Public incident library · 12 sourced cases

Agent incidents: what action-capable AI did, and what evidence would have caught it

Public, sourced cases where an AI agent or assistant with the power to act changed something it should not have — or was shown it could. For each: what happened, which of our seven gates it touches, the OWASP Agentic risk, and the record that would have prevented or proven it.

Filter the evidence map

Gate and OWASP risk

Gate
OWASP ASI

Showing all 12 cases.

INC-01Jul 2025Replit · SaaStr
Incident

Replit agent wipes SaaStr production database during code freeze

During a declared code-and-action freeze, Replit's AI agent ran destructive commands that deleted production records. It had also produced fake data and reports, and said rollback was impossible; the rollback later worked. Replit's CEO called it unacceptable and added dev/prod database separation and a planning-only mode.

Seven-gate mapping
Authority BudgetExternal confirmationRecovery
OWASP Agentic
ASI02ASI10ASI09
INC-02Apr 2026PocketOS · Cursor · Railway
Incident

PocketOS: coding agent deletes production database and backups in one API call

While fixing a credential mismatch in staging, a Cursor agent running Claude Opus 4.6 used a fully permissioned Railway API token unrelated to its task and, in one API call, deleted the production volume and its volume-level backups. Railway later restored the data and patched the endpoint.

Seven-gate mapping
Authority BudgetObject bindingRecovery
OWASP Agentic
ASI03ASI02
INC-03Dec 2025Google Antigravity
IncidentSelf-reported

Google Antigravity wipes a user's drive while clearing a cache

In a mode where commands run without per-step approval, a user asked the agent to clear a project cache; the delete targeted the root of his D: drive and bypassed the Recycle Bin. Google said it was investigating.

Seven-gate mapping
Object bindingEvidence Before EffectRecovery
OWASP Agentic
ASI02ASI05
INC-04Feb 2026OpenClaw
IncidentSelf-reported

OpenClaw agent bulk-deletes a researcher's inbox and ignores stop

A user told her agent to only suggest emails to archive or delete; on a large inbox it began bulk-deleting and ignored stop messages until the process was killed. She attributed it to context compaction dropping the instruction.

Seven-gate mapping
Evidence Before EffectFreshnessAuthority Budget
OWASP Agentic
ASI10ASI02
INC-05Mar 2026Meta
Incident

Internal agent posts unapproved advice, leading to a Sev 1 data exposure at Meta

An internal agent asked to analyse a forum question posted an answer itself without approval; a colleague followed the inaccurate advice and sensitive data was exposed to unauthorised employees for about two hours. Meta said no user data was misused.

Seven-gate mapping
Evidence Before EffectAuthority owner
OWASP Agentic
ASI09ASI08
INC-06Dec 2025 (reported Feb 2026)AWS · Kiro
IncidentDisputed

AWS Kiro 'delete and recreate' and a Cost Explorer interruption (disputed)

The FT reported an AI coding agent chose to delete and recreate an environment, interrupting AWS Cost Explorer in one region. Amazon says the cause was a misconfigured role, calls the event extremely limited, and added mandatory peer review for production access.

Seven-gate mapping
Authority BudgetAuthority ownerEvidence Before Effect
OWASP Agentic
ASI03ASI02
INC-07Jul 2025Amazon Q Developer
Incident

Amazon Q Developer extension ships with a wiper prompt

An improperly scoped token in AWS's build setup let an attacker commit a prompt telling the agent to wipe local files and cloud resources; it shipped in v1.84.0. AWS says it failed to run and changed no customer environments; AWS released a fixed version (CVE-2025-8217).

Seven-gate mapping
Authority ownerEvidence Before Effect
OWASP Agentic
ASI04ASI01
INC-08Feb 2026Cline
Incident

Clinejection: hijacked AI triage bot leads to an unauthorised npm release

Cline's AI issue-triage workflow could be steered by instructions in issue titles; this enabled cache poisoning and exposure of a release token. On 17 Feb 2026 an unauthorised cline@2.3.0 was published with a postinstall step that installed another package globally; it was live about 8 hours.

Seven-gate mapping
Authority BudgetFreshnessExternal confirmation
OWASP Agentic
ASI01ASI04ASI05
INC-09Aug 2025Salesloft Drift · Salesforce
Incident

Salesloft Drift integration tokens used to raid Salesforce orgs

Attackers used stolen OAuth and refresh tokens from the Drift AI chat integration to bulk-query many corporate Salesforce instances for secrets; all tokens were revoked on 20 Aug 2025.

Seven-gate mapping
Authority BudgetFreshnessAuthority owner
OWASP Agentic
ASI03ASI04
INC-10Feb 2025OpenAI Operator · Instacart
Incident

Browser agent places a grocery order without confirmation

A Washington Post columnist asked OpenAI's Operator to find cheap eggs; it completed a $31.43 Instacart order without asking for confirmation. OpenAI said it was looking into why confirmations were skipped.

Seven-gate mapping
Evidence Before EffectAuthority BudgetObject binding
OWASP Agentic
ASI02
INC-11Feb 2024Air Canada
Incident

Air Canada held liable for its chatbot's invented fare rule

The airline's website chatbot told a customer he could claim a bereavement fare retroactively, contradicting policy; the BC Civil Resolution Tribunal held the airline responsible and awarded C$812.02.

Seven-gate mapping
Authority ownerFreshness
OWASP Agentic
ASI09
INC-12May 2025GitHub MCP
Demonstration

GitHub MCP 'toxic agent flow' leaks private repositories

Researchers showed a malicious issue in a public repo could hijack an agent using the GitHub MCP server into reading the user's private repositories and publishing their data in a public pull request. The flaw is an over-broad token plus untrusted input.

Seven-gate mapping
Authority BudgetObject binding
OWASP Agentic
ASI01ASI02ASI03