Offensive-security firm CodeWall pointed an autonomous AI agent at McKinsey’s internal generative-AI platform, Lilli, and within two hours it had gained full read/write access to the platform’s production database by chaining an SQL injection flaw with unauthenticated API endpoints — 22 of more than 200 documented endpoints required no authentication at all. The exposed database held roughly 46.5 million internal chat messages, 728,000 file records, and 57,000 user accounts covering topics such as corporate strategy, M&A discussions, and client engagements. McKinsey patched the exposed endpoints within 24 hours of responsible disclosure and said it found no evidence that any unauthorized party had accessed client-confidential data.