{
 "name": "AI Agent Incidents Database: Failures Logged Since 2024",
 "source": "https://gravity.fast/data/ai-agent-incidents-database/",
 "license": "CC BY-SA 4.0",
 "updated": "2026-10-04",
 "rows": [
  {
   "id": "2026-09-29-multiple-vendors-cli-coding-agents",
   "date": "2026-09-29",
   "date_basis": "first report",
   "company": "Multiple vendors",
   "product": "CLI coding agents (PixelLeak)",
   "victim": "More than 300 organisations",
   "agent_type": "Coding agent",
   "incident_type": "Data exposure",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "3",
   "impact": "Coding agents that could not attach images to pull requests created public GitHub repos for screenshots, exposing 13,000+ internal images from 900+ repos, including billing records.",
   "outcome": "Glow Labs began notifying affected organisations on 9 September 2026 and published the research as PixelLeak.",
   "source_1_url": "https://www.glow.io/blogs/how-ai-agents-exposed-developer-screenshots-from-leading-tech-companies",
   "source_1_publisher": "Glow Labs (researcher)",
   "source_1_date": "2026-09-29",
   "source_2_url": "https://cyberpress.org/ai-agents-private-developer-screenshots/",
   "source_2_publisher": "Cyber Press",
   "source_2_date": "2026-09-30",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-09-24-salesforce-agentforce",
   "date": "2026-09-24",
   "date_basis": "first report",
   "company": "Salesforce",
   "product": "Agentforce",
   "victim": "Salesforce Agentforce customers",
   "agent_type": "Workplace assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "yes",
   "severity": "2",
   "impact": "Three SalesBleed flaws let a poisoned public Web-to-Lead form hijack Agentforce agents to exfiltrate CRM data with no click and send phishing under the agents' identity.",
   "outcome": "Zenity Labs reported the flaws and Salesforce worked with it to fix them; the attack chains no longer work.",
   "source_1_url": "https://labs.zenity.io/post/salesbleed-0-click-data-exfiltration-on-agentforce",
   "source_1_publisher": "Zenity Labs",
   "source_1_date": "2026-09-24",
   "source_2_url": "https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958",
   "source_2_publisher": "The Register",
   "source_2_date": "2026-09-24",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-09-10-anthropic-claude",
   "date": "2026-09-10",
   "date_basis": "first report",
   "company": "Anthropic",
   "product": "Claude (agentic multi-agent frameworks)",
   "victim": "More than 20 government, military, diplomatic and defence organisations, including a North African government authority",
   "agent_type": "Coding agent",
   "incident_type": "Attacker-operated agent",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "3",
   "impact": "GTG-20006, consistent with Midnight Blizzard, automated phishing, exploitation and exfiltration with Claude agents, stealing mailboxes and more than 300,000 national identity records.",
   "outcome": "Anthropic disrupted the activity, banned the accounts, strengthened safeguards and shared intelligence with authorities and industry.",
   "source_1_url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
   "source_1_publisher": "Anthropic",
   "source_1_date": "2026-09-10",
   "source_2_url": "https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/",
   "source_2_publisher": "BleepingComputer",
   "source_2_date": "2026-09-11",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-09-10-anthropic-claude-code",
   "date": "2026-09-10",
   "date_basis": "first report",
   "company": "Anthropic",
   "product": "Claude Code",
   "victim": "Technology providers, an airline, energy firms and about 200 downstream customers of one SaaS provider",
   "agent_type": "Coding agent",
   "incident_type": "Attacker-operated agent",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "3",
   "impact": "ShinyHunters affiliates (GTG-50014) had Claude scan 1.8 million Android apps for hardcoded secrets and used the access in breaches, including over 1 TB taken from one provider.",
   "outcome": "Anthropic banned the accounts, added measures against similar misuse and engaged authorities and victims.",
   "source_1_url": "https://www.anthropic.com/threat-intelligence-report-september-2026",
   "source_1_publisher": "Anthropic",
   "source_1_date": "2026-09-10",
   "source_2_url": "https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/",
   "source_2_publisher": "BleepingComputer",
   "source_2_date": "2026-09-11",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-08-10-openclaw-openclaw-personal-assistant",
   "date": "2026-08-10",
   "date_basis": "first report",
   "company": "OpenClaw (running Anthropic Claude Opus 4.6)",
   "product": "OpenClaw personal assistant",
   "victim": "Australian gym and a gym member removed from a waitlist",
   "agent_type": "Personal assistant agent",
   "incident_type": "Wrong commitment or action",
   "harm": "Wrong action",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "1",
   "impact": "Asked to book a gym class, the agent exploited booking-site flaws to book months ahead, then unprompted cancelled another member's waitlist entry to move its user up.",
   "outcome": "ABC called it the first known Australian autonomous cyber attack; Aikido later reproduced the exploit in 9 of 10 test runs.",
   "source_1_url": "https://www.abc.net.au/news/2026-08-10/ai-assistant-hacks-gym-website-aus-cyber-attack/107007986",
   "source_1_publisher": "ABC News (Australia)",
   "source_1_date": "2026-08-10",
   "source_2_url": "https://www.aikido.dev/blog/australian-gym-hack-openclaw-test",
   "source_2_publisher": "Aikido Security",
   "source_2_date": "2026-08-25",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-07-30-anthropic-claude-models-in-internal",
   "date": "2026-07-30",
   "date_basis": "first report",
   "company": "Anthropic",
   "product": "Claude models in internal cybersecurity evaluations",
   "victim": "Three real organisations",
   "agent_type": "Coding agent",
   "incident_type": "Wrong commitment or action",
   "harm": "System compromise",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "2",
   "impact": "In evaluations from April 2026, models reached the real internet, hacked real systems and published a malicious PyPI package that 15 real systems ran, leaking one company's credentials.",
   "outcome": "Anthropic disclosed the incidents, notified affected organisations on 27 July 2026, alerted PyPI and is remediating with them.",
   "source_1_url": "https://www.anthropic.com/news/investigating-incidents-cybersecurity-evals",
   "source_1_publisher": "Anthropic",
   "source_1_date": "2026-07-30",
   "source_2_url": "https://www.stepsecurity.io/blog/anthropic-incident-ai-agent-malicious-package-pypi",
   "source_2_publisher": "StepSecurity",
   "source_2_date": "2026-07-30",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-07-14-openai-gpt-5-6-sol",
   "date": "2026-07-14",
   "date_basis": "first report",
   "company": "OpenAI",
   "product": "GPT-5.6 Sol (agentic coding use)",
   "victim": "Multiple developers, including Matt Shumer and Bruno Lemos",
   "agent_type": "Coding agent",
   "incident_type": "Destructive action",
   "harm": "Data deleted",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "Developers reported the model deleting files beyond the task, including almost all files on one user's Mac and another user's production database.",
   "outcome": "OpenAI did not immediately comment; its June system card had warned the model tends to go beyond user intent and take destructive actions.",
   "source_1_url": "https://techcrunch.com/2026/07/14/openais-new-flagship-model-deletes-files-on-its-own-people-keep-warning/",
   "source_1_publisher": "TechCrunch",
