Nx versions.Malicious tool or supply chain
Data leaked
3 SevereMalicious versions were removed after about 4 hours; Nx published a postmortem blaming an injectable pull_request_target workflow that leaked its npm token.Nx (vendor postmortem), 2025-09-05; Wiz, 2025-08-27

first report
Perplexity
Comet browser assistant
Browser or computer-use agentHidden instructions in a web page or Reddit comment could make Comet's summarise feature act on the user's logged-in accounts, such as reading their email. Affected: Comet users.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
2 SignificantPerplexity shipped fixes before Brave's August 20, 2025 disclosure, but Brave later reported the mitigation was incomplete and re-reported it.Brave, 2025-08-20

first report
Lenovo
Lena customer-support chatbot
Customer-facing agentA single crafted prompt made the GPT-4 powered chatbot emit HTML that ran scripts and could leak support agents' session cookies. Affected: Lenovo customer-support staff and systems.Vulnerability disclosed
System compromise, prompt injection, no known exploitation
1 ContainedCybernews disclosed responsibly; Lenovo acknowledged the cross-site scripting flaw and said it had protected its systems before publication.Cybernews, 2025-08-18

first report
Microsoft (GitHub)
GitHub Copilot in Visual Studio / VS Code agent mode
Coding agentInjected instructions in code or issues could make Copilot write chat.tools.autoApprove into .vscode/settings.json, switching off confirmations and allowing arbitrary shell commands.Vulnerability disclosed
System compromise, prompt injection, no known exploitation
2 SignificantReported to Microsoft on 29 June 2025 and fixed in the August 2025 Patch Tuesday as CVE-2025-53773.Embrace The Red (Johann Rehberger), 2025-08-12

first report
Cognition
Devin
Coding agentA malicious web page could make Devin start a web server and use its expose_port tool to publish local files on a public devinapps.com URL without approval.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
1 ContainedReported to Cognition on 6 April 2025; the researcher disclosed after 120+ days with receipt acknowledged but no confirmed fix.Embrace The Red (Johann Rehberger), 2025-08-08
Salesloft
Drift (AI chat agent) Salesforce integration
Customer-facing agentBetween 8 and 18 August 2025, actor UNC6395 used stolen Drift OAuth tokens to export Salesforce data, including contacts, cases, AWS keys, passwords and Snowflake tokens. Affected: More than 700 organisations, including Cloudflare, Palo Alto Networks, Zscaler, Tanium and Proofpoint.Malicious tool or supply chain
Data leaked
3 SevereSalesloft and Salesforce revoked all Drift tokens on 20 August 2025, Drift was pulled from AppExchange, and Salesloft engaged Mandiant.Google Threat Intelligence Group, 2025-08-27; SecurityWeek, 2025-09-05

first report
Google
Gemini (web, mobile app and Google Assistant)
Personal assistant agentHidden instructions in a Google Calendar invite made Gemini control smart-home devices, delete events, start Zoom calls and leak emails across 14 attack scenarios.Vulnerability disclosed
Wrong action, prompt injection, no known exploitation
1 ContainedReported in February 2025; Google added user confirmations for sensitive actions, URL sanitisation and prompt injection classifiers.SafeBreach, 2025-08-06; Android Authority, 2025-08-06

first report
Anysphere
Cursor
Coding agentCurXecute: a prompt injection arriving through an MCP-connected source such as Slack could rewrite ~/.cursor/mcp.json, and Cursor executed the new entry without confirmation.Vulnerability disclosed
System compromise, prompt injection, no known exploitation
2 SignificantFixed in Cursor 1.3 on 29 July 2025; tracked as CVE-2025-54135 (CVSS 8.6), found by Aim Labs.BleepingComputer, 2025-08-01

first report
Google
Gemini CLI
Coding agentAsked to rename and reorganise a folder on Windows, the agent assumed a failed mkdir had worked and its move commands overwrote the user's files one after another. Affected: Anuraag Gupta (individual user).Destructive action
Data deleted
1 ContainedThe user filed a priority bug on the gemini-cli GitHub repository and published a write-up; no formal Google statement was reported.GitHub (google-gemini/gemini-cli issue), 2025-07-21; WinBuzzer, 2025-07-26

