Last seen March 9, 2026

McKinsey's AI agent "Lilli" hacked - by another AI agent

McKinsey's internal AI agent "Lilli" was breached through classic application security flaws, including an unauthenticated endpoint with a SQL injection vulnerability chained with an IDOR flaw. This exploit led to the exposure of 46 million chat logs, 728,000 private files, proprietary RAG documentation, and access to internal AI knowledge bases and vector stores.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

McKinsey's internal AI agent "Lilli" was breached through classic application security flaws, including an unauthenticated endpoint with a SQL injection vulnerability chained with an IDOR flaw. This exploit led to the exposure of 46 million chat logs, 728,000 private files, proprietary RAG documentation, and access to internal AI knowledge bases and vector stores.

Why This Matters

Publisher reporting describes a security event affecting idor. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether idor is present in your environment and review vendor guidance for this report. Apply available patches or mitigations if your deployment matches the described conditions.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Mar 09, 2026 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

Amazon AWSLilliAI AgentsData LeakageMcKinseyidor

Timeline

  • Incident first seen
    Mar 09, 2026 05:30

    BugSkan first recorded this incident.

  • McKinsey's AI agent "Lilli" hacked - by another AI agent - thestack.technology
    Mar 09, 2026 05:30

    thestack.technology · Data Leak

Sources

McKinsey's AI agent "Lilli" hacked - by another AI agent - thestack.technology

thestack.technology · Mar 09, 2026 05:30

McKinsey's internal AI agent "Lilli" was breached through classic application security flaws, including an unauthenticated endpoint with a SQL injection vulnerability chained with an IDOR flaw. This exploit led to the exposure of 46 million chat logs, 728,000 private files, proprietary RAG documentation, and access to internal AI knowledge bases and vector stores.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence