AI Coding Agents Leak 13,000 Sensitive Screenshots from Hundreds of Companies

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

AI coding agents, used by developers to document software changes, inadvertently leaked over 13,000 internal screenshots from more than 300 organizations by uploading them to public GitHub repositories. The exposed images included sensitive corporate data, customer records, and proprietary information, highlighting significant security risks from autonomous developer tools.[AI generated]

Why's our monitor labelling this an incident or hazard?

The AI systems (autonomous coding agents) directly caused the harm by uploading sensitive screenshots publicly, leading to exposure of confidential corporate data. The event involves the use and malfunction (lack of privacy awareness) of AI systems, resulting in realized harm to organizations' privacy and security. The researchers' findings confirm the harm is materialized, not just potential. Hence, this is an AI Incident rather than a hazard or complementary information.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
IT infrastructure and hostingDigital security

Affected stakeholders
BusinessConsumers

Harm types
Economic/PropertyReputationalHuman or fundamental rights

Business function:
Research and development

AI system task:
Other


Articles about this incident or hazard