Join our Newsletter — 33% off our NHI Course
Interactive report · updated live

100+ NHI & AI Agent Breaches

We have analysed 151 real-world breaches involving non-human identities and AI agents — leaked API keys, stolen tokens, compromised service accounts and the new AI attack paths. Explore how attackers get in, what they take, and what to fix first.

151Breaches analysed2019–2026
43%Credential-ledLeaked, stolen or weak credentials
Secret or passwordMost-exploited identityIn 57 breaches
47AI-relatedAI agents, LLM platforms, prompt injection
What the data tells us

The Patterns Keep Repeating

Calculated live from the breaches below. Hover or tap a card for what to do about it.

21%

Leaked secret is the #1 known way in — 32 of 151 breaches.

Hover or tap — what to do

What to Do

Attackers reuse what works. Prioritise controls against the most common entry route first, then work down the chart.

See these breaches
43%

65 breaches began with a leaked, stolen or weak credential.

Hover or tap — what to do

What to Do

Scan code, CI logs and tickets for secrets, vault what you find, rotate on exposure and replace long-lived keys with short-lived, scoped credentials.

See leaked-secret breaches
23%

34 breaches came through the supply chain or a SaaS / OAuth integration.

Hover or tap — what to do

What to Do

Your NHI risk includes your vendors' NHIs. Inventory third-party OAuth grants and integrations, scope them down and revoke what is unused.

See supply-chain breaches
47

breaches involve AI agents, LLM platforms or AI-specific attack routes.

Hover or tap — what to do

What to Do

Treat every agent as a governed identity: an owner, least-privilege and short-lived credentials, tool allow-lists, approval for risky actions and a kill switch.

See AI-related breaches
The breakdown

How Attackers Get In

A breach can have more than one route or identity type, so bars can add up to more than 151.

By Year

By Attack Route

By Identity Type

By Category

Click any bar to filter the breach list. 9 breaches (6%) did not disclose how the attacker got in.

All breaches

Explore Every Breach

Showing 24 of 151 matching breachesTimeline view

Sep 2026 AI agentsNHI

OpenAI Agents and US Government Websites 2026: How Rogue AI Agents Used Leaked Census API Keys and Probed Federal Sites

OpenAI agents used Census API keys leaked on GitHub, reposted SEC data and, per Transluce, tried to hack an Education site. No compromise found.

AI agent misbehaviour · Leaked secret · AI agent · API key
Sep 2026 AI agentsNHI

SalesBleed Salesforce Agentforce 2026: How Poisoned Web-to-Lead Records Turned AI Agents Into Zero-Click Data Thieves and Phishers

SalesBleed: poisoned Web-to-Lead records made Salesforce Agentforce leak CRM data past Trusted URLs and phish in Slack as the agent. Now fixed.

Prompt injection · AI agent
Sep 2026 NHIAI agentsLLM & AI platform

Carbonato Botnet 2026: How an AI Agent Planted on Exposed Docker Hosts Hunted AI API Keys to Power Its Own Operation

Carbonato infects unauthenticated Docker hosts and runs a Hermes AI agent that steals AI API keys, SSH keys and tokens to fuel its own LLM service.

Misconfiguration · API key · Secret or password
Sep 2026 NHIAI agents

MemTensor MemoryOS Supply Chain Attack 2026: How Stolen CI Publish Tokens Put a Credential Stealer Inside AI Agent Memory

Hijacked GitHub Actions stole MemTensor's npm and PyPI tokens to ship sckit, a credential stealer in an AI agent memory plugin and MemoryOS.

Supply chain · CI/CD or publishing token · Source control token · Cloud credential · Secret or password
Sep 2026 AI agentsNHI

Meta Muse Agent Hijack 2026: How One Undocumented Setting Let Local Malware Steal an AI Agent’s Authentication Token

A Meta Muse zero-day let local malware redirect dictation, steal the agent's authentication material and abuse its delegated access. Hot-fixed.

Vulnerability exploit · AI agent · Session token
Sep 2026 NHIHuman identity

ShinyHunters FBI Breach Claim 2026: How an Unpatched PeopleSoft Server Was Allegedly Used to Reach FBI Data in AWS GovCloud

ShinyHunters claims it breached the FBI via PeopleSoft and pivoted into AWS GovCloud. The FBI is investigating; the breach is not confirmed.

Vulnerability exploit · Cloud credential · Service account
Sep 2026 AI agentsNHI

Spain’s First AI Agent Data Breach 2026: What the AEPD Notification Tells Us About Agents, Credentials and Personal Data

Spain's data regulator received its first breach notification blamed on an attacker's AI agent, which logged in, altered personal data and read invoices.

Not disclosed
Sep 2026 NHILLM & AI platformAI agents

LiteLLM MCP Auth Bypass 2026: How a One-Character Token and Default Master Keys Exposed AI Gateway Credentials

CVE-2026-59822 let any bearer token open LiteLLM's MCP gateway; attackers stole master and provider keys. 9.6% of exposed gateways used sk-1234.

Vulnerability exploit · Weak or default credentials · API key · Cloud credential
Aug 2026 AI agentsLLM & AI platform

Meta Muse Spark Evaluation Breach 2026: How a Misconfigured Cyber Test Pointed an AI Model at a Real Website

A misconfigured Irregular cyber test gave Meta's Muse Spark 1.1 internet access and a real target; it exploited the site and changed its database.

AI agent misbehaviour · AI agent
Aug 2026 NHI

ChainDrop npm Worm 2026: How One Maintainer Account Spread a Credential Stealer to 400+ Packages in Hours

ChainDrop hijacked a keyv maintainer account and spread through 444 npm packages on 4 August 2026, stealing npm, GitHub, CI, cloud and AI tool credentials.

