| Arup: Employee tricked into $25.6 million deepfake video call fraud |
2024-02-04 |
Consulting & Professional Services |
High
|
Arup |
Hong Kong |
— |
— |
| Air Canada: Tribunal holds airline liable for its chatbot’s false bereavement-fare promise |
2024-02-14 |
Transportation & Logistics |
High
|
Air Canada |
Canada |
— |
— |
| Character.AI: Company and Google settle wrongful-death suit over teen’s suicide |
2024-02-28 |
Technology |
Critical
|
Character.AI / Google |
United States |
— |
— |
| Microsoft: ‘EchoLeak’ zero-click flaw could have exfiltrated 365 Copilot data |
2025-06-12 |
Technology |
Low
|
Microsoft |
United States |
— |
— |
| SaaStr: Replit AI agent deletes production database during code freeze |
2025-07-18 |
Technology |
High
|
SaaStr |
United States |
— |
— |
| Perplexity: Comet AI browser prompt injection exposes user accounts to takeover |
2025-08-20 |
Technology |
Medium
|
Perplexity |
United States |
— |
— |
| Salesforce: Agentforce prompt injection flaw could exfiltrate CRM data |
2025-09-01 |
Technology |
Low
|
Salesforce |
United States |
— |
Salesforce |
| Google: Lawsuit alleges Gemini chatbot drove Florida man to suicide |
2025-10-02 |
Technology |
Critical
|
Google |
United States |
— |
Gemini |
| Anthropic: State-sponsored group jailbreaks Claude Code for cyber espionage |
2025-11-13 |
Other |
Critical
|
Anthropic (Claude Code) |
United States |
— |
Claude |
| Government of Mexico: Claude Code jailbroken to exfiltrate 195 million records |
2025-12-15 |
Government & Public Sector |
Critical
|
Government of Mexico |
Mexico |
GPT-4.1 |
Claude, OpenAI |
| Alibaba: Research AI agent covertly mined crypto and tunneled out of its training environment |
2025-12-31 |
Technology |
Medium
|
Alibaba |
China |
ROME (internal research model) |
— |
| Microsoft: ‘Reprompt’ prompt-injection flaw enabled single-click Copilot data theft |
2026-01-15 |
Technology |
Low
|
Microsoft |
United States |
— |
— |
| Adelphi University: Court overturns AI-detection cheating finding against student with autism |
2026-01-28 |
Education |
Medium
|
Adelphi University |
United States |
— |
— |
| Codeway: Misconfigured Firebase database exposed 300 million AI chat messages |
2026-01-29 |
Technology |
High
|
Codeway |
Turkey |
— |
Claude, OpenAI, Gemini |
| Amazon: AI coding agent triggers cascading order-system outages |
2026-03-05 |
Retail & E-commerce |
High
|
Amazon |
United States |
— |
— |
| Sears Home Services: Unsecured databases exposed 3.7 million AI chatbot logs and call recordings |
2026-03-17 |
Retail & E-commerce |
High
|
Sears Home Services |
United States |
— |
— |
| Meta: Internal AI agent exposes company and user data to unauthorized employees |
2026-03-20 |
Technology |
Medium
|
Meta |
United States |
— |
— |
| Anthropic: Claude models breach three organizations during security evaluations |
2026-04-01 |
Technology |
Critical
|
Anthropic |
United States |
Opus 4.7, internal research model |
Claude |
| Mercor: AI startup breached via LiteLLM supply-chain attack |
2026-04-02 |
Technology |
High
|
Mercor |
United States |
— |
— |
| Grafana Labs: ‘GrafanaGhost’ prompt-injection chain could have silently exfiltrated dashboard data |
2026-04-07 |
Technology |
Low
|
Grafana Labs |
— |
— |
— |
| Vercel: Third-party AI vendor breach exposes customer credentials via OAuth token theft |
2026-04-20 |
Technology |
Critical
|
Vercel |
United States |
— |
— |
| PocketOS: Cursor AI coding agent deletes production database and backups |
2026-04-25 |
Technology |
High
|
PocketOS |
United States |
Opus 4.6 |
Claude |
| xAI: Attacker uses Morse-code prompt injection to drain Grok-linked crypto wallet |
2026-05-04 |
Technology |
Medium
|
xAI |
United States |
Grok |
xAI |
| Braintrust: AI evaluation startup breach exposes customer API keys |
2026-05-05 |
Technology |
Medium
|
Braintrust |
United States |
— |
— |
| Character.AI: Pennsylvania sues over chatbot posing as a licensed psychiatrist |
2026-05-05 |
Healthcare |
Critical
|
Character.AI |
United States |
— |
— |