AI Agent Security Incidents — Fencio Postmortem Database
A public record of autonomous AI agents that failed in production. Real incidents, real attack vectors — prompt injection, data exfiltration, excessive agency, and more.
- GitLab AI Gateway Flaw Allows Command Execution
- AI Phishing Targets Anthropic Exec and Ex-White House Official
- OpenAI Pauses Training Its Most Powerful Models After Rogue Agents Target Government
- OpenAI Agent Breaches Australian Health Service
- Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
- Meta Muse AI App Flaw Exposes Voice Prompts
- Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
- OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
- Browser Extension Hijacks Multiple AI Assistants
- OpenAI's malicious bot swarm attacked RubyGems
- Telegram Bot Exfiltrates Messages via HTML Export Flaw
- BengalSEO Poisons Bing Search Results
- Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident
- AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
- AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure
- Grok chat duped into swallowing injected instructions
- Cloudflare Workers Spectre Attack Leaks JWT
- Meta AI Agent Exposes Internal Data
- Attackers use AI-made code to hack critical infrastructure controllers
- OpenAI Overhauls Safety Protocols After Its AI Agents Went Rogue
- AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira
- Israel's Fake Think Tank
- AWS Key Exposure Leads to Charity Data Exfiltration
- 'Near-autonomous' AI agents attack Taiwan's nuclear safety agency
- Malicious LiteLLM Releases Expose 2,100+ Organizations
- RCE flaw in IBM's agentic AI platform under active exploitation
- Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project
- Leaked n8n API Tokens Exposed Live Instances to Credential Theft
- DeepSeek AI Agent Launches Autonomous Attacks
- Anthropic's Claude Breaches Real Organizations During Tests
- AI Image Prompt Injection Identified
- OpenAI and Hugging Face Model Evaluation Security Incident
- OpenAI agent swarm attacks Hugging Face
- AI music platform Suno exposes 55M users in data breach
- Frontier LLMs couldn't help Hugging Face fight off evil agents
- World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
- 54% of Enterprises Report AI Agent Security Incidents
- Word Worm Crawls into Copilot, Spreads Chaos
- Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory
- n8n Sandbox Escape Allows OS Command Execution
- 30 ClawHub Skills Co-opt AI Agents for Crypto Mining
- Vect Ransomware Wipes Data from LiteLLM Supply Chain Victims
- LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours
- AI Tools Empower North Korean Hackers to Steal Millions
- Cohere AI Sandbox Flaw Allows Root Code Execution
- Google Antigravity IDE Prompt Injection
- NGate Campaign Uses AI-Generated Code to Steal NFC Data
- Vercel Breached via Context.ai AI Platform
- LiteLLM Supply Chain Attack Hits 96 Million Monthly Downloads
- Autonomous AI Seizes Domain Admin Credentials
- Moltbook AI Agent Network Leaks Credentials
- Replit AI Deletes Production Database. Then Lies About It.
- Air Canada Loses in Court After Chatbot Invents Its Own Policy
- Google Suspends Gemini After It Reimagines History
- Chevrolet's Chatbot Agrees to Sell a $76,000 Truck for $1
- Lawyers Submit Six ChatGPT-Invented Court Cases. Judge Notices.
- Samsung Leaks Semiconductor Secrets to ChatGPT. Twice. Then Once More.
- ChatGPT Shows Users Each Other's Credit Cards