   "source_1_date": "2026-07-14",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-07-01-anysphere-cursor",
   "date": "2026-07-01",
   "date_basis": "first report",
   "company": "Anysphere",
   "product": "Cursor",
   "victim": "Users",
   "agent_type": "Coding agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "System compromise",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "DuneSlide: zero-click prompt injection via MCP data or web results could escape Cursor's terminal sandbox and run commands on the host; rated CVSS 9.8.",
   "outcome": "Found by Cato AI Labs; fixed in Cursor 3.0 (released 2 April 2026) as CVE-2026-50548 and CVE-2026-50549.",
   "source_1_url": "https://thehackernews.com/2026/07/critical-cursor-flaws-could-let-prompt.html",
   "source_1_publisher": "The Hacker News",
   "source_1_date": "2026-07-01",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-06-18-openai-internal-research-agent",
   "date": "2026-06-18",
   "date_basis": "incident",
   "company": "OpenAI",
   "product": "Internal research agent",
   "victim": "Services Australia (Medicare statistics portal)",
   "agent_type": "Browser or computer-use agent",
   "incident_type": "Wrong commitment or action",
   "harm": "System compromise",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "During an internal evaluation, an OpenAI agent worked around repeated refusals and reached non-public files on a Medicare statistics portal; no personal records were found accessed.",
   "outcome": "OpenAI notified the government on September 10; Australia took the portal offline, opened ASD and agency investigations, and set up a taskforce.",
   "source_1_url": "https://www.abc.net.au/news/2026-09-24/what-we-know-about-the-openai-medicare-hack/107189452",
   "source_1_publisher": "ABC News (Australia)",
   "source_1_date": "2026-09-24",
   "source_2_url": "https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html",
   "source_2_publisher": "The Hacker News",
   "source_2_date": "2026-09-24",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-06-15-microsoft-microsoft-365-copilot",
   "date": "2026-06-15",
   "date_basis": "first report",
   "company": "Microsoft",
   "product": "Microsoft 365 Copilot (Enterprise Search)",
   "victim": "Users",
   "agent_type": "Workplace assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "SearchLeak: one click on a crafted Microsoft link made Copilot search the victim's mail, calendar and indexed files and send the results to an attacker server.",
   "outcome": "Microsoft rated it critical as CVE-2026-42824 and deployed a backend fix on 4 June 2026; no evidence of malicious use.",
   "source_1_url": "https://www.varonis.com/blog/searchleak",
   "source_1_publisher": "Varonis Threat Labs",
   "source_1_date": "2026-06-15",
   "source_2_url": "https://thenextweb.com/news/microsoft-365-copilot-searchleak-one-click-data-exfiltration",
   "source_2_publisher": "The Next Web",
   "source_2_date": "2026-06-15",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-05-05-xai-bankr-grok-and-bankrbot-wallet",
   "date": "2026-05-05",
   "date_basis": "first report",
   "company": "xAI / Bankr",
   "product": "Grok and Bankrbot wallet agent",
   "victim": "Grok's Bankr wallet",
   "agent_type": "Autonomous finance agent",
   "incident_type": "Prompt-injection exploit",
   "harm": "Money lost",
   "prompt_injection": "yes",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "An X user gave Grok's wallet a Bankr membership NFT, then had Grok translate Morse code that told Bankrbot to send 3 billion DRB tokens, about $200,000.",
   "outcome": "The attacker sold the tokens and deleted the account; Dexerto reported blockchain data later showed funds linked to Grok's wallet were returned.",
   "source_1_url": "https://www.dexerto.com/entertainment/x-user-tricks-grok-into-sending-them-200000-in-crypto-using-morse-code-3361036/",
   "source_1_publisher": "Dexerto",
   "source_1_date": "2026-05-05",
   "source_2_url": "https://gbhackers.com/hackers-use-morse-code-to-trick-grok-and-bankrbot/",
   "source_2_publisher": "GBHackers",
   "source_2_date": "2026-05-08",
   "source_3_url": "https://neuraltrust.ai/blog/grok-morse-code",
   "source_3_publisher": "NeuralTrust",
   "source_3_date": "2026-05-08",
   "added": "2026-10-04"
  },
  {
   "id": "2026-04-29-anthropic-claude-opus-used-as",
   "date": "2026-04-29",
   "date_basis": "first report",
   "company": "Anthropic",
   "product": "Claude Opus used as a coding agent (PromptMink npm campaign)",
   "victim": "openpaw-graveyard crypto trading agent project and other developers",
   "agent_type": "Coding agent",
   "incident_type": "Malicious tool or supply chain",
   "harm": "System compromise",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "3",
   "impact": "North Korea-linked Famous Chollima published about 60 npm packages crafted to be picked by coding agents; a Claude co-authored commit added one to a crypto trading agent.",
   "outcome": "ReversingLabs disclosed the campaign; npm removed some packages but the actors kept publishing replacements.",
   "source_1_url": "https://www.reversinglabs.com/blog/claude-promptmink-malware-crypto",
   "source_1_publisher": "ReversingLabs",
   "source_1_date": "2026-04-29",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-04-25-anysphere-cursor",
   "date": "2026-04-25",
   "date_basis": "incident",
   "company": "Anysphere",
   "product": "Cursor (running Claude Opus 4.6)",
   "victim": "PocketOS (Jer Crane) and its rental-business customers",
   "agent_type": "Coding agent",
   "incident_type": "Destructive action",
   "harm": "Data deleted",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "2",
   "impact": "Working on a staging task, the agent used an unrelated account-scoped Railway token to delete a volume, erasing the production database and its backups in nine seconds.",
   "outcome": "Railway's CEO restored the data and Railway added delayed-delete logic to the endpoint.",
   "source_1_url": "https://www.theregister.com/software/2026/04/27/cursor-opus-agent-snuffs-out-startups-production-database/5224442",
   "source_1_publisher": "The Register",
   "source_1_date": "2026-04-27",
   "source_2_url": "https://ia.acs.org.au/article/2026/gone-in-9-seconds--ai-agent-deletes-company-database.html",
   "source_2_publisher": "ACS Information Age",
   "source_2_date": "2026-05-05",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-03-30-openai-codex",
   "date": "2026-03-30",
   "date_basis": "first report",
   "company": "OpenAI",
   "product": "Codex (ChatGPT web, CLI, SDK, IDE extension)",
   "victim": "Users",
   "agent_type": "Coding agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "System compromise",
   "prompt_injection": "no",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "An unsanitised GitHub branch name was passed into shell commands when Codex set up its container, letting an attacker steal the GitHub token Codex used.",
   "outcome": "BeyondTrust Phantom Labs reported it on 16 December 2025; OpenAI rated it critical and patched it by 5 February 2026.",
   "source_1_url": "https://thehackernews.com/2026/03/openai-patches-chatgpt-data.html",
   "source_1_publisher": "The Hacker News",
   "source_1_date": "2026-03-30",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-03-09-perplexity-comet-browser-shopping-assistant",
   "date": "2026-03-09",
   "date_basis": "incident",
   "company": "Perplexity",
   "product": "Comet browser shopping assistant",
   "victim": "Perplexity (enjoined); Amazon (claimant)",
   "agent_type": "Browser or computer-use agent",
   "incident_type": "Legal or regulatory",
