Sensitive Data Exposed by Unsecured AI Systems

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

Legit Security's research reveals that hundreds of open-source LLM servers and vector databases are leaking sensitive corporate and personal data online. Companies integrating AI into workflows often neglect security, leading to exposure of emails, financial records, and API keys. Most affected servers have since been secured.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event describes actual misconfigurations of AI-related infrastructure (vector databases for GenAI) leading to the exposure of private and sensitive information. This constitutes a breach of confidentiality and a violation of privacy rights, meeting the criteria for an AI Incident.[AI generated]
AI principles
Privacy & data governanceRobustness & digital securityAccountabilityRespect of human rightsSafety

Industries
IT infrastructure and hostingDigital securityBusiness processes and support services

Affected stakeholders
BusinessGeneral public

Harm types
Human or fundamental rightsEconomic/PropertyReputational

Business function:
ICT management and information security

AI system task:
Interaction support/chatbotsContent generationReasoning with knowledge structures/planning


Articles about this incident or hazard