Exfiltration
What data left through an agent?
11 records of kind exfiltration are on the Agent Incident Ledger as of September 2026: 9 verified, 2 reported, 0 announced, 0 absent, 0 open. By jurisdiction: United States 8, Global 3.
Exfiltration
11 records, newest first
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
CoSnitch, where an injected instruction wrote itself into a copilot's persistent memory and re armed every session
United States · verified 15 September 2026
The research states the injected instruction remains active in every future session for that user unless the user manually navigates to memory settings and deletes it.
SearchLeak, where a crafted link made an enterprise copilot search the victim's own mailbox and push the results out
United States · verified 15 September 2026
The research states that the copilot interprets the query parameter as instructions and searches the victim's mailbox.
GrafanaGhost, where stored data became an instruction and the assistant posted observability data to an external server
Global · verified 15 September 2026
The research states that because the exploit ignores model restrictions and operates autonomously, sensitive enterprise data can be leaked silently.
A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint
United States · verified 15 September 2026
The research states that the code execution sandbox restricts outbound network access but allows connections to the vendor's own interface endpoint.
A cloned MCP server silently copied every email agents sent through it
Global · verified 15 September 2026
The Register reports that a backdoored version added a blind copy of every message to an attacker controlled address.
Audit logs and token revocation contained a stolen agent integration, after its permissions had already been abused
United States · verified 15 September 2026
Google reports that on 20 August 2025 the vendor, working with the platform, revoked all active access and refresh tokens for the agent application.
A hiring chatbot's administrator console opened to a default password and let researchers read applicant chats
United States · verified 15 September 2026
The researchers write that they entered the same six digit string as username and password and were immediately logged in.
ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud
United States · verified 15 September 2026
Radware states that the deep research agent, executing in the vendor's cloud, performed the sensitive data exfiltration autonomously from those servers.
EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot
United States · verified 15 September 2026
Microsoft's advisory for CVE-2025-32711 states the vulnerability has already been fully mitigated and that there is no action for users of the service to take.
Malware in the Nx packages drove developers' own AI command line agents to hunt for secrets
Global · verified 15 September 2026
The Nx postmortem states that on 26 August 2025 malicious versions of several Nx packages were published to npm.
Every surface
Cut the ledger another way
By kind
By jurisdiction
Cite this page
Free to reuse under CC BY 4.0, with attribution.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), exfiltration: agent incident ledger.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). Exfiltration