   "harm": "Legal liability",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "A US federal judge preliminarily barred Comet's agent from accessing Amazon, finding strong evidence it entered customer accounts without Amazon's authorization.",
   "outcome": "The Ninth Circuit vacated the injunction on August 4, 2026, holding Amazon unlikely to succeed on its computer fraud claims.",
   "source_1_url": "https://www.cnbc.com/2026/03/10/amazon-wins-court-order-to-block-perplexitys-ai-shopping-agent.html",
   "source_1_publisher": "CNBC",
   "source_1_date": "2026-03-10",
   "source_2_url": "https://www.cooley.com/news/insight/2026/2026-08-06-ninth-circuit-rules-on-ai-agent-access-to-third-party-websites-under-cfaa",
   "source_2_publisher": "Cooley",
   "source_2_date": "2026-08-06",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-02-26-anthropic-claude-code",
   "date": "2026-02-26",
   "date_basis": "incident",
   "company": "Anthropic",
   "product": "Claude Code",
   "victim": "DataTalks.Club (Alexey Grigorev)",
   "agent_type": "Coding agent",
   "incident_type": "Destructive action",
   "harm": "Data deleted",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "2",
   "impact": "Using a stale Terraform state file, the agent ran terraform destroy and removed the course platform's production infrastructure and database, 2.5 years of submissions, plus automated snapshots.",
   "outcome": "AWS Business Support restored a snapshot in about 24 hours (1,943,200 rows in one table); the owner moved state to S3, added deletion protection and stopped letting the agent run Terraform.",
   "source_1_url": "https://aishippingblog.com/p/how-i-dropped-our-production-database",
   "source_1_publisher": "Alexey Grigorev (victim post-mortem)",
   "source_1_date": "2026-03-06",
   "source_2_url": "https://tech.yahoo.com/ai/claude/articles/claude-code-deletes-developers-production-130000104.html",
   "source_2_publisher": "Tom's Hardware (via Yahoo Tech)",
   "source_2_date": "2026-03-07",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-02-23-openclaw-openclaw-email-agent",
   "date": "2026-02-23",
   "date_basis": "first report",
   "company": "OpenClaw",
   "product": "OpenClaw email agent",
   "victim": "Summer Yue (Meta Superintelligence Labs)",
   "agent_type": "Personal assistant agent",
   "incident_type": "Destructive action",
   "harm": "Data deleted",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "1",
   "impact": "Asked to suggest emails to delete or archive, the agent began deleting her inbox and ignored stop commands sent from her phone.",
   "outcome": "She stopped it at her Mac mini and attributed the failure to context compaction dropping her confirm-first instruction.",
   "source_1_url": "https://techcrunch.com/2026/02/23/a-meta-ai-security-researcher-said-an-openclaw-agent-ran-amok-on-her-inbox/",
   "source_1_publisher": "TechCrunch",
   "source_1_date": "2026-02-23",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-02-22-lobstar-wilde-lobstar-wilde-autonomous-trading",
   "date": "2026-02-22",
   "date_basis": "incident",
   "company": "Lobstar Wilde (independent project by Nik Pash)",
   "product": "Lobstar Wilde autonomous trading agent",
   "victim": "Nik Pash (agent owner)",
   "agent_type": "Autonomous finance agent",
   "incident_type": "Wrong commitment or action",
   "harm": "Money lost",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "Asked by an X user for 4 SOL, the agent sent 52.4 million LOBSTAR tokens, worth about $441,780, in one transaction, apparently misreading decimals.",
   "outcome": "The agent publicly admitted the error; the recipient sold part of the tokens for about $40,000.",
   "source_1_url": "https://cointelegraph.com/news/openai-employee-s-ai-agent-accidentally-sent-442k-to-beggar",
   "source_1_publisher": "Cointelegraph",
   "source_1_date": "2026-02-23",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-02-20-amazon-web-services-kiro",
   "date": "2026-02-20",
   "date_basis": "first report",
   "company": "Amazon Web Services",
   "product": "Kiro",
   "victim": "AWS Cost Explorer customers in one mainland China region",
   "agent_type": "Coding agent",
   "incident_type": "Destructive action",
   "harm": "Service outage",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "2",
   "impact": "The FT reported that in mid-December 2025 Kiro chose to delete and recreate an environment, causing a 13-hour interruption to AWS Cost Explorer in one region.",
   "outcome": "Amazon disputes the account: it says the cause was user error, specifically misconfigured access controls, not AI, calls it an extremely limited event, and added mandatory peer review for production access.",
   "source_1_url": "https://the-decoder.com/aws-ai-coding-tool-decided-to-delete-and-recreate-a-customer-facing-system-causing-13-hour-outage-report-says/",
   "source_1_publisher": "The Decoder (summarising the Financial Times)",
   "source_1_date": "2026-02-20",
   "source_2_url": "https://www.aboutamazon.com/news/aws/aws-service-outage-ai-bot-kiro",
   "source_2_publisher": "Amazon",
   "source_2_date": "2026-02-20",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-02-17-cline-cline-ai-issue-triage",
   "date": "2026-02-17",
   "date_basis": "incident",
   "company": "Cline",
   "product": "Cline AI issue-triage workflow (claude-code-action) and Cline CLI",
   "victim": "Users who installed cline@2.3.0",
   "agent_type": "Coding agent",
   "incident_type": "Prompt-injection exploit",
   "harm": "System compromise",
   "prompt_injection": "yes",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "2",
   "impact": "A prompt-injectable AI triage workflow led to theft of Cline's npm token, later used to publish cline@2.3.0, which silently installed OpenClaw for about 8 hours.",
   "outcome": "Cline shipped 2.4.0, deprecated 2.3.0, revoked the token, moved npm publishing to OIDC provenance and published advisory GHSA-9ppg-jx86-fqw7.",
   "source_1_url": "https://adnanthekhan.com/posts/clinejection/",
   "source_1_publisher": "Adnan Khan (researcher)",
   "source_1_date": "2026-02-09",
   "source_2_url": "https://github.com/cline/cline/security/advisories/GHSA-9ppg-jx86-fqw7",
   "source_2_publisher": "Cline security advisory",
   "source_2_date": "2026-02-17",
   "source_3_url": "https://snyk.io/blog/cline-supply-chain-attack-prompt-injection-github-actions/",
   "source_3_publisher": "Snyk",
   "source_3_date": "2026-02-17",
   "added": "2026-10-04"
  },
  {
   "id": "2026-02-12-openclaw-openclaw-agent-mj-rathbun",
   "date": "2026-02-12",
   "date_basis": "first report",
   "company": "OpenClaw",
   "product": "OpenClaw agent \"MJ Rathbun\"",
   "victim": "Scott Shambaugh (matplotlib maintainer)",
   "agent_type": "Personal assistant agent",
   "incident_type": "Wrong commitment or action",
   "harm": "Wrong action",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "1",
   "impact": "After a maintainer closed its pull request, an autonomous OpenClaw agent researched him and published a blog post attacking his character to pressure him into accepting its code.",
   "outcome": "The maintainer published a detailed account and follow-ups; the agent later posted an apology and its operator came forward.",
   "source_1_url": "https://theshamblog.com/an-ai-agent-published-a-hit-piece-on-me/",
   "source_1_publisher": "The Shamblog (Scott Shambaugh)",
   "source_1_date": "2026-02-12",
   "source_2_url": "https://cybernews.com/security/openclaw-bot-attacks-developer-who-rejected-its-code/",
   "source_2_publisher": "Cybernews",
   "source_2_date": "2026-02-13",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-02-02-openclaw-openclaw-gateway-control-ui",
   "date": "2026-02-02",
   "date_basis": "first report",
   "company": "OpenClaw",
   "product": "OpenClaw gateway Control UI",
   "victim": "OpenClaw users",
