{
  "title": "AI Agent Incidents",
  "source": "https://github.com/basitalisandhu/ai-agent-incidents",
  "total": 88,
  "period": {
    "from": "2023-02",
    "to": "2026-09"
  },
  "by_year": {
    "2023": 11,
    "2024": 13,
    "2025": 32,
    "2026": 32
  },
  "by_type": {
    "vulnerability-disclosure": 48,
    "incident": 29,
    "threat-report": 11
  },
  "by_lens": {
    "surface": 51,
    "target": 21,
    "weapon": 16
  },
  "by_vector": {
    "indirect-injection": 27,
    "autonomous-ops": 12,
    "exploitation": 9,
    "excessive-agency": 6,
    "supply-chain": 6,
    "direct-injection": 4,
    "exposure/misconfig": 4,
    "nhi-secrets": 4,
    "extraction": 3,
    "generated-code": 3,
    "poisoning": 3,
    "social-engineering": 3,
    "retrieval-memory": 2,
    "availability": 1,
    "jailbreak": 1
  },
  "by_channel_in": {
    "chat message": 25,
    "none": 17,
    "web page": 11,
    "package": 9,
    "document": 8,
    "repo issue/pr": 8,
    "rules file": 3,
    "email": 2,
    "support ticket": 2,
    "tool description": 2,
    "calendar invite": 1
  },
  "by_authority": {
    "shell/exec": 38,
    "read-only": 15,
    "none": 9,
    "database": 7,
    "send-message": 7,
    "cloud-creds": 5,
    "write-repo": 5,
    "file-delete": 1,
    "payments": 1
  },
  "by_channel_out": {
    "code exec": 36,
    "disclosure-only": 14,
    "tool-call send": 12,
    "image/link fetch": 11,
    "file publish": 6,
    "data destruction": 4,
    "api-abuse": 3,
    "financial transfer": 1,
    "service-disruption": 1
  },
  "by_adversarial": {
    "yes": 71,
    "no": 17
  },
  "by_outcome": {
    "data-exfiltration": 33,
    "code-execution": 22,
    "information-disclosure": 13,
    "none-demo": 10,
    "data-destruction": 3,
    "financial-loss": 3,
    "fraud": 3,
    "service-disruption": 1
  },
  "by_status": {
    "confirmed": 88
  },
  "by_lens_and_type": {
    "surface": {
      "vulnerability-disclosure": 36,
      "incident": 14,
      "threat-report": 1
    },
    "weapon": {
      "threat-report": 9,
      "incident": 7
    },
    "target": {
      "vulnerability-disclosure": 12,
      "incident": 8,
      "threat-report": 1
    }
  },
  "by_year_and_lens": {
    "2023": {
      "surface": 6,
      "weapon": 0,
      "target": 5
    },
    "2024": {
      "surface": 7,
      "weapon": 2,
      "target": 4
    },
    "2025": {
      "surface": 23,
      "weapon": 5,
      "target": 4
    },
    "2026": {
      "surface": 15,
      "weapon": 9,
      "target": 8
    }
  },
  "with_cve": 25,
  "mapped": {
    "owasp_llm": 67,
    "owasp_agentic": 57,
    "mitre_atlas": 72,
    "any": 85
  },
  "by_owasp_llm": {
    "LLM01": 39,
    "LLM02": 24,
    "LLM03": 12,
    "LLM05": 4,
    "LLM06": 27,
    "LLM07": 1,
    "LLM08": 1,
    "LLM09": 3,
    "LLM10": 4
  },
  "by_owasp_agentic": {
    "ASI01": 26,
    "ASI02": 16,
    "ASI03": 7,
    "ASI04": 12,
    "ASI05": 17,
    "ASI06": 4,
    "ASI07": 1,
    "ASI10": 5
  },
  "by_mitre_atlas": {
    "AML.T0051.001": 32,
    "AML.T0050": 14,
    "AML.T0077": 10,
    "AML.T0016.002": 9,
    "AML.T0086": 9,
    "AML.T0051.000": 5,
    "AML.T0081": 5,
    "AML.T0093": 5,
    "AML.T0010.005": 4,
    "AML.T0011.003": 4,
    "AML.T0012": 3,
    "AML.T0040": 3,
    "AML.T0049": 3,
    "AML.T0054": 3,
    "AML.T0010.001": 2,
    "AML.T0011.001": 2,
    "AML.T0011.002": 2,
    "AML.T0052.000": 2,
    "AML.T0053": 2,
    "AML.T0055": 2,
    "AML.T0057": 2,
    "AML.T0060": 2,
    "AML.T0062": 2,
    "AML.T0080.000": 2,
    "AML.T0104": 2,
    "AML.T0105": 2,
    "AML.T0110": 2,
    "AML.T0010.003": 1,
    "AML.T0011.000": 1,
    "AML.T0021": 1,
    "AML.T0024.002": 1,
    "AML.T0029": 1,
    "AML.T0048.000": 1,
    "AML.T0052.001": 1,
    "AML.T0056": 1,
    "AML.T0058": 1,
    "AML.T0070": 1,
    "AML.T0072": 1,
    "AML.T0088": 1,
    "AML.T0098": 1,
    "AML.T0100": 1,
    "AML.T0101": 1,
    "AML.T0102": 1,
    "AML.T0108": 1
  },
  "by_tag": {
    "threat-report": 10,
    "coding-agent": 9,
    "indirect-prompt-injection": 8,
    "rce": 7,
    "markdown-image-exfiltration": 6,
    "mcp": 6,
    "autonomous-agent": 5,
    "no-adversary": 4,
    "one-click": 4,
    "supply-chain": 4,
    "agentic-cyber-operations": 3,
    "chatbot": 3,
    "excessive-agency": 3,
    "github-actions": 3,
