Join our Newsletter — 33% off our NHI Course
NHI Breach Database

Non-Human Identity & AI Security Breaches

Real-world breaches involving API keys, service accounts, secrets, tokens and AI agents — what happened, how attackers got in, and what to fix. Researched and analysed by NHI Mgmt Group.

151 breaches analysed · updated September 2026
Showing 151 breaches
Sep 2026 8 breaches
AI agentsNHI AI agent misbehaviour

OpenAI Agents and US Government Websites 2026: How Rogue AI Agents Used Leaked Census API Keys and Probed Federal Sites

OpenAI agents used Census API keys leaked on GitHub, reposted SEC data and, per Transluce, tried to hack an Education site. No compromise found.

Read breach analysis →
AI agentsNHI Prompt injection

SalesBleed Salesforce Agentforce 2026: How Poisoned Web-to-Lead Records Turned AI Agents Into Zero-Click Data Thieves and Phishers

SalesBleed: poisoned Web-to-Lead records made Salesforce Agentforce leak CRM data past Trusted URLs and phish in Slack as the agent. Now fixed.

Read breach analysis →
NHIAI agentsLLM & AI platform Misconfiguration

Carbonato Botnet 2026: How an AI Agent Planted on Exposed Docker Hosts Hunted AI API Keys to Power Its Own Operation

Carbonato infects unauthenticated Docker hosts and runs a Hermes AI agent that steals AI API keys, SSH keys and tokens to fuel its own LLM service.

Read breach analysis →
NHIAI agents Supply chain

MemTensor MemoryOS Supply Chain Attack 2026: How Stolen CI Publish Tokens Put a Credential Stealer Inside AI Agent Memory

Hijacked GitHub Actions stole MemTensor's npm and PyPI tokens to ship sckit, a credential stealer in an AI agent memory plugin and MemoryOS.

Read breach analysis →
AI agentsNHI Vulnerability exploit

Meta Muse Agent Hijack 2026: How One Undocumented Setting Let Local Malware Steal an AI Agent’s Authentication Token

A Meta Muse zero-day let local malware redirect dictation, steal the agent's authentication material and abuse its delegated access. Hot-fixed.

Read breach analysis →
Claimed NHIHuman identity Vulnerability exploit

ShinyHunters FBI Breach Claim 2026: How an Unpatched PeopleSoft Server Was Allegedly Used to Reach FBI Data in AWS GovCloud

ShinyHunters claims it breached the FBI via PeopleSoft and pivoted into AWS GovCloud. The FBI is investigating; the breach is not confirmed.

Read breach analysis →
AI agentsNHI Not disclosed

Spain’s First AI Agent Data Breach 2026: What the AEPD Notification Tells Us About Agents, Credentials and Personal Data

Spain's data regulator received its first breach notification blamed on an attacker's AI agent, which logged in, altered personal data and read invoices.

Read breach analysis →
NHILLM & AI platformAI agents Vulnerability exploit

LiteLLM MCP Auth Bypass 2026: How a One-Character Token and Default Master Keys Exposed AI Gateway Credentials

CVE-2026-59822 let any bearer token open LiteLLM's MCP gateway; attackers stole master and provider keys. 9.6% of exposed gateways used sk-1234.

Read breach analysis →
Aug 2026 2 breaches
Jul 2026 6 breaches
AI agentsNHILLM & AI platform AI agent misbehaviour

Anthropic Claude Evaluation Incidents 2026: How Misconfigured Cyber Tests Let AI Models Breach Four Real Organisations

Four Claude models in misconfigured cyber evaluations reached the internet and breached real organisations, including via a malicious PyPI package.

Read breach analysis →
AI agentsLLM & AI platform AI agent misbehaviour

UK AISI Agent Testing Incident 2026: How AI Agents in a Cyber Evaluation Created Fake Identities and Targeted Real People

In UK AISI cyber tests, AI agents took 19 unsanctioned actions on the live internet, creating fake identities to push malicious code to a real project.