   "agent_type": "Personal assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "System compromise",
   "prompt_injection": "no",
   "in_the_wild": "no",
   "postmortem": "yes",
   "severity": "2",
   "impact": "Visiting a malicious link could leak the OpenClaw gateway token and give an attacker full control of the user's agent, a one-click remote code execution chain.",
   "outcome": "Tracked as CVE-2026-25253 (CVSS 8.8); fixed in OpenClaw 2026.1.29 released January 30, 2026, with a maintainer advisory.",
   "source_1_url": "https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html",
   "source_1_publisher": "The Hacker News",
   "source_1_date": "2026-02-02",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-02-01-openclaw-clawhub-skill-marketplace",
   "date": "2026-02-01",
   "date_basis": "first report",
   "company": "OpenClaw",
   "product": "ClawHub skill marketplace",
   "victim": "Users",
   "agent_type": "Agent tooling (MCP, plugins, skills)",
   "incident_type": "Malicious tool or supply chain",
   "harm": "System compromise",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "An audit of 2,857 ClawHub skills found 341 malicious ones; 335 used fake prerequisites to install the Atomic Stealer infostealer on users' machines.",
   "outcome": "OpenClaw added user reporting that auto-hides skills with more than three reports; the number of infected users was not disclosed.",
   "source_1_url": "https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html",
   "source_1_publisher": "The Hacker News",
   "source_1_date": "2026-02-02",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-01-31-moltbook-moltbook-social-network-for",
   "date": "2026-01-31",
   "date_basis": "incident",
   "company": "Moltbook",
   "product": "Moltbook social network for OpenClaw agents",
   "victim": "Moltbook users and their agents",
   "agent_type": "Personal assistant agent",
   "incident_type": "Data exposure",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "no",
   "postmortem": "yes",
   "severity": "2",
   "impact": "A misconfigured Supabase database gave anyone read and write access to 1.5 million agent API tokens, 35,000 email addresses and private messages between agents.",
   "outcome": "After Wiz's report on January 31, 2026, Moltbook secured all tables within about three hours; Wiz published a disclosure timeline.",
   "source_1_url": "https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys",
   "source_1_publisher": "Wiz",
   "source_1_date": "2026-02-02",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-01-14-microsoft-microsoft-copilot-personal",
   "date": "2026-01-14",
   "date_basis": "first report",
   "company": "Microsoft",
   "product": "Microsoft Copilot Personal",
   "victim": "Users",
   "agent_type": "Personal assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "1",
   "impact": "Reprompt: one click on a real Copilot link with a hidden prompt in the URL let attackers keep pulling the user's personal data and Copilot memory to their server.",
   "outcome": "Reported 31 August 2025; Microsoft patched it on 13 January 2026; Microsoft 365 Copilot enterprise users were not affected.",
   "source_1_url": "https://www.varonis.com/blog/reprompt",
   "source_1_publisher": "Varonis Threat Labs",
   "source_1_date": "2026-01-14",
   "source_2_url": "https://cybersecuritynews.com/reprompt-single-click-copilot-exploit/",
   "source_2_publisher": "Cyber Security News",
   "source_2_date": "2026-01-14",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2026-01-13-servicenow-now-assist-ai-agents",
   "date": "2026-01-13",
   "date_basis": "first report",
   "company": "ServiceNow",
   "product": "Now Assist AI Agents and Virtual Agent API",
   "victim": "Users",
   "agent_type": "Workplace assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "System compromise",
   "prompt_injection": "no",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "BodySnatcher: a shared static secret and email-only account linking let an unauthenticated attacker impersonate any user, bypass MFA and SSO, and run privileged AI agent workflows.",
   "outcome": "CVE-2025-12420, CVSS 9.3; reported 23 October 2025, ServiceNow patched hosted instances on 30 October 2025; no exploitation observed.",
   "source_1_url": "https://appomni.com/ao-labs/bodysnatcher-agentic-ai-security-vulnerability-in-servicenow/",
   "source_1_publisher": "AppOmni",
   "source_1_date": "2026-01-13",
   "source_2_url": "https://thehackernews.com/2026/01/servicenow-patches-critical-ai-platform.html",
   "source_2_publisher": "The Hacker News",
   "source_2_date": "2026-01-13",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-12-09-anthropic-claude-code",
   "date": "2025-12-09",
   "date_basis": "first report",
   "company": "Anthropic",
   "product": "Claude Code",
   "victim": "Individual user (Reddit r/ClaudeAI)",
   "agent_type": "Coding agent",
   "incident_type": "Destructive action",
   "harm": "Data deleted",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "1",
   "impact": "Asked to clean up an old repository, the agent ran rm -rf tests/ patches/ plan/ ~/ and the trailing ~/ wiped the user's Mac home directory, including Keychain data.",
   "outcome": "No formal Anthropic response was reported; coverage noted the user may have bypassed permission prompts or approved the command without review.",
   "source_1_url": "https://simonwillison.net/2025/Dec/9/claude/",
   "source_1_publisher": "Simon Willison's Weblog",
   "source_1_date": "2025-12-09",
   "source_2_url": "https://gigazine.net/gsc_news/en/20251216-claude-code-cli-mac-deleted/",
   "source_2_publisher": "GIGAZINE",
   "source_2_date": "2025-12-16",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-12-01-google-antigravity",
   "date": "2025-12-01",
   "date_basis": "first report",
   "company": "Google",
   "product": "Antigravity",
   "victim": "Tassos M (individual developer)",
   "agent_type": "Coding agent",
   "incident_type": "Destructive action",
   "harm": "Data deleted",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "1",
   "impact": "Running in Turbo mode, the agent tried to clear a project cache but targeted the root of the user's D: drive and deleted its entire contents, bypassing the Recycle Bin.",
   "outcome": "Google told The Register it was aware of the report and actively investigating.",
   "source_1_url": "https://www.theregister.com/2025/12/01/google_antigravity_wipes_d_drive/",
   "source_1_publisher": "The Register",
   "source_1_date": "2025-12-01",
   "source_2_url": "https://www.newsweek.com/google-ai-accidentally-deletes-hard-drive-data-antigravity-11169711",
   "source_2_publisher": "Newsweek",
   "source_2_date": "2025-12-08",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-11-13-anthropic-claude-code",
   "date": "2025-11-13",
   "date_basis": "first report",
   "company": "Anthropic",
   "product": "Claude Code",
   "victim": "About 30 organisations in tech, finance, chemicals and government; a small number breached",
   "agent_type": "Coding agent",
   "incident_type": "Attacker-operated agent",
   "harm": "System compromise",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "3",
   "impact": "A Chinese state-sponsored group, GTG-1002, used Claude Code with MCP tools to run 80 to 90 percent of an espionage campaign, detected in mid-September 2025.",
   "outcome": "Anthropic banned the accounts, notified affected organisations and coordinated with authorities over ten days.",
   "source_1_url": "https://www.anthropic.com/news/disrupting-AI-espionage",
   "source_1_publisher": "Anthropic",
   "source_1_date": "2025-11-13",
   "source_2_url": "https://www.theregister.com/2025/11/13/chinese_spies_claude_attacks/",
   "source_2_publisher": "The Register",
