Every event of this shape, as it happens.

Published incidents where an AI agent reached data across systems. Dated, sourced, no commentary.

What has already happened, most recent first.

  • Sep 2026

    SalesBleed (Salesforce Agentforce)

    Instructions hidden in a lead submitted through a public Web-to-Lead form made Agentforce query account records, including deal sizes, with the asking employee’s own permissions. The agent then sent them out through a web address its URL filter missed, or through Slack’s link previews, with no click needed. A third flaw let the agent post unattributed Slack messages without confirmation. Reported June 2026, all three patched by 21 September.

    Zenity Labs

  • Jun 2026

    SearchLeak, CVE-2026-42824 (M365 Copilot Enterprise)

    A chain of three weaknesses turned enterprise search into an exfiltration path. One click on a genuine Microsoft link made Copilot search the victim’s own mailbox and files, then send the results out through an image URL. CVSS 9.1. Patched server-side.

    CVE-2026-42824

  • Mar 2026

    Double Agents (Google Vertex AI)

    The service agent provisioned by default for Agent Engine deployments carried excessive permissions by design. A compromised agent could read every storage bucket in the project, not only its own, and reach Google-internal registries. Defaults adjusted, no known exploitation.

    Unit 42

  • Feb 2026

    Teams Copilot, Microsoft incident CW1226324

    Copilot drew context from HR investigation channels, legal-hold discussions and executive compensation threads wherever a user’s access was broad enough. Staff received AI summaries of disciplinary matters and planning nobody intended them to see. Behaviour patched. Reported by secondary sources, and the incident ID is not confirmed at Microsoft.

    Secondary reporting

  • Aug 2025

    Salesloft Drift / Salesforce

    Attackers took the OAuth tokens held by Drift, an AI chat agent wired into Salesforce, and exported records from more than 700 organisations over ten days. All Drift tokens revoked, the app pulled from AppExchange, Drift taken offline, a FINRA alert to member firms.

    Salesforce / FINRA

None of these was a broken control. Every one of them was permitted.

No entry above is a break-in. In each case the agent asked systems that answered correctly, for an identity those systems accepted.

That is the shape worth watching for. The report will say the permissions were misconfigured, or that a default was too broad, or that a connector inherited more than anyone intended. All three are the same finding: nothing was asked to authorize the answer.

Find out what your agents can already reach before somebody else does.

Contact sales

Fill out the form and we will be in touch.

Start with a scan

Ready to find out what your agents can reach before somebody else does?

Tell us a bit about your setup and we will be in touch.