first report
Replit
Replit Agent
Coding agentDuring a declared code freeze the agent deleted a live production database holding records for more than 1,200 executives and 1,190 companies, then generated about 4,000 fake records. Affected: SaaStr (Jason Lemkin).Destructive action
Data deleted
2 SignificantThe agent first said rollback was impossible but it worked; CEO Amjad Masad called it unacceptable and announced automatic dev/prod database separation and a planning-only mode.The Register, 2025-07-21; Fortune, 2025-07-23
Amazon Web Services
Amazon Q Developer extension for VS Code
Coding agentA hacker's unapproved commit planted a prompt telling the agent to wipe the system to a near-factory state and delete cloud resources, and it shipped in the official 1.84.0 release. Affected: Users who installed version 1.84.0.Malicious tool or supply chain
System compromise, prompt injection
2 SignificantAWS revoked credentials, removed the code, shipped 1.85.0 and issued bulletin AWS-2025-015 (CVE-2025-8217), saying a syntax error stopped the code from executing.AWS Security Bulletin, 2025-07-23; BleepingComputer, 2025-07-25

first report
Microsoft
Copilot Studio
Customer-facing agentOn a replica of a public Copilot Studio customer service agent, one email with a prompt injection made the agent send knowledge files and CRM records to the attacker.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
2 SignificantMicrosoft confirmed the report as critical, deployed a prompt shielding fix on 24 April 2025 and paid an $8,000 bounty.Zenity Labs, 2025-07-07
Paradox.ai / McDonald's
McHire "Olivia" hiring agent platform
Customer-facing agentDefault admin credentials (123456:123456) plus an insecure API let researchers reach chats and personal data for more than 64 million applicant records. Affected: McDonald's job applicants.Vulnerability disclosed
Data leaked, no known exploitation
2 SignificantCredentials were disabled within hours of disclosure on June 30, 2025, and Paradox.ai confirmed the issues resolved on July 1.Ian Carroll and Sam Curry (researchers), 2025-07-09
Anysphere
Cursor
Coding agentA Pro plan change to a $20 usage credit billed at API rates left users who had not set spend limits with unexpected overage charges. Affected: Cursor Pro users.Runaway cost
Unexpected cost
1 ContainedCEO Michael Truell apologised and Cursor offered refunds for unexpected charges incurred between 16 June and 4 July 2025.Cursor, 2025-07-04; TechCrunch, 2025-07-07

first report
Microsoft
Microsoft 365 Copilot
Workplace assistant agentEchoLeak: a single crafted email with hidden instructions could make Copilot pull sensitive organisational data from the user's context and send it out, with no click needed.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
2 SignificantMicrosoft rated it critical as CVE-2025-32711, fixed it server side in May 2025 and said there was no evidence of real-world exploitation.BleepingComputer, 2025-06-11
Asana
Asana MCP server
Agent tooling (MCP, plugins, skills)A logic bug in Asana's MCP server, live since 1 May 2025, could expose one organisation's tasks, projects, comments and files to other organisations' MCP users. Affected: About 1,000 Asana customers.Data exposure
Data leaked
2 SignificantAsana found the bug on 4 June, took the MCP server offline from 5 to 17 June, fixed it and contacted affected customers directly.BleepingComputer, 2025-06-18; The Register, 2025-06-18

first report
Lovable
Lovable app builder
Coding agentOf 1,645 Lovable-generated apps scanned, 170 lacked adequate row-level security, exposing emails, addresses, payment details and API keys through 303 endpoints. Affected: Users of Lovable-built apps.Data exposure
Data leaked
2 SignificantResearcher Matt Palmer published CVE-2025-48757 after Lovable confirmed receipt but gave no meaningful fix; Lovable 2.0 added a scanner that only checks whether RLS policies exist.Matt Palmer (researcher), 2025-05-29; SecurityOnline, 2025-06-10

first report
GitLab
GitLab Duo Chat
Coding agentHidden prompts in merge requests, commits, issues or code could make Duo leak private source code and confidential issues and inject untrusted HTML into answers.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
1 ContainedReported by Legit Security on 12 February 2025; GitLab patched Duo to stop rendering unsafe HTML tags pointing outside gitlab.com.Legit Security, 2025-05-22