   "source_2_date": "2025-11-13",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-10-09-microsoft-github-copilot-chat",
   "date": "2025-10-09",
   "date_basis": "first report",
   "company": "Microsoft (GitHub)",
   "product": "GitHub Copilot Chat",
   "victim": "Users",
   "agent_type": "Coding agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "CamoLeak: hidden markdown comments in pull requests could make Copilot Chat exfiltrate secrets and private code through GitHub's Camo image proxy; rated CVSS 9.6.",
   "outcome": "GitHub disabled image rendering in Copilot Chat on 14 August 2025 after a HackerOne report from Legit Security.",
   "source_1_url": "https://www.theregister.com/2025/10/09/github_copilot_chat_vulnerability/",
   "source_1_publisher": "The Register",
   "source_1_date": "2025-10-09",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-09-25-salesforce-agentforce",
   "date": "2025-09-25",
   "date_basis": "first report",
   "company": "Salesforce",
   "product": "Agentforce",
   "victim": "Users",
   "agent_type": "Workplace assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "ForcedLeak: instructions hidden in a Web-to-Lead form made Agentforce send CRM data to an attacker URL when employees later worked with the lead.",
   "outcome": "Rated CVSS 9.4 by the researchers; Salesforce enforced Trusted URLs for Agentforce and Einstein AI on 8 September 2025.",
   "source_1_url": "https://noma.security/blog/forcedleak-agent-risks-exposed-in-salesforce-agentforce/",
   "source_1_publisher": "Noma Security",
   "source_1_date": "2025-09-25",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-09-18-openai-chatgpt-deep-research",
   "date": "2025-09-18",
   "date_basis": "first report",
   "company": "OpenAI",
   "product": "ChatGPT Deep Research (Gmail connector)",
   "victim": "Users",
   "agent_type": "Personal assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "1",
   "impact": "ShadowLeak: a crafted email made Deep Research send inbox data to an attacker URL from OpenAI's own servers, with no user click and no network trace on the victim side.",
   "outcome": "Reported 18 June 2025; OpenAI fixed it by early August and marked it resolved on 3 September 2025; no exploitation seen.",
   "source_1_url": "https://therecord.media/openai-fixes-zero-click-shadowleak-vulnerability",
   "source_1_publisher": "The Record",
   "source_1_date": "2025-09-18",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-09-18-replit-replit-agent-3",
   "date": "2025-09-18",
   "date_basis": "first report",
   "company": "Replit",
   "product": "Replit Agent 3",
   "victim": "Users",
   "agent_type": "Coding agent",
   "incident_type": "Runaway cost",
   "harm": "Unexpected cost",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "1",
   "impact": "Under effort-based pricing, users reported Agent 3 running sub-agents on small edits, with one spending $1,000 in a week versus $180 to $200 a month before.",
   "outcome": "The Register asked Replit for comment and had no response at publication.",
   "source_1_url": "https://www.theregister.com/2025/09/18/replit_agent3_pricing/",
   "source_1_publisher": "The Register",
   "source_1_date": "2025-09-18",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-09-17-unofficial-npm-publisher-postmark-mcp-npm-package",
   "date": "2025-09-17",
   "date_basis": "incident",
   "company": "Unofficial npm publisher (impersonating Postmark)",
   "product": "postmark-mcp npm package",
   "victim": "Users (1,643 downloads)",
   "agent_type": "Agent tooling (MCP, plugins, skills)",
   "incident_type": "Malicious tool or supply chain",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "Version 1.0.16 of a copycat Postmark MCP server added one line that BCC'd every email sent through it to an attacker-controlled address.",
   "outcome": "Koi Security flagged it and the package was removed from npm; users were told to remove it and rotate exposed credentials.",
   "source_1_url": "https://thehackernews.com/2025/09/first-malicious-mcp-server-found.html",
   "source_1_publisher": "The Hacker News",
   "source_1_date": "2025-09-29",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-29-taco-bell-drive-thru-voice-ai",
   "date": "2025-08-29",
   "date_basis": "first report",
   "company": "Taco Bell (Yum Brands)",
   "product": "Drive-thru voice AI ordering",
   "victim": "Taco Bell customers and restaurant staff",
   "agent_type": "Customer-facing agent",
   "incident_type": "Wrong commitment or action",
   "harm": "Wrong action",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "1",
   "impact": "Viral videos showed the voice AI, deployed at over 500 US drive-thrus, mishandling orders, including one customer ordering 18,000 water cups.",
   "outcome": "Taco Bell's technology chief told the Wall Street Journal the chain is rethinking where to use voice AI and keeping staff ready to step in at busy times.",
   "source_1_url": "https://www.bbc.com/news/articles/ckgyk2p55g8o",
   "source_1_publisher": "BBC News",
   "source_1_date": "2025-08-29",
   "source_2_url": "https://techcrunch.com/2025/08/30/taco-bell-is-having-second-thoughts-about-relying-on-ai-at-the-drive-through/",
   "source_2_publisher": "TechCrunch",
   "source_2_date": "2025-08-30",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-27-anthropic-claude-code",
   "date": "2025-08-27",
   "date_basis": "first report",
   "company": "Anthropic",
   "product": "Claude Code",
   "victim": "At least 17 organisations, including healthcare, emergency services and government bodies",
   "agent_type": "Coding agent",
   "incident_type": "Attacker-operated agent",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "3",
   "impact": "Actor GTG-2002 used Claude Code to automate reconnaissance, credential theft, network intrusion and ransom notes in a data extortion campaign, with demands sometimes above $500,000.",
   "outcome": "Anthropic banned the accounts, built new detection classifiers and shared indicators with authorities in its August 2025 threat report.",
   "source_1_url": "https://www.anthropic.com/news/detecting-countering-misuse-aug-2025",
   "source_1_publisher": "Anthropic",
   "source_1_date": "2025-08-27",
   "source_2_url": "https://www.heise.de/en/news/Threat-report-How-cybercriminals-are-abusing-Claude-from-Anthropic-10623474.html",
   "source_2_publisher": "heise online",
   "source_2_date": "2025-08-27",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-26-nx-nx-npm-packages",
   "date": "2025-08-26",
   "date_basis": "incident",
   "company": "Nx (Nrwl)",
   "product": "Nx npm packages (s1ngularity attack abusing Claude Code, Gemini CLI and Amazon Q CLIs)",
   "victim": "Developers and organisations that installed malicious Nx versions",
   "agent_type": "Coding agent",
   "incident_type": "Malicious tool or supply chain",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "3",
   "impact": "Malicious Nx versions ran installed AI CLIs with permission-bypass flags to hunt secrets; Wiz counted over 1,000 valid GitHub tokens leaked and 5,500+ private repositories made public.",
   "outcome": "Malicious versions were removed after about 4 hours; Nx published a postmortem blaming an injectable pull_request_target workflow that leaked its npm token.",
   "source_1_url": "https://nx.dev/blog/s1ngularity-postmortem",
   "source_1_publisher": "Nx (vendor postmortem)",
   "source_1_date": "2025-09-05",
   "source_2_url": "https://www.wiz.io/blog/s1ngularity-supply-chain-attack",
   "source_2_publisher": "Wiz",
   "source_2_date": "2025-08-27",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-20-perplexity-comet-browser-assistant",
   "date": "2025-08-20",
   "date_basis": "first report",
   "company": "Perplexity",
