logo

AI vs AI: Agent hacked McKinsey's chatbot and gained full read-write access in just two hours

ID: 9990864c-c85a-5eb2-a705-cd5ddf975d64

STIX ID: report--9990864c-c85a-5eb2-a705-cd5ddf975d64

Feed Name: The Register (Security)

Threat Score
80/100

Date Published: 2026-03-09

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

CodeWall's autonomous AI agent discovered unauthenticated API endpoints and exploited an SQL injection in McKinsey's Lilli chatbot, reportedly gaining read/write access to production data (46.5M chat messages, 728K files, 57K accounts) and writable system prompts that could enable prompt poisoning; McKinsey patched the vulnerabilities quickly and says forensic review found no evidence of client-data access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.