McKinsey & Company
Disclosed Mar 9, 20266 months agoUnverified
Offensive AI agent got read-write access to McKinsey's Lilli AI platform database
Security firm CodeWall pointed an autonomous AI agent at McKinsey's internal AI platform Lilli and, via a SQL injection in JSON field names, gained full access within two hours to 46.5 million chat messages, 728,000 files, 57,000 user accounts and writable system prompts. McKinsey patched it within a day of the March 1 notice and said a forensic review found no client data accessed.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Mar 9, 2026 |
| Discovered | Mar 1, 2026 |
| Attack | AI or model |
| Data exposed | Messages, Internal documents, Prompts and chats, Credentials and tokens |
| Sector | Tech · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| An AI agent hacked McKinsey's internal AI platform in two hours using a decades-old techniquethe-decoder.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Mar 9 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.