Skip to content

McKinsey & Company

Disclosed Mar 9, 20266 months agoUnverified

Offensive AI agent got read-write access to McKinsey's Lilli AI platform database

Security firm CodeWall pointed an autonomous AI agent at McKinsey's internal AI platform Lilli and, via a SQL injection in JSON field names, gained full access within two hours to 46.5 million chat messages, 728,000 files, 57,000 user accounts and writable system prompts. McKinsey patched it within a day of the March 1 notice and said a forensic review found no client data accessed.

What is known

People affectedNot stated in the sources we have
DisclosedMar 9, 2026
DiscoveredMar 1, 2026
AttackAI or model
Data exposedMessages, Internal documents, Prompts and chats, Credentials and tokens
SectorTech · US
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalMar 9
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about McKinsey & Company

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.