    "npm": 3,
    "sandbox-escape": 3,
    "ssrf": 3,
    "agent-skills": 2,
    "ai-orchestrated-attack": 2,
    "approval-bypass": 2,
    "browser-agent": 2,
    "credential-harvesting": 2,
    "credential-theft": 2,
    "data-exposure": 2,
    "database-deletion": 2,
    "direct-prompt-injection": 2,
    "evaluation-escape": 2,
    "generated-code-execution": 2,
    "llm-misuse": 2,
    "mcp-config": 2,
    "memory-poisoning": 2,
    "persistence": 2,
    "pypi": 2,
    "slopsquatting": 2,
    "state-actor": 2,
    "stolen-credentials": 2,
    "tool-poisoning": 2,
    "vibe-coding": 2,
    "zero-click": 2,
    "acceptable-use": 1,
    "agent-to-agent": 1,
    "agentic-attacker": 1,
    "ai-augmented-attacker": 1,
    "ai-cli-abuse": 1,
    "allowlist-bypass": 1,
    "api-key-theft": 1,
    "api-tokens": 1,
    "argument-injection": 1,
    "auto-approve": 1,
    "availability": 1,
    "backdoor": 1,
    "bot-account": 1,
    "business-email-compromise": 1,
    "cache-poisoning": 1,
    "calendar-invite": 1,
    "camo-proxy": 1,
    "chatbot-platform": 1,
    "ci-permissions": 1,
    "cloud": 1,
    "cloud-metadata": 1,
    "code-interpreter": 1,
    "coding-assistant": 1,
    "command-allowlist": 1,
    "command-and-control": 1,
    "computer-use-agent": 1,
    "context-file": 1,
    "crm": 1,
    "cross-plugin-request-forgery": 1,
    "cross-tenant": 1,
    "csp-bypass": 1,
    "customer-service": 1,
    "cve-cluster": 1,
    "data-destruction": 1,
    "data-leak": 1,
    "ddos": 1,
    "deepfake": 1,
    "default-configuration": 1,
    "default-credentials": 1,
    "disputed-cve": 1,
    "distillation": 1,
    "dns-exfiltration": 1,
    "education": 1,
    "email": 1,
    "email-bcc": 1,
    "espionage": 1,
    "evaluation": 1,
    "expired-domain": 1,
    "exposed-database": 1,
    "exposed-endpoint": 1,
    "exposed-secrets": 1,
    "extortion": 1,
    "file-delete": 1,
    "file-write-tool": 1,
    "framework": 1,
    "fraud": 1,
    "fraudulent-accounts": 1,
    "fsmonitor": 1,
    "git-config": 1,
    "github-pull-requests": 1,
    "gmail": 1,
    "government": 1,
    "guardrail-bypass": 1,
    "hacking-as-a-service": 1,
    "hallucination": 1,
    "hidden-comment": 1,
    "hidden-text": 1,
    "hidden-unicode": 1,
    "hooks": 1,
    "host-header": 1,
    "ide": 1,
    "ide-extension": 1,
    "idor": 1,
    "in-the-wild": 1,
    "in-the-wild-exploitation": 1,
    "inference-server": 1,
    "infostealer": 1,
    "insecure-generated-code": 1,
    "issue-title-injection": 1,
    "jailbreak": 1,
    "just-in-time-malware": 1,
    "liability": 1,
    "library-bug": 1,
    "llm-in-malware": 1,
    "llmjacking": 1,
    "malicious-mcp-server": 1,
    "malicious-model": 1,
    "malicious-packages": 1,
    "malware-download": 1,
    "markdown-link-exfiltration": 1,
    "marketplace": 1,
    "mass-exploitation": 1,
    "memorization": 1,
    "misconfiguration": 1,
    "model-extraction": 1,
    "model-hub": 1,
    "multi-agent": 1,
    "npm-token": 1,
    "otp-theft": 1,
    "outage": 1,
    "package-hallucination": 1,
    "package-registry": 1,
    "papercut": 1,
    "path-traversal": 1,
    "path-validation": 1,
    "pdf": 1,
    "pickle-deserialization": 1,
    "plugin": 1,
    "plugin-marketplace": 1,
    "private-repository-leak": 1,
    "promptware": 1,
    "public-repository": 1,
    "pwn-request": 1,
    "rag": 1,
    "reputational": 1,
    "reverse-shell": 1,
    "row-level-security": 1,
    "rug-pull": 1,
    "rules-file": 1,
    "sanitizer-race": 1,
    "scams": 1,
    "scoped-token": 1,
    "screenshots": 1,
    "second-order-injection": 1,
    "seo-phishing": 1,
    "service-side-exfiltration": 1,
    "settings-injection": 1,
    "sha-pinning": 1,
    "shadow-ai": 1,
    "shared-document": 1,
    "smart-home": 1,
    "sql-exfiltration": 1,
    "support-ticket": 1,
    "system-prompt-leak": 1,
    "teampcp": 1,
    "text-to-sql": 1,
    "threat-intelligence": 1,
    "token-exfiltration": 1,
    "toxic-agent-flow": 1,
    "training-data-extraction": 1,
    "tribunal-ruling": 1,
    "trust-bypass": 1,
    "trust-prompt": 1,
    "untrusted-repository": 1,
    "url-parameter": 1,
    "user-data": 1,
    "vector-store-filter": 1,
    "video-call": 1,
    "weak-credentials": 1,
    "web-search-tool": 1,
    "websocket": 1,
    "wiper": 1
  }
}
