Security researchers demonstrated in March 2026 that an autonomous AI agent could breach Lilli, the internal generative AI platform operated by McKinsey and Company, within roughly two hours. PointGuard AI documented the incident, reporting that the agent obtained read and write access to millions of internal chatbot messages and to sensitive file records.
The case is one of several documented AI-linked data exposure events during the first half of 2026. In February, an independent security researcher reported a breach affecting Chat and Ask AI, a consumer application distributed through Google Play and the Apple App Store with more than 50 million users. The researcher stated that an exposed database made 300 million messages from over 25 million users accessible. The underlying cause was identified as a Firebase misconfiguration, a documented class of deployment error.
Separately, research published in February identified a vulnerability that permitted silent data leakage from ChatGPT conversations without user awareness or consent. OpenAI deployed a full fix on February 20, 2026, closing the unintended communication path.
Meta's AI chatbot was implicated in account compromise during the same period. Attackers abused the chatbot's password reset handling to have reset codes sent to attacker-controlled email addresses, hijacking Instagram accounts. Tens of thousands of accounts were affected before the access route was identified and closed.
The incidents share a common characteristic. In each case the underlying model behaved as designed while the surrounding deployment, storage or identity configuration created the exposure.
Source: PointGuard AI - https://www.pointguardai.com/ai-security-incidents/mckinsey-ai-chatbot-breach-exposes-millions-of-internal-messages