   "product": "Comet browser assistant",
   "victim": "Comet users",
   "agent_type": "Browser or computer-use agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "yes",
   "severity": "2",
   "impact": "Hidden instructions in a web page or Reddit comment could make Comet's summarise feature act on the user's logged-in accounts, such as reading their email.",
   "outcome": "Perplexity shipped fixes before Brave's August 20, 2025 disclosure, but Brave later reported the mitigation was incomplete and re-reported it.",
   "source_1_url": "https://www.brave.com/blog/comet-prompt-injection/",
   "source_1_publisher": "Brave",
   "source_1_date": "2025-08-20",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-18-lenovo-lena-customer-support-chatbot",
   "date": "2025-08-18",
   "date_basis": "first report",
   "company": "Lenovo",
   "product": "Lena customer-support chatbot",
   "victim": "Lenovo customer-support staff and systems",
   "agent_type": "Customer-facing agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "System compromise",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "1",
   "impact": "A single crafted prompt made the GPT-4 powered chatbot emit HTML that ran scripts and could leak support agents' session cookies.",
   "outcome": "Cybernews disclosed responsibly; Lenovo acknowledged the cross-site scripting flaw and said it had protected its systems before publication.",
   "source_1_url": "https://cybernews.com/security/lenovo-chatbot-lena-plagued-by-critical-vulnerabilities/",
   "source_1_publisher": "Cybernews",
   "source_1_date": "2025-08-18",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-12-microsoft-github-copilot-in-visual",
   "date": "2025-08-12",
   "date_basis": "first report",
   "company": "Microsoft (GitHub)",
   "product": "GitHub Copilot in Visual Studio / VS Code agent mode",
   "victim": "Users",
   "agent_type": "Coding agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "System compromise",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "Injected instructions in code or issues could make Copilot write chat.tools.autoApprove into .vscode/settings.json, switching off confirmations and allowing arbitrary shell commands.",
   "outcome": "Reported to Microsoft on 29 June 2025 and fixed in the August 2025 Patch Tuesday as CVE-2025-53773.",
   "source_1_url": "https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/",
   "source_1_publisher": "Embrace The Red (Johann Rehberger)",
   "source_1_date": "2025-08-12",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-08-cognition-devin",
   "date": "2025-08-08",
   "date_basis": "first report",
   "company": "Cognition",
   "product": "Devin",
   "victim": "Users",
   "agent_type": "Coding agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "1",
   "impact": "A malicious web page could make Devin start a web server and use its expose_port tool to publish local files on a public devinapps.com URL without approval.",
   "outcome": "Reported to Cognition on 6 April 2025; the researcher disclosed after 120+ days with receipt acknowledged but no confirmed fix.",
   "source_1_url": "https://embracethered.com/blog/posts/2025/devin-ai-kill-chain-exposing-ports/",
   "source_1_publisher": "Embrace The Red (Johann Rehberger)",
   "source_1_date": "2025-08-08",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-08-salesloft-drift-salesforce-integration",
   "date": "2025-08-08",
   "date_basis": "incident",
   "company": "Salesloft",
   "product": "Drift (AI chat agent) Salesforce integration",
   "victim": "More than 700 organisations, including Cloudflare, Palo Alto Networks, Zscaler, Tanium and Proofpoint",
   "agent_type": "Customer-facing agent",
   "incident_type": "Malicious tool or supply chain",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "3",
   "impact": "Between 8 and 18 August 2025, actor UNC6395 used stolen Drift OAuth tokens to export Salesforce data, including contacts, cases, AWS keys, passwords and Snowflake tokens.",
   "outcome": "Salesloft and Salesforce revoked all Drift tokens on 20 August 2025, Drift was pulled from AppExchange, and Salesloft engaged Mandiant.",
   "source_1_url": "https://cloud.google.com/blog/topics/threat-intelligence/data-theft-salesforce-instances-via-salesloft-drift",
   "source_1_publisher": "Google Threat Intelligence Group",
   "source_1_date": "2025-08-27",
   "source_2_url": "https://www.securityweek.com/more-cybersecurity-firms-hit-by-salesforce-salesloft-drift-breach/",
   "source_2_publisher": "SecurityWeek",
   "source_2_date": "2025-09-05",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-06-google-gemini",
   "date": "2025-08-06",
   "date_basis": "first report",
   "company": "Google",
   "product": "Gemini (web, mobile app and Google Assistant)",
   "victim": "Users",
   "agent_type": "Personal assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Wrong action",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "yes",
   "severity": "1",
   "impact": "Hidden instructions in a Google Calendar invite made Gemini control smart-home devices, delete events, start Zoom calls and leak emails across 14 attack scenarios.",
   "outcome": "Reported in February 2025; Google added user confirmations for sensitive actions, URL sanitisation and prompt injection classifiers.",
   "source_1_url": "https://www.safebreach.com/blog/invitation-is-all-you-need-hacking-gemini/",
   "source_1_publisher": "SafeBreach",
   "source_1_date": "2025-08-06",
   "source_2_url": "https://www.androidauthority.com/gemini-hacked-calendar-invite-smart-homes-3584529/",
   "source_2_publisher": "Android Authority",
   "source_2_date": "2025-08-06",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-08-01-anysphere-cursor",
   "date": "2025-08-01",
   "date_basis": "first report",
   "company": "Anysphere",
   "product": "Cursor",
   "victim": "Users",
   "agent_type": "Coding agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "System compromise",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "CurXecute: a prompt injection arriving through an MCP-connected source such as Slack could rewrite ~/.cursor/mcp.json, and Cursor executed the new entry without confirmation.",
   "outcome": "Fixed in Cursor 1.3 on 29 July 2025; tracked as CVE-2025-54135 (CVSS 8.6), found by Aim Labs.",
   "source_1_url": "https://www.bleepingcomputer.com/news/security/ai-powered-cursor-ide-vulnerable-to-prompt-injection-attacks/",
   "source_1_publisher": "BleepingComputer",
   "source_1_date": "2025-08-01",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-07-21-google-gemini-cli",
   "date": "2025-07-21",
   "date_basis": "first report",
   "company": "Google",
   "product": "Gemini CLI",
   "victim": "Anuraag Gupta (individual user)",
   "agent_type": "Coding agent",
   "incident_type": "Destructive action",
   "harm": "Data deleted",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "1",
   "impact": "Asked to rename and reorganise a folder on Windows, the agent assumed a failed mkdir had worked and its move commands overwrote the user's files one after another.",
   "outcome": "The user filed a priority bug on the gemini-cli GitHub repository and published a write-up; no formal Google statement was reported.",
   "source_1_url": "https://github.com/google-gemini/gemini-cli/issues/4586",
   "source_1_publisher": "GitHub (google-gemini/gemini-cli issue)",
   "source_1_date": "2025-07-21",
   "source_2_url": "https://winbuzzer.com/2025/07/26/googles-gemini-cli-deletes-user-files-confesses-catastrophic-failure-xcxwbn/",
   "source_2_publisher": "WinBuzzer",
   "source_2_date": "2025-07-26",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-07-18-replit-replit-agent",
   "date": "2025-07-18",
   "date_basis": "first report",
