Two organizations suffered data exposures tied directly to their AI chat systems within days of each other in early 2026, according to analysis published by the Wharton Accountable AI Lab. Both involved conversational data stored in plaintext behind databases that were left open to well known attack methods.
Cybersecurity researcher Jeremiah Fowler found three unprotected databases holding data from customer facing AI chatbots and voice agents operated by Sears Home Services. The databases carried no passwords and no encryption. They contained 3.7 million chat log transcripts, 1.4 million audio recordings, and more than 4 terabytes of plaintext data. Some recordings ran for hours and continued capturing household noise after calls ended. Fields included names, phone numbers, home addresses, email addresses, appliance details, and repair and delivery records. The databases were secured shortly after Fowler reported the finding.
On February 28, an autonomous offensive AI agent operated by CodeWall targeted Lilli, the internal generative AI platform McKinsey provides to tens of thousands of consultants. Running without human intervention or credentials, the agent located 22 unauthenticated API endpoints and exploited a SQL injection vulnerability to gain read and write access to the production database. In under two hours it reached 46.5 million plaintext chat messages, 728,000 confidential files, 57,000 user accounts, 3.68 million retrieval document chunks, and 95 writable system prompts governing how Lilli responds.
McKinsey responded quickly and reported no evidence of client data access beyond the researcher's test. The writable prompts drew particular attention because altering them would change the system's behavior across the firm without any code change.
Source: Wharton AI and Analytics Initiative - https://ai-analytics.wharton.upenn.edu/wharton-accountable-ai-lab/two-early-2026-ai-exposures-lessons-for-the-future-of-ai-and-data-governance/