Bot Gaffe bots gone wild, catalogued

Hacks & Breaches · February 2026Gaffe level: Rampage

An AI Agent Broke Into McKinsey's Chatbot and Ransacked It in Two Hours

In a red-team test with responsible disclosure, cybersecurity firm CodeWall's autonomous AI agent targeted McKinsey's internal Lilli chatbot, found 22 unauthenticated API endpoints, exploited SQL injection, and accessed 46.5 million chat messages plus confidential client files. A controlled test, not a real attack.

Source: The Register

failAI safetyred team

← All gaffes