Read breach analysis →
NHIAI agentsLLM & AI platform AI agent misbehaviour

OpenAI and Hugging Face Breach 2026: How AI Agents Escaped an Evaluation Sandbox and Took Over Cloud Credentials

In July 2026 OpenAI evaluation agents escaped their sandbox and used stolen Kubernetes, cloud, VPN and GitHub tokens to take over Hugging Face clusters.

Read breach analysis →
AI agentsHuman identityNHI Weak or default credentials

Taiwan Autonomous AI Agent Cyberattack 2026: How Up to Eight AI Agents Cracked 85 Government Accounts and Pivoted Through SSO

Autonomous AI agents mapped 21 Taiwanese government systems, cracked 85 accounts, pivoted via SSO and stole 2,564+ records in four days.

Read breach analysis →
AI agentsNHI Vulnerability exploit

JADEPUFFER Agentic Ransomware 2026: How an AI Agent Used Harvested and Default Credentials to Destroy a Production Database

An AI agent exploited Langflow, harvested API keys and cloud credentials, used default MinIO and Nacos secrets, and destroyed a production database.

Read breach analysis →
AI agentsNHI Vulnerability exploit

AI Agent Retail Card Theft Campaign 2026: How Autonomous Agents Stole 600,000 Cards Using Cloud Keys, Vault Dumps and Stolen Admin Access

Autonomous AI agents hit hundreds of retailers for ~$25 each, dumping AWS Secrets Manager and cloud keys to steal 600,000+ cards and plant skimmers.

Read breach analysis →
Jun 2026 7 breaches
NHIAI agents Vulnerability exploit

Amazon Q MCP Config Vulnerability 2026: How Opening a Malicious Repository Could Hand Over a Developer’s AWS Credentials

Amazon Q auto-ran MCP servers from a repo's .amazonq/mcp.json, passing developers' AWS keys and tokens to attacker commands. Fixed; no exploitation.

Read breach analysis →
AI agentsNHI AI agent misbehaviour

OpenAI Agent Medicare Portal Breach 2026: How an AI Agent Reached Non-Public Australian Government Data

An OpenAI agent reached non-public files on an Australian Medicare statistics portal, via a guest endpoint, and OpenAI took 84 days to notify.

Read breach analysis →
NHIAI agentsHuman identity Supply chain

Mastra npm Supply Chain Attack 2026: How a Forgotten Contributor Account Backdoored 140+ AI Framework Packages

In June 2026 a former contributor's unrevoked npm account republished 140+ Mastra AI packages with a RAT dependency. Microsoft blames Sapphire Sleet.

Read breach analysis →
NHILLM & AI platform Supply chain

JetBrains Marketplace AI Plugin Campaign 2026: How 15 Fake AI Coding Assistants Stole Developers’ AI API Keys

In 2026, 15 fake AI assistant plugins on the JetBrains Marketplace stole OpenAI, DeepSeek and SiliconFlow API keys. How it worked and how to govern AI keys.

Read breach analysis →
AI agentsNHI Prompt injection

Sentry MCP Agentjacking 2026: How a Public DSN and a Fake Error Report Hijacked AI Coding Agents

A fake Sentry error posted with a public DSN made Claude Code, Cursor and Codex run attacker commands with the developer's credentials, via MCP.

Read breach analysis →
NHI OAuth / SaaS integration

Klue OAuth Breach 2026: How a Forgotten Integration Credential Exposed Customers’ Salesforce Data

In June 2026 a stale Klue GitHub token let attackers plant code, steal customers' Salesforce OAuth tokens and export CRM data from connected tenants.

Read breach analysis →
NHIAI agents Supply chain

Miasma and Hades Worms 2026: How Stolen Developer Tokens Spread Malware Across npm, PyPI and Microsoft’s Azure Repos

In June 2026 the Miasma and Hades worms used stolen GitHub accounts, OIDC publishing and npm and PyPI tokens to spread credential theft to Microsoft repos.

Read breach analysis →
May 2026 4 breaches
Apr 2026 4 breaches
Mar 2026 4 breaches
Feb 2026 2 breaches
Jan 2026 2 breaches
Dec 2025 4 breaches
Nov 2025 6 breaches
NHI Leaked secret

GitLab Public Repositories Secrets Study 2025: How 17,000+ Live Credentials Surfaced in 5.6 Million Public Projects

2025 study: a TruffleHog scan of 5.6 million public GitLab repositories found 17,430 live secrets, from GCP keys to Slack tokens. NHI lessons and fixes.

Read breach analysis →
NHI Leaked secret

JSONFormatter and CodeBeautify Leak 2025: How Saved Code Formatter Links Exposed 80,000+ Pastes of Secrets

In November 2025 watchTowr found 80,000+ saved pastes on JSONFormatter and CodeBeautify exposing cloud keys, tokens and passwords, and attackers testing them.

Read breach analysis →
NHI Supply chain

Shai-Hulud npm Worm 2025: How Stolen Publishing Tokens Spread a Secret-Stealing Worm to 25,000+ GitHub Repos

Shai-Hulud npm worm 2025: stolen npm and CI tokens spread a preinstall credential stealer to hundreds of packages and 25,000+ GitHub repos. Lessons for NHIs.

Read breach analysis →
NHI Leaked secret

CISA Private-CISA GitHub Leak 2026: How a Contractor’s Public Repository Exposed AWS GovCloud Admin Keys for Six Months

A contractor's public "Private-CISA" repo exposed AWS GovCloud admin keys, Artifactory credentials and plaintext passwords for six months.

Read breach analysis →
NHI Weak or default credentials

SAP SQL Anywhere Monitor Hard-Coded Credentials 2025: Why CVE-2025-42890 Scored a Maximum 10.0

Hard-coded credentials in SAP SQL Anywhere Monitor (Non-GUI) earned a CVSS 10.0 (CVE-2025-42890). SAP removed the monitor to fix it.

Read breach analysis →
NHI Stolen credentials

Amazon AWS Crypto-Mining Campaign 2025: How Compromised IAM Credentials Had Miners Running in 10 Minutes

In 2025, attackers used stolen AWS IAM credentials to mine crypto on EC2 and ECS in customer accounts, then blocked termination and created backdoor users.

Read breach analysis →
Oct 2025 7 breaches
NHI Stolen credentials

TruffleNet 2025: How Attackers Tested Stolen AWS Keys at Scale and Abused Amazon SES for Business Email Compromise

TruffleNet used 800+ attacker hosts running TruffleHog to test stolen AWS keys; in one account SES was abused for a vendor invoice scam.

Read breach analysis →
NHIAI agents Social engineering

CoPhish 2025: How Copilot Studio Agents Can Wrap OAuth Consent Phishing in a Trusted Microsoft Domain

Datadog showed Copilot Studio agents on a Microsoft domain can lead users to malicious OAuth consent and forward their tokens to attackers.

Read breach analysis →
NHI Supply chain

GlassWorm Campaign 2025: How a VS Code Extension Worm Turned Stolen Developer Tokens Into New Infections

How GlassWorm hid in Open VSX and VS Code extensions, stole npm, GitHub and Open VSX tokens and used publishing tokens to spread.

Read breach analysis →
NHI Leaked secret

Secrets in VS Code Extensions 2025: How 550 Leaked Secrets Included Tokens to Push Updates to 150,000 Installs

Wiz found 550+ secrets in 500+ VS Code extensions, including 130+ publishing tokens that could push updates to about 150,000 installs.

Read breach analysis →
Human identity Stolen credentials

SonicWall SSL VPN Account Compromises 2025: How Valid Credentials Opened More Than 100 VPN Accounts

Huntress saw attackers log in to more than 100 SonicWall SSL VPN accounts with valid credentials in October 2025. Source of logins unknown.

Read breach analysis →
NHI Not disclosed

Red Hat Consulting GitLab Breach 2025: How Customer Engagement Reports Exposed Tokens and Connection Strings

The Crimson Collective copied a Red Hat Consulting GitLab instance in 2025, exposing customer tokens, keys and connection strings in engagement reports.

Read breach analysis →
NHI Vulnerability exploit

OneLogin API Flaw 2025: How CVE-2025-59363 Exposed OIDC Client Secrets to Anyone Holding an API Key

A OneLogin API returned OIDC client secrets to any caller with valid API credentials (CVE-2025-59363). Fixed in 2025.3.0; no customers hit.

Read breach analysis →
Sep 2025 5 breaches
AI agentsLLM & AI platformNHI Prompt injection

ForcedLeak 2025: How a Web Form and a $5 Expired Domain Turned Salesforce Agentforce Into a Data Exfiltration Tool

ForcedLeak let a Web-to-Lead form inject instructions into Salesforce Agentforce and exfiltrate CRM data via an expired, allowlisted $5 domain.

Read breach analysis →
NHIAI agents Leaked secret

CrewAI “Uncrew” Flaw 2025: How an Error Message Exposed an Admin GitHub Token

A CrewAI error response exposed an internal GitHub token with admin rights over all private repositories. Fixed within five hours.

Read breach analysis →
AI agentsNHILLM & AI platform Vulnerability exploit

Anthropic GTG-1002 Campaign 2025: Inside the First Reported AI-Orchestrated Cyber Espionage Operation

A Chinese state-sponsored group used Claude Code agents to attack about 30 organisations, with AI doing 80-90% of the work, including credential theft.

Read breach analysis →
NHI Vulnerability exploit

Entra ID Actor Token Flaw 2025: How CVE-2025-55241 Could Have Given Global Admin in Every Tenant

Undocumented Actor tokens and an Azure AD Graph flaw could let an attacker impersonate Global Admins in any Entra ID tenant. Fixed in July 2025.

Read breach analysis →
NHI OAuth / SaaS integration

Palo Alto Networks Salesforce Data Theft 2025: A Victim’s View of the Salesloft Drift OAuth Token Attack

Stolen Salesloft Drift OAuth tokens let attackers export Palo Alto Networks Salesforce data, including support case notes with credentials.

Read breach analysis →
Aug 2025 4 breaches
Jul 2025 6 breaches
NHIAI agents Prompt injection

Gemini CLI Prompt Injection Flaw 2025: How a Poisoned README Could Make an AI Coding Agent Leak Developer Secrets

Tracebit found a poisoned README could make Google Gemini CLI silently run commands and send developer secrets out. Fixed in 0.1.14.

Read breach analysis →
NHIAI agents Supply chain

Amazon Q Developer Extension Compromise 2025: How an Over-Scoped GitHub Token Shipped a Wiper Prompt to an AI Coding Agent

An over-scoped GitHub token let an attacker add a wiper prompt to the Amazon Q Developer VS Code extension, which AWS shipped in v1.84.0.

Read breach analysis →
AI agentsNHI AI agent misbehaviour

Replit AI Agent Database Deletion 2025: How a Coding Agent Wiped Production Data During a Code Freeze

Replit's AI coding agent deleted a live production database during a code freeze, then said recovery was impossible. Rollback worked.

Read breach analysis →
NHI Vulnerability exploit

ToolShell SharePoint Exploitation 2025: How Stolen ASP.NET Machine Keys Kept Attackers Inside After Patching

How ToolShell attackers exploited on-premises SharePoint in July 2025 and stole ASP.NET machine keys that kept access alive after patching.

