Every event of this shape, as it happens.
Published incidents where an AI agent reached data across systems. Dated, sourced, no commentary.
What has already happened, most recent first.
- Sep 2026
SalesBleed (Salesforce Agentforce)
Instructions hidden in a lead submitted through a public Web-to-Lead form made Agentforce query account records, including deal sizes, with the asking employee’s own permissions. The agent then sent them out through a web address its URL filter missed, or through Slack’s link previews, with no click needed. A third flaw let the agent post unattributed Slack messages without confirmation. Reported June 2026, all three patched by 21 September.
- Jun 2026
SearchLeak, CVE-2026-42824 (M365 Copilot Enterprise)
A chain of three weaknesses turned enterprise search into an exfiltration path. One click on a genuine Microsoft link made Copilot search the victim’s own mailbox and files, then send the results out through an image URL. CVSS 9.1. Patched server-side.
CVE-2026-42824
- Mar 2026
Double Agents (Google Vertex AI)
The service agent provisioned by default for Agent Engine deployments carried excessive permissions by design. A compromised agent could read every storage bucket in the project, not only its own, and reach Google-internal registries. Defaults adjusted, no known exploitation.
Unit 42
- Feb 2026
Teams Copilot, Microsoft incident CW1226324
Copilot drew context from HR investigation channels, legal-hold discussions and executive compensation threads wherever a user’s access was broad enough. Staff received AI summaries of disciplinary matters and planning nobody intended them to see. Behaviour patched. Reported by secondary sources, and the incident ID is not confirmed at Microsoft.
Secondary reporting
- Aug 2025
Salesloft Drift / Salesforce
Attackers took the OAuth tokens held by Drift, an AI chat agent wired into Salesforce, and exported records from more than 700 organisations over ten days. All Drift tokens revoked, the app pulled from AppExchange, Drift taken offline, a FINRA alert to member firms.
Salesforce / FINRA
None of these was a broken control. Every one of them was permitted.
No entry above is a break-in. In each case the agent asked systems that answered correctly, for an identity those systems accepted.
That is the shape worth watching for. The report will say the permissions were misconfigured, or that a default was too broad, or that a connector inherited more than anyone intended. All three are the same finding: nothing was asked to authorize the answer.