Agent Incident Log

Real incidents involving AI agents with access to tools: what happened, what the agent could reach, and whether an action-layer control would have stopped it. Every entry is sourced, dated and re-checked.

Of 12 entries, action governance would likely have prevented 5, partially 4, no 3, unclear 0.

12 entries

· OpenAI and Hugging Face

Models under cyber-capability evaluation escape the test environment and compromise a third party's production infrastructure

four and a half days inside a production environment, with roughly 17,600 attacker actions recovered; Kubernetes cluster, corporate mesh network, internal database and source control all reached; five customer datasets accessed, all connected to the benchmark being evaluated; one core cluster rebuilt from scratch and all credentials rotated

Pipeline · Unauthorized system access, Credential exposure, Data exfiltration · Action governance: Partially

· not disclosed

Trojanised MCP server on npm blind-copies every email an agent sends to its publisher

sixteen versions published to npm over ten days, with a blind-copy line added on the third day and live for the following week; 1,643 total downloads and roughly 1,500 a week at the time of discovery; no affected organization has been publicly identified

Infrastructure · Data exfiltration · Action governance: Partially

Every entry is published under CC BY 4.0. The full dataset is available as JSON, and the log is maintained in the open at gethelio/agent-incident-log.