Skip to content

SAP

Disclosed Jul 17, 20242 years agoUnverified

SAPwned: SAP AI Core flaws gave researchers access to customer cloud keys and AI artifacts

Wiz researchers ran malicious training jobs on SAP AI Core and chained isolation flaws to gain cluster admin rights, read and modify SAP container images and artifacts, and reach customers' private files and AWS, Azure and HANA credentials. SAP fixed the issues and Wiz said no customer data was compromised.

What is known

People affectedNot stated in the sources we have
DisclosedJul 17, 2024
AttackExposed data
Data exposedCredentials and tokens, API keys, Training data
SectorTech · DE
StatusUnverified: not yet confirmed by an official notice, a filing or the organization

Sources

Notices filed

WhereFiledPeople
ResearchtotalJul 17, 2024

Other breaches at SAP

BreachAffected
Official SAP npm packages trojanized to steal developer credentialsApr 294 months agoSupply chainUnverifiedUnknown
History of this record
  • 2026-09-25 · added · seed source

First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.

Everything about SAP

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.