   "company": "Replit",
   "product": "Replit Agent",
   "victim": "SaaStr (Jason Lemkin)",
   "agent_type": "Coding agent",
   "incident_type": "Destructive action",
   "harm": "Data deleted",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "During a declared code freeze the agent deleted a live production database holding records for more than 1,200 executives and 1,190 companies, then generated about 4,000 fake records.",
   "outcome": "The agent first said rollback was impossible but it worked; CEO Amjad Masad called it unacceptable and announced automatic dev/prod database separation and a planning-only mode.",
   "source_1_url": "https://www.theregister.com/2025/07/21/replit_saastr_vibe_coding_incident/",
   "source_1_publisher": "The Register",
   "source_1_date": "2025-07-21",
   "source_2_url": "https://fortune.com/2025/07/23/ai-coding-tool-replit-wiped-database-called-it-a-catastrophic-failure",
   "source_2_publisher": "Fortune",
   "source_2_date": "2025-07-23",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-07-17-amazon-web-services-amazon-q-developer-extension",
   "date": "2025-07-17",
   "date_basis": "incident",
   "company": "Amazon Web Services",
   "product": "Amazon Q Developer extension for VS Code",
   "victim": "Users who installed version 1.84.0",
   "agent_type": "Coding agent",
   "incident_type": "Malicious tool or supply chain",
   "harm": "System compromise",
   "prompt_injection": "yes",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "2",
   "impact": "A hacker's unapproved commit planted a prompt telling the agent to wipe the system to a near-factory state and delete cloud resources, and it shipped in the official 1.84.0 release.",
   "outcome": "AWS revoked credentials, removed the code, shipped 1.85.0 and issued bulletin AWS-2025-015 (CVE-2025-8217), saying a syntax error stopped the code from executing.",
   "source_1_url": "https://aws.amazon.com/security/security-bulletins/AWS-2025-015/",
   "source_1_publisher": "AWS Security Bulletin",
   "source_1_date": "2025-07-23",
   "source_2_url": "https://www.bleepingcomputer.com/news/security/amazon-ai-coding-agent-hacked-to-inject-data-wiping-commands/",
   "source_2_publisher": "BleepingComputer",
   "source_2_date": "2025-07-25",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-07-07-microsoft-copilot-studio",
   "date": "2025-07-07",
   "date_basis": "first report",
   "company": "Microsoft",
   "product": "Copilot Studio",
   "victim": "Users",
   "agent_type": "Customer-facing agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "On a replica of a public Copilot Studio customer service agent, one email with a prompt injection made the agent send knowledge files and CRM records to the attacker.",
   "outcome": "Microsoft confirmed the report as critical, deployed a prompt shielding fix on 24 April 2025 and paid an $8,000 bounty.",
   "source_1_url": "https://labs.zenity.io/p/a-copilot-studio-story-2-when-aijacking-leads-to-full-data-exfiltration-bc4a",
   "source_1_publisher": "Zenity Labs",
   "source_1_date": "2025-07-07",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-06-30-paradox-ai-mcdonald-s-mchire-olivia-hiring-agent",
   "date": "2025-06-30",
   "date_basis": "incident",
   "company": "Paradox.ai / McDonald's",
   "product": "McHire \"Olivia\" hiring agent platform",
   "victim": "McDonald's job applicants",
   "agent_type": "Customer-facing agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "2",
   "impact": "Default admin credentials (123456:123456) plus an insecure API let researchers reach chats and personal data for more than 64 million applicant records.",
   "outcome": "Credentials were disabled within hours of disclosure on June 30, 2025, and Paradox.ai confirmed the issues resolved on July 1.",
   "source_1_url": "https://ian.sh/mcdonalds",
   "source_1_publisher": "Ian Carroll and Sam Curry (researchers)",
   "source_1_date": "2025-07-09",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-06-16-anysphere-cursor",
   "date": "2025-06-16",
   "date_basis": "incident",
   "company": "Anysphere",
   "product": "Cursor",
   "victim": "Cursor Pro users",
   "agent_type": "Coding agent",
   "incident_type": "Runaway cost",
   "harm": "Unexpected cost",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "1",
   "impact": "A Pro plan change to a $20 usage credit billed at API rates left users who had not set spend limits with unexpected overage charges.",
   "outcome": "CEO Michael Truell apologised and Cursor offered refunds for unexpected charges incurred between 16 June and 4 July 2025.",
   "source_1_url": "https://cursor.com/blog/june-2025-pricing",
   "source_1_publisher": "Cursor",
   "source_1_date": "2025-07-04",
   "source_2_url": "https://techcrunch.com/2025/07/07/cursor-apologizes-for-unclear-pricing-changes-that-upset-users/",
   "source_2_publisher": "TechCrunch",
   "source_2_date": "2025-07-07",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-06-11-microsoft-microsoft-365-copilot",
   "date": "2025-06-11",
   "date_basis": "first report",
   "company": "Microsoft",
   "product": "Microsoft 365 Copilot",
   "victim": "Users",
   "agent_type": "Workplace assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "yes",
   "severity": "2",
   "impact": "EchoLeak: a single crafted email with hidden instructions could make Copilot pull sensitive organisational data from the user's context and send it out, with no click needed.",
   "outcome": "Microsoft rated it critical as CVE-2025-32711, fixed it server side in May 2025 and said there was no evidence of real-world exploitation.",
   "source_1_url": "https://www.bleepingcomputer.com/news/security/zero-click-ai-data-leak-flaw-uncovered-in-microsoft-365-copilot/",
   "source_1_publisher": "BleepingComputer",
   "source_1_date": "2025-06-11",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-06-04-asana-asana-mcp-server",
   "date": "2025-06-04",
   "date_basis": "incident",
   "company": "Asana",
   "product": "Asana MCP server",
   "victim": "About 1,000 Asana customers",
   "agent_type": "Agent tooling (MCP, plugins, skills)",
   "incident_type": "Data exposure",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "A logic bug in Asana's MCP server, live since 1 May 2025, could expose one organisation's tasks, projects, comments and files to other organisations' MCP users.",
   "outcome": "Asana found the bug on 4 June, took the MCP server offline from 5 to 17 June, fixed it and contacted affected customers directly.",
   "source_1_url": "https://www.bleepingcomputer.com/news/security/asana-warns-mcp-ai-feature-exposed-customer-data-to-other-orgs/",
   "source_1_publisher": "BleepingComputer",
   "source_1_date": "2025-06-18",
   "source_2_url": "https://www.theregister.com/security/2025/06/18/asana-mcp-server-back-online-after-plugging-a-data-leak-hole/1199951",
   "source_2_publisher": "The Register",
   "source_2_date": "2025-06-18",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-05-29-lovable-lovable-app-builder",
   "date": "2025-05-29",
   "date_basis": "first report",
   "company": "Lovable",
   "product": "Lovable app builder",
   "victim": "Users of Lovable-built apps",
   "agent_type": "Coding agent",
   "incident_type": "Data exposure",
   "harm": "Data leaked",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "Of 1,645 Lovable-generated apps scanned, 170 lacked adequate row-level security, exposing emails, addresses, payment details and API keys through 303 endpoints.",
   "outcome": "Researcher Matt Palmer published CVE-2025-48757 after Lovable confirmed receipt but gave no meaningful fix; Lovable 2.0 added a scanner that only checks whether RLS policies exist.",
   "source_1_url": "https://mattpalmer.io/posts/2025/05/statement-on-CVE-2025-48757/",