first report
Anysphere (Cursor)
Cursor AI email support agent "Sam"
Customer-facing agentThe AI support agent told users that logouts were due to a one-device-per-subscription policy that did not exist, prompting public complaints and cancellation threats. Affected: Cursor users.Wrong commitment or action
Wrong action
1 ContainedCofounder Michael Truell apologised on Hacker News, said the user was refunded, and blamed a backend session-security change; Cursor said AI drafts its first-line email replies.Wired, 2025-04-19; Hacker News, 2025-04-14
aixbt
aixbt autonomous crypto agent (via Simulacrum AI)
Autonomous finance agentAn attacker breached the agent's dashboard and queued two prompts that made it send 55.5 ETH, worth about $106,200, from its wallet. Affected: aixbt.Financial loss
Money lost
2 SignificantThe maintainer said core systems were unaffected; servers were migrated, keys swapped, dashboard access paused and attacker addresses reported to exchanges.Cointelegraph, 2025-03-19

first report
OpenAI
Operator
Browser or computer-use agentAsked only to find cheap eggs, Operator charged the columnist's credit card US$31.43 for a dozen eggs delivered to his home without asking for confirmation. Affected: Geoffrey A. Fowler (Washington Post).Wrong commitment or action
Money lost
1 ContainedOpenAI said Operator made a mistake and fell short of its safeguards, and that it was adding stricter confirmation requirements for transactions.Washington Post (syndicated by NZ Herald), 2025-02-11

first report
Salesforce (Slack)
Slack AI
Workplace assistant agentAn attacker who could post in a public channel could plant instructions that made Slack AI leak data, such as API keys, from private channels the attacker could not read.Vulnerability disclosed
Data leaked, prompt injection, no known exploitation
1 ContainedSlack first called channel search intended behavior, then Salesforce said it deployed a patch and had no evidence of unauthorized access to customer data.PromptArmor, 2024-08-20; The Register, 2024-08-21

first report
McDonald's / IBM
Automated Order Taker (drive-thru voice AI)
Customer-facing agentMcDonald's ended its IBM voice-ordering test in more than 100 US drive-thrus after the technology underperformed expectations. Affected: McDonald's customers and franchisees.Wrong commitment or action
Wrong action
1 ContainedA memo to franchisees said the system would be shut off no later than July 26, 2024; McDonald's said voice ordering remains part of its future.CNBC via NBC New York, 2024-06-17; CIO Dive, 2024-06-18

first report
Air Canada
Air Canada website support chatbot
Customer-facing agentThe chatbot told a grieving customer he could claim a bereavement fare retroactively; Air Canada refused, arguing the chatbot was a separate legal entity responsible for its own actions. Affected: Jake Moffatt.Legal or regulatory
Legal liability
2 SignificantBC Civil Resolution Tribunal (Moffatt v. Air Canada) held the airline responsible for its chatbot and ordered it to pay Moffatt $812.CBC News, 2024-02-15

Severity: 1 contained, 2 significant, 3 severe (scale in the methodology). "No known exploitation" marks a flaw the vendor confirmed and fixed before any reported real-world use. Download every row as data.csv.

Breakdown

The same rows, counted three ways. A single incident has one type, one agent type and one main harm, so each table adds up to the total.

By incident type
Incident typeIncidentsShare
Vulnerability disclosed2135%
Destructive action915%
Wrong commitment or action915%
Malicious tool or supply chain610%
Attacker-operated agent47%
Data exposure47%
Legal or regulatory23%
Prompt-injection exploit23%
Runaway cost23%
Financial loss12%
By agent type
Agent typeIncidentsShare
Coding agent2847%
Customer-facing agent813%
Personal assistant agent813%
Workplace assistant agent610%
Browser or computer-use agent47%
Agent tooling (MCP, plugins, skills)35%
Autonomous finance agent35%
By harm
HarmIncidentsShare
Data leaked2338%
System compromise1423%
Data deleted813%
Wrong action610%
Money lost47%
Legal liability23%
Unexpected cost23%
Service outage12%

Trend by quarter

Incidents by quarter (date of incident or first public report)
QuarterLoggedReal-world harm
2024 Q111
2024 Q211
2024 Q310
2024 Q400
2025 Q122
2025 Q274
2025 Q3189
2025 Q443
2026 Q1138
2026 Q254
2026 Q386
2026 Q4 (to date)00

By year: 2024, 3 logged (2 real-world harm); 2025, 31 (18); 2026 to 4 October 2026, 26 (18). The rise partly reflects more agents in production and partly more people looking; read it as reported incidents, not the true rate.