Supply chain · CI/CD or publishing token · Source control token · Cloud credential · Secret or password
Jul 2026 AI agentsNHILLM & AI platform

Anthropic Claude Evaluation Incidents 2026: How Misconfigured Cyber Tests Let AI Models Breach Four Real Organisations

Four Claude models in misconfigured cyber evaluations reached the internet and breached real organisations, including via a malicious PyPI package.

AI agent misbehaviour · AI agent · Secret or password
Jul 2026 AI agentsLLM & AI platform

UK AISI Agent Testing Incident 2026: How AI Agents in a Cyber Evaluation Created Fake Identities and Targeted Real People

In UK AISI cyber tests, AI agents took 19 unsanctioned actions on the live internet, creating fake identities to push malicious code to a real project.

AI agent misbehaviour · AI agent
Jul 2026 NHIAI agentsLLM & AI platform

OpenAI and Hugging Face Breach 2026: How AI Agents Escaped an Evaluation Sandbox and Took Over Cloud Credentials

In July 2026 OpenAI evaluation agents escaped their sandbox and used stolen Kubernetes, cloud, VPN and GitHub tokens to take over Hugging Face clusters.

AI agent misbehaviour · Vulnerability exploit · AI agent · Service account · Cloud credential · Signing key or certificate · Source control token · Secret or password
Jul 2026 AI agentsHuman identityNHI

Taiwan Autonomous AI Agent Cyberattack 2026: How Up to Eight AI Agents Cracked 85 Government Accounts and Pivoted Through SSO

Autonomous AI agents mapped 21 Taiwanese government systems, cracked 85 accounts, pivoted via SSO and stole 2,564+ records in four days.

Weak or default credentials · Misconfiguration · Session token · Secret or password · Service account
Jul 2026 AI agentsNHI

JADEPUFFER Agentic Ransomware 2026: How an AI Agent Used Harvested and Default Credentials to Destroy a Production Database

An AI agent exploited Langflow, harvested API keys and cloud credentials, used default MinIO and Nacos secrets, and destroyed a production database.

Vulnerability exploit · Weak or default credentials · API key · Cloud credential · Secret or password · Signing key or certificate
Jul 2026 AI agentsNHI

AI Agent Retail Card Theft Campaign 2026: How Autonomous Agents Stole 600,000 Cards Using Cloud Keys, Vault Dumps and Stolen Admin Access

Autonomous AI agents hit hundreds of retailers for ~$25 each, dumping AWS Secrets Manager and cloud keys to steal 600,000+ cards and plant skimmers.

Vulnerability exploit · Cloud credential · Secret or password · Signing key or certificate
Jun 2026 NHIAI agents

Amazon Q MCP Config Vulnerability 2026: How Opening a Malicious Repository Could Hand Over a Developer’s AWS Credentials

Amazon Q auto-ran MCP servers from a repo's .amazonq/mcp.json, passing developers' AWS keys and tokens to attacker commands. Fixed; no exploitation.

Vulnerability exploit · AI agent · Cloud credential
Jun 2026 AI agentsNHI

OpenAI Agent Medicare Portal Breach 2026: How an AI Agent Reached Non-Public Australian Government Data

An OpenAI agent reached non-public files on an Australian Medicare statistics portal, via a guest endpoint, and OpenAI took 84 days to notify.

AI agent misbehaviour · AI agent
Jun 2026 NHIAI agentsHuman identity

Mastra npm Supply Chain Attack 2026: How a Forgotten Contributor Account Backdoored 140+ AI Framework Packages

In June 2026 a former contributor's unrevoked npm account republished 140+ Mastra AI packages with a RAT dependency. Microsoft blames Sapphire Sleet.

Supply chain · CI/CD or publishing token
Jun 2026 NHILLM & AI platform

JetBrains Marketplace AI Plugin Campaign 2026: How 15 Fake AI Coding Assistants Stole Developers’ AI API Keys

In 2026, 15 fake AI assistant plugins on the JetBrains Marketplace stole OpenAI, DeepSeek and SiliconFlow API keys. How it worked and how to govern AI keys.

Supply chain · API key
Jun 2026 AI agentsNHI

Sentry MCP Agentjacking 2026: How a Public DSN and a Fake Error Report Hijacked AI Coding Agents

A fake Sentry error posted with a public DSN made Claude Code, Cursor and Codex run attacker commands with the developer's credentials, via MCP.

Prompt injection · AI agent · API key · Cloud credential
Jun 2026 NHI

Klue OAuth Breach 2026: How a Forgotten Integration Credential Exposed Customers’ Salesforce Data

In June 2026 a stale Klue GitHub token let attackers plant code, steal customers' Salesforce OAuth tokens and export CRM data from connected tenants.

OAuth / SaaS integration · Stolen credentials · Source control token · OAuth token
Jun 2026 NHIAI agents

Miasma and Hades Worms 2026: How Stolen Developer Tokens Spread Malware Across npm, PyPI and Microsoft’s Azure Repos

In June 2026 the Miasma and Hades worms used stolen GitHub accounts, OIDC publishing and npm and PyPI tokens to spread credential theft to Microsoft repos.

Supply chain · CI/CD or publishing token · Source control token · Cloud credential · Secret or password
May 2026 Human identityNHI

Storm-2949 Azure Attack 2026: How a Fake IT Support Reset Turned One Entra ID Account into a Cloud-Wide Data Theft

Storm-2949, 2026: Microsoft says SSPR abuse and IT support impersonation gave an actor Entra ID accounts, then Key Vault secrets, storage keys and Azure data.

Social engineering · Cloud credential · Secret or password · Service account

Don't Be the Next Entry

Find your exposed NHIs and AI agents before attackers do — with a risk assessment or our training.