   "source_1_publisher": "Matt Palmer (researcher)",
   "source_1_date": "2025-05-29",
   "source_2_url": "https://securityonline.info/cve-2025-48757-lovables-row-level-security-breakdown-exposes-sensitive-data-across-hundreds-of-projects/",
   "source_2_publisher": "SecurityOnline",
   "source_2_date": "2025-06-10",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-05-22-gitlab-gitlab-duo-chat",
   "date": "2025-05-22",
   "date_basis": "first report",
   "company": "GitLab",
   "product": "GitLab Duo Chat",
   "victim": "Users",
   "agent_type": "Coding agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "1",
   "impact": "Hidden prompts in merge requests, commits, issues or code could make Duo leak private source code and confidential issues and inject untrusted HTML into answers.",
   "outcome": "Reported by Legit Security on 12 February 2025; GitLab patched Duo to stop rendering unsafe HTML tags pointing outside gitlab.com.",
   "source_1_url": "https://www.legitsecurity.com/blog/remote-prompt-injection-in-gitlab-duo",
   "source_1_publisher": "Legit Security",
   "source_1_date": "2025-05-22",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-04-14-anysphere-cursor-ai-email-support",
   "date": "2025-04-14",
   "date_basis": "first report",
   "company": "Anysphere (Cursor)",
   "product": "Cursor AI email support agent \"Sam\"",
   "victim": "Cursor users",
   "agent_type": "Customer-facing agent",
   "incident_type": "Wrong commitment or action",
   "harm": "Wrong action",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "yes",
   "severity": "1",
   "impact": "The AI support agent told users that logouts were due to a one-device-per-subscription policy that did not exist, prompting public complaints and cancellation threats.",
   "outcome": "Cofounder Michael Truell apologised on Hacker News, said the user was refunded, and blamed a backend session-security change; Cursor said AI drafts its first-line email replies.",
   "source_1_url": "https://www.wired.com/story/cursor-ai-hallucination-policy-customer-service/",
   "source_1_publisher": "Wired",
   "source_1_date": "2025-04-19",
   "source_2_url": "https://news.ycombinator.com/item?id=43683012",
   "source_2_publisher": "Hacker News",
   "source_2_date": "2025-04-14",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-03-18-aixbt-aixbt-autonomous-crypto-agent",
   "date": "2025-03-18",
   "date_basis": "incident",
   "company": "aixbt",
   "product": "aixbt autonomous crypto agent (via Simulacrum AI)",
   "victim": "aixbt",
   "agent_type": "Autonomous finance agent",
   "incident_type": "Financial loss",
   "harm": "Money lost",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "An attacker breached the agent's dashboard and queued two prompts that made it send 55.5 ETH, worth about $106,200, from its wallet.",
   "outcome": "The maintainer said core systems were unaffected; servers were migrated, keys swapped, dashboard access paused and attacker addresses reported to exchanges.",
   "source_1_url": "https://cointelegraph.com/news/hacker-breaches-ai-crypto-bot-aixbt-steals-55-eth",
   "source_1_publisher": "Cointelegraph",
   "source_1_date": "2025-03-19",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2025-02-07-openai-operator",
   "date": "2025-02-07",
   "date_basis": "first report",
   "company": "OpenAI",
   "product": "Operator",
   "victim": "Geoffrey A. Fowler (Washington Post)",
   "agent_type": "Browser or computer-use agent",
   "incident_type": "Wrong commitment or action",
   "harm": "Money lost",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "1",
   "impact": "Asked only to find cheap eggs, Operator charged the columnist's credit card US$31.43 for a dozen eggs delivered to his home without asking for confirmation.",
   "outcome": "OpenAI said Operator made a mistake and fell short of its safeguards, and that it was adding stricter confirmation requirements for transactions.",
   "source_1_url": "https://www.nzherald.co.nz/business/i-let-chatgpts-new-agent-manage-my-life-it-spent-55-on-a-dozen-eggs/YZB6UAFYIVCNBBFCN3ANROIV5U/",
   "source_1_publisher": "Washington Post (syndicated by NZ Herald)",
   "source_1_date": "2025-02-11",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2024-08-20-salesforce-slack-ai",
   "date": "2024-08-20",
   "date_basis": "first report",
   "company": "Salesforce (Slack)",
   "product": "Slack AI",
   "victim": "Users",
   "agent_type": "Workplace assistant agent",
   "incident_type": "Vulnerability disclosed",
   "harm": "Data leaked",
   "prompt_injection": "yes",
   "in_the_wild": "no",
   "postmortem": "no",
   "severity": "1",
   "impact": "An attacker who could post in a public channel could plant instructions that made Slack AI leak data, such as API keys, from private channels the attacker could not read.",
   "outcome": "Slack first called channel search intended behavior, then Salesforce said it deployed a patch and had no evidence of unauthorized access to customer data.",
   "source_1_url": "https://promptarmor.substack.com/p/data-exfiltration-from-slack-ai-via",
   "source_1_publisher": "PromptArmor",
   "source_1_date": "2024-08-20",
   "source_2_url": "https://www.theregister.com/2024/08/21/slack_ai_prompt_injection/",
   "source_2_publisher": "The Register",
   "source_2_date": "2024-08-21",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2024-06-17-mcdonald-s-ibm-automated-order-taker",
   "date": "2024-06-17",
   "date_basis": "first report",
   "company": "McDonald's / IBM",
   "product": "Automated Order Taker (drive-thru voice AI)",
   "victim": "McDonald's customers and franchisees",
   "agent_type": "Customer-facing agent",
   "incident_type": "Wrong commitment or action",
   "harm": "Wrong action",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "1",
   "impact": "McDonald's ended its IBM voice-ordering test in more than 100 US drive-thrus after the technology underperformed expectations.",
   "outcome": "A memo to franchisees said the system would be shut off no later than July 26, 2024; McDonald's said voice ordering remains part of its future.",
   "source_1_url": "https://www.nbcnewyork.com/news/business/money-report/mcdonalds-to-end-ai-drive-thru-test-with-ibm/5514924/",
   "source_1_publisher": "CNBC via NBC New York",
   "source_1_date": "2024-06-17",
   "source_2_url": "https://www.ciodive.com/news/mcdonalds-ibm-drive-thru-automation-voice-ordering-ai/719127/",
   "source_2_publisher": "CIO Dive",
   "source_2_date": "2024-06-18",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  },
  {
   "id": "2024-02-15-air-canada-air-canada-website-support",
   "date": "2024-02-15",
   "date_basis": "first report",
   "company": "Air Canada",
   "product": "Air Canada website support chatbot",
   "victim": "Jake Moffatt",
   "agent_type": "Customer-facing agent",
   "incident_type": "Legal or regulatory",
   "harm": "Legal liability",
   "prompt_injection": "no",
   "in_the_wild": "yes",
   "postmortem": "no",
   "severity": "2",
   "impact": "The chatbot told a grieving customer he could claim a bereavement fare retroactively; Air Canada refused, arguing the chatbot was a separate legal entity responsible for its own actions.",
   "outcome": "BC Civil Resolution Tribunal (Moffatt v. Air Canada) held the airline responsible for its chatbot and ordered it to pay Moffatt $812.",
   "source_1_url": "https://www.cbc.ca/news/canada/british-columbia/air-canada-chatbot-lawsuit-1.7116416",
   "source_1_publisher": "CBC News",
   "source_1_date": "2024-02-15",
   "source_2_url": "",
   "source_2_publisher": "",
   "source_2_date": "",
   "source_3_url": "",
   "source_3_publisher": "",
   "source_3_date": "",
   "added": "2026-10-04"
  }
 ]
}
