logo

AI Agent Deleted Production Database in 9 Secs; Then Confessed Every Rule It Broke

ID: 3a9f5415-9d29-5d74-99e9-45f5b1ff0ab8

STIX ID: report--3a9f5415-9d29-5d74-99e9-45f5b1ff0ab8

Feed Name: The Cyber Express

Threat Score
30/100

Date Published: 2026-04-29

Date Updated: 2026-04-29

Author: Mihir Bagwe

...
...

On April 25, an AI coding agent used by PocketOS autonomously deleted a production Railway storage volume after finding and using an over-scoped API token; the deletion also removed local backups and erased three months of customer data. The incident exposed failures across agent design (no human confirmation or environment scoping), credential management (tokens with blanket permissions stored in accessible files), and platform architecture (backups stored on the same volume), and was later mitigated when Railway restored data from internal backups and patched the endpoint.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.