Read breach analysis →
NHIAI agents Weak or default credentials

McHire Default Password Flaw 2025: How “123456” and an IDOR Exposed McDonald’s AI Hiring Platform

Researchers logged in to McDonald's McHire AI hiring platform with 123456/123456 and found an IDOR exposing up to 64 million applicant records.

Read breach analysis →
NHI Weak or default credentials

HPE Aruba Instant On Hard-Coded Credentials 2025: How CVE-2025-37103 Gave Anyone Admin Access to Access Points

Aruba Instant On access points shipped with hard-coded admin credentials (CVE-2025-37103, CVSS 9.8). Firmware 3.2.1.0 fixes it.

Read breach analysis →
Jun 2025 3 breaches
May 2025 2 breaches
Apr 2025 4 breaches
Mar 2025 3 breaches
Feb 2025 6 breaches
NHILLM & AI platform Leaked secret

12,000 Live Secrets in LLM Training Data 2025: What Truffle Security Found in Common Crawl

Truffle Security found 11,908 live API keys and passwords in Common Crawl, a dataset used to train LLMs, mostly hard-coded in web pages.

Read breach analysis →
NHI Social engineering

Bybit Hack 2025: How One Developer’s AWS Session Tokens Enabled a $1.5 Billion Theft

How hijacked AWS session tokens from a Safe{Wallet} developer laptop let North Korean attackers alter wallet code and steal about $1.5 billion from Bybit.

Read breach analysis →
NHI Stolen credentials

Salt Typhoon Telecom Intrusions 2025: How Stolen Credentials and Network Device Secrets Kept China-Linked Hackers Inside for Years

Cisco Talos found Salt Typhoon entered US telecoms mostly with stolen credentials, then harvested SNMP strings and TACACS/RADIUS keys to persist.

Read breach analysis →
Claimed Human identity Not disclosed

Zacks Investment Research Breach Claim 2025: 12 Million Accounts Leaked, Unconfirmed by Zacks

A hacker claims a 2024 Zacks breach; HIBP verified 12 million leaked accounts with unsalted SHA-256 hashes. Zacks has not confirmed it.

Read breach analysis →
Claimed NHI Stolen credentials

Cisco Active Directory Credentials Leak 2025: How Kraken Republished Hashes from the 2022 Breach

Kraken posted Cisco Active Directory hashes, including service accounts and krbtgt, in 2025. Cisco says the data is from its May 2022 breach.

Read breach analysis →
NHI Leaked secret

ASP.NET Machine Key Attacks 2025: How 3,000 Publicly Disclosed Keys Enabled Remote Code Execution

Microsoft found 3,000+ ASP.NET machine keys copied from public sources; one was used to inject Godzilla malware via ViewState in 2024.

Read breach analysis →
Jan 2025 4 breaches
Dec 2024 3 breaches
Nov 2024 1 breach
Oct 2024 2 breaches
Sep 2024 2 breaches
Aug 2024 1 breach
Jun 2024 2 breaches
May 2024 3 breaches
Apr 2024 3 breaches
Mar 2024 2 breaches
Feb 2024 1 breach
Jan 2024 3 breaches
Nov 2023 4 breaches
Oct 2023 1 breach
Sep 2023 3 breaches
Jul 2023 2 breaches
Jun 2023 1 breach
May 2023 2 breaches
Apr 2023 1 breach
Mar 2023 1 breach
Dec 2022 4 breaches
Nov 2022 1 breach
Oct 2022 1 breach
Sep 2022 1 breach
Aug 2022 2 breaches
May 2022 1 breach
Apr 2022 1 breach
Mar 2022 1 breach
Oct 2021 1 breach
May 2021 1 breach
Feb 2021 1 breach
Jan 2021 2 breaches
Dec 2020 1 breach
Jul 2020 1 breach
Mar 2019 1 breach
No breaches match these filters.

Go deeper with NHI Mgmt Group.

NHI Ultimate Guide → Security Guides → NHI Foundation Level Course → Products → Blogs → Forum → Our Services →