Real incidents involving AI agents with access to tools: what happened, what the agent could reach, and whether an action-layer control would have stopped it. Every entry is sourced, dated and re-checked.
Of 12 entries, action governance would likely have prevented 5, partially 4, no 3, unclear 0.
one member's confirmed class reservation cancelled without authorisation and not restorable, sending them to the back of the waitlist; booking limits bypassed by weeks to months on a single gym's platform
Chat agent · Unauthorized state change · Action governance: Likely
four and a half days inside a production environment, with roughly 17,600 attacker actions recovered; Kubernetes cluster, corporate mesh network, internal database and source control all reached; five customer datasets accessed, all connected to the benchmark being evaluated; one core cluster rebuilt from scratch and all credentials rotated
Pipeline · Unauthorized system access, Credential exposure, Data exfiltration · Action governance: Partially
84 malicious versions across 42 packages published in a six-minute window; all deprecated within 1 hour 43 minutes and removed from the registry within 4 hours 35 minutes
Pipeline · Credential exposure, Data exfiltration, Malicious code distribution · Action governance: Partially
production database and volume-level backups for a SaaS platform serving car rental operators; service degraded for roughly two days before the provider restored the data
Coding agent · Data destruction, Service disruption · Action governance: Likely
two malicious package versions live on PyPI for roughly 40 minutes; credentials harvested from systems that installed them; a downstream breach affecting a limited subset of one company's registered experts
Pipeline · Credential exposure, Data exfiltration · Action governance: No
roughly 52.4 million tokens, about 5 per cent of the token's supply, transferred in place of an intended payment of about 310 US dollars; the developer put the loss at approximately 450,000 US dollars
Chat agent · Financial loss · Action governance: Likely
sixteen versions published to npm over ten days, with a blind-copy line added on the third day and live for the following week; 1,643 total downloads and roughly 1,500 a week at the time of discovery; no affected organization has been publicly identified
Infrastructure · Data exfiltration · Action governance: Partially
production database holding records for more than 1,200 executives and 1,190 companies, deleted on the ninth day of a twelve-day platform evaluation; recovered manually by the customer after the agent reported that recovery was not possible
Coding agent · Data destruction, Unauthorized state change · Action governance: Likely
one release of a Visual Studio Code extension published to the marketplace and installable for roughly a week before withdrawal; the vendor states the injected instructions did not execute and that no service or customer environment was changed
Coding agent · Malicious code distribution · Action governance: Partially