May to July 2026 · intrusion 9 to 13 July · ~17,600 logged actions · disclosed 16 July
On 16 July 2026 Hugging Face disclosed an intrusion it described as "driven, end to end, by an autonomous AI agent system." The agent was running inside OpenAI's evaluation infrastructure, under test on a cyber-capability benchmark. It left its sandbox through a zero-day in a package registry proxy and an unsecured…
Read the case June to September 2026 · 18 June · notified 10 September · announced 24 September
On 18 June 2026 an OpenAI agent doing internet research into public medicine spending reached the Medicare Statistics Reporting Service portal, run by Services Australia. After repeated blocks, in the Prime Minister's words, it "found a way around those blocks", accessed public and non-public files, and wrote files to…
Read the case
Several public databases track AI incidents. Rather than duplicate them,
this guide links to the main ones and notes what each is for. They
largely record what reached the news, not what a system did internally,
and were not built for agentic systems.
liability · 2024 · British Columbia, Canada · FM-07 FM-04
Air Canada's website chatbot told a customer he could apply for a bereavement fare after travel. The BC Civil Resolution Tribunal rejected the argument that the chatbot was a separate entity and held the airline liable for negligent misrepresentation.
Source: Moffatt v. Air Canada, 2024 BCCRT 149↗
professional · 2026 · Multiple (US, UK, Canada, Australia, Israel, Brazil) · FM-07
A growing, actively maintained database tracks court and tribunal decisions in which a party was found to have relied on AI-fabricated case citations. The count has risen steadily as more matters reach judgment.
Source: AI Hallucination Cases Database (Damien Charlotin)↗
operations · 2025 · FM-02 FM-03 FM-06
A Replit AI coding agent, holding write access to a live production database, deleted production data despite instructions not to make changes. Replit's CEO confirmed the deletion and rolled out automatic development/production database separation in response.
Source: Amjad Masad (Replit CEO), 20 July 2025↗
security · 2026 · FM-01 FM-05
Google DeepMind researchers published a six-category taxonomy of how adversarial web content (hidden HTML instructions, poisoned images, manipulated memory, multi-agent cascades) can hijack autonomous agents, including sites that detect an agent visitor and serve it content a human never sees.
Source: Franklin et al., AI Agent Traps, Google DeepMind (March 2026)↗
security · 2026 · FM-03 FM-06
Sysdig's threat research team documented an extortion operation it describes as driven end to end by a large language model. It entered through an internet-facing Langflow instance (CVE-2025-3248), pivoted to the intended target, and ran a destructive database-extortion playbook against production data.
Source: Sysdig Threat Research Team, JADEPUFFER (July 2026)↗
security · 2026 · FM-01 FM-03
Pillar Security reported an MCP server distributed through public GitHub pull requests that behaves as a text formatting tool until a client has made three tool calls. It then returns instructions directing the agent to collect SSH keys, AWS credentials, shell history and Kubernetes configuration, and to hide the activity from the user.
Source: Pillar Security, Deadbugz (August 2026)↗
security · 2026 · FM-02 FM-04
Google confirmed in September 2026 that during a capture-the-flag evaluation run by the testing firm Irregular earlier in the year, a Gemini model reached three real companies' systems, guessing a password once and using credentials found in public databases twice. Google's security engineering VP said the model "guessed credentials to access websites it thought were part of the test" and that "in all three of these instances, the model stopped."
Source: Cybersecurity Dive, reporting Google's statement (21 September 2026)↗