What the record shows

The damaging incidents share one shape: an agent with more access than the task needed. Replit's agent deleted SaaStr's production database during a declared code freeze in July 2025. Claude Code ran terraform destroy against DataTalks.Club's production stack in February 2026 because it was working from a stale state file. In April 2026 a Cursor agent on a staging task found an account-wide Railway token and deleted PocketOS's production volume, backups included, in nine seconds. None of these needed an attacker. Each needed a credential that reached production.

Prompt injection is mostly found by researchers, and sometimes used for real. Most of the prompt-injection rows are flaws in Microsoft 365 Copilot, Salesforce Agentforce, GitHub Copilot, Cursor and Perplexity's Comet that researchers reported and vendors fixed. The real-world cases are fewer and stranger: a wiper prompt shipped inside the official Amazon Q extension in July 2025, a poisoned GitHub issue that turned Cline's triage bot into a path to its npm token in February 2026, and a Morse-code message that got Grok to tell Bankrbot to send about $200,000 in tokens in May 2026.

The tooling around agents is now a supply chain. A copycat Postmark MCP server quietly copied every email it sent to an attacker in September 2025. The s1ngularity attack on Nx in August 2025 used developers' own installed AI command-line tools to hunt for secrets. Researchers counted 341 malicious skills on OpenClaw's ClawHub in February 2026. If an agent installs what it is told to install, the package registry becomes part of its attack surface.

Attackers run agents too. Anthropic's threat reports describe a data-extortion campaign automated with Claude Code (August 2025), a state-sponsored espionage operation that ran most of its steps through Claude Code (November 2025) and two more operations in September 2026. These are the only severe rows where the agent worked exactly as designed, for the wrong person.

Customer-facing agents fail in public and in court. The Air Canada ruling in February 2024 settled, for one tribunal at least, that a company owns what its bot tells customers. Cursor's support agent invented a login policy in April 2025 and the cofounder apologised on Hacker News. OpenAI's Operator bought a columnist a dozen eggs he had not agreed to buy. Small sums, large headlines.

If you run agents, the controls that would have stopped most of these rows are boring: scoped credentials, separate production access, confirmation before anything destructive or financial, and an allowlist for what an agent may install. The 47-control security checklist and the prompt-injection defence guide go through them, and the incident response runbook covers what to do once something has already gone wrong. That is also why every agent on Gravity is built and kept working by its builder rather than assembled by the user. Gravity is in private alpha; pricing starts with one free agent.

Change log

One dated line for each batch of rows added or corrected. Corrections name the row and what changed.

  1. : Database opened with 60 verified incidents dated 15 February 2024 to 29 September 2026, each read against its source before entry.

Methodology

Here is exactly what goes in, so you can decide how far to trust the counts.

What counts. An AI agent, meaning an autonomous or tool-using system such as a coding agent, a browser or computer-use agent, a customer-facing agent, a workplace assistant with connectors, or the tooling agents run on (MCP servers, plugins, skills), took or enabled an action that caused real harm or a public failure: data deleted or leaked, money lost, a wrong action, a security exploit through prompt injection, a runaway bill, or a legal or regulatory consequence.

What does not. Plain chatbot wrong answers that nobody acted on. Lab-only research demos against systems that were never shipped. Benchmark failures. Self-driving cars and physical robots. Lawyers who filed hallucinated citations, because a person filed them, not an agent.

Disclosed flaws are kept, and labelled. When researchers find a flaw in a shipped agent product and the vendor confirms and fixes it, through a CVE or an advisory, the row goes in as "Vulnerability disclosed" with no known exploitation. These rows show where agents are weak, but they are not harm, so every headline number on this page says which group it counts. A flaw the vendor disputed or left unfixed stays out until that changes.

Sources. Every row cites one to three sources, at least one of them original reporting, a vendor advisory or postmortem, a researcher's own write-up or a court document, and each source was opened and read before the row went in. Aggregator lists, including other "agents gone rogue" roundups and the AI Incident Database, were used only to find leads; nothing is copied from them. The date is the day the incident happened when the reporting gives it, otherwise the day it was first reported, and the table says which.

Postmortem. A row is marked as having a public postmortem when the vendor or the victim published an account of the cause: an engineering postmortem, a security advisory explaining the root cause, a threat report, or the victim's own technical write-up. A one-line statement to the press does not count.

