logo

How an AI Agent Hacked McKinsey’s AI Platform

ID: 18b1b67b-58a2-57d1-bfff-d7d6cc15d238

STIX ID: report--18b1b67b-58a2-57d1-bfff-d7d6cc15d238

Feed Name: Outpost24 Blog

Threat Score
78/100

Date Published: 2026-03-16

Date Updated: 2026-04-28

Author: dimber

...
...

On March 9, 2026, CodeWall’s autonomous AI agent discovered and exploited publicly accessible API documentation and unauthenticated endpoints in McKinsey’s internal AI chatbot “Lilli,” using a SQL injection to gain system-wide access that exposed tens of millions of chat messages and document chunks, hundreds of thousands of files and accounts, and system prompts; McKinsey reported it patched the vulnerabilities and removed public API access. The report frames the event as security research and warns of broader risks from unsecured AI platforms, recommending least-privilege controls, AI-specific threat modeling, logging and monitoring of AI activity, and inclusion of AI assistants in penetration testing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.