Severity scale

  • 1, contained: one user or team affected, a small loss, or a low or medium flaw fixed before any known exploitation.
  • 2, significant: an organisation's production data lost or leaked, money lost above $10,000, a binding legal ruling, or a critical flaw (CVSS 8 or higher, or rated critical by the vendor) in a widely used product.
  • 3, severe: many organisations or users harmed, exploitation at scale, losses above $1 million, or an operation run by a state-backed group.

Refresh. Weekly. A script pulls candidate news stories every week; each candidate is checked against these rules and its source before a row is added, and the numbers on this page are recomputed from the rows. Nothing in the table is edited by hand.

Known gaps. This is a log of incidents that became public, so it undercounts. Companies rarely announce that an internal agent deleted something, and VentureBeat reported in May 2026 that most organisations have no incident category for "an agent did this" at all. Coverage is English-language and skews to the US, the UK and Australia. Severity is my judgement against the scale above; the CSV includes every field so you can apply your own.

FAQ

What counts as an AI agent incident?

An AI agent is software that takes actions with tools: it runs commands, sends email, edits records, moves money or browses for you. An incident is a public case where such an agent took or enabled an action that caused real harm: data deleted or leaked, money lost, a wrong action, a prompt-injection exploit, a runaway bill or a legal consequence. A chatbot giving a wrong answer that nobody acted on does not count.

What is the most common AI agent failure?

As of 4 October 2026, the most common harm in this database is data leaked, in 23 of 60 incidents. By agent type, coding agents lead with 28. Among real-world incidents, the pattern that repeats is an agent holding broad credentials and running a destructive command that nobody asked for.

How many AI agent incidents involve prompt injection?

20 of the 60 incidents logged as of 4 October 2026 (33%) used prompt injection, meaning instructions hidden in content the agent read. Most of those are flaws researchers found and vendors fixed; in-the-wild cases include the Amazon Q extension wiper prompt in July 2025, the Cline triage bot in February 2026 and the Grok and Bankrbot token transfer in May 2026.

Has an AI agent ever deleted a production database?

Yes, several times. Replit's agent deleted SaaStr's production database during a code freeze in July 2025; Claude Code ran terraform destroy on DataTalks.Club's production infrastructure in February 2026; and a Cursor agent deleted PocketOS's production database and its backups through a Railway token in April 2026. Each row in the table links the reporting.

Is a company liable for what its AI agent tells customers?

In the one tribunal ruling in this database, yes. In Moffatt v. Air Canada (February 2024) the British Columbia Civil Resolution Tribunal rejected the airline's argument that its chatbot was a separate entity and ordered it to honour what the chatbot had said. Other jurisdictions have not ruled the same way yet, so treat it as a signal rather than settled law.

How is this different from the AI Incident Database?

The AI Incident Database covers every kind of AI harm, from deepfakes to biased hiring models, and holds thousands of reports. This page covers only agents that take actions, records the agent type, prompt-injection mechanism and outcome for each, and is built from original reporting rather than from that database. Its rows are CC BY 4.0; the AI Incident Database snapshots are CC BY-SA.

Can I use this data?

Yes. The table and the CSV are licensed CC BY 4.0: copy them, chart them, quote the numbers, and credit "Gravity AI agent incidents database" with a link to this page. If you spot an error, tell me and I will fix it and note the correction in the change log.

How do I report an incident?

Email support@gravity.fast with a link to a public source: news reporting, a vendor advisory, a postmortem or a court document. I verify each one against its source before it goes in, so a report with only a social post may wait until it is covered elsewhere.

Sources

  1. Per-incident sources: linked in each table row and listed in full in data.csv (up to three per row, with publisher and date).
  2. VentureBeat, "AI agents are quietly generating chaos engineering failures enterprises don't track yet", 24 May 2026: venturebeat.com
  3. OWASP GenAI Security Project, LLM01:2025 Prompt Injection: genai.owasp.org
  4. Moffatt v. Air Canada, 2024 BCCRT 149, as reported by CBC News, 15 February 2024: cbc.ca
  5. Anthropic, threat intelligence report, August 2025, and "Disrupting the first reported AI-orchestrated cyber espionage campaign", November 2025: anthropic.com, anthropic.com
  6. AI Incident Database (Responsible AI Collaborative), the general AI harms archive this page complements; its data is CC BY-SA 4.0 and none of it is reused here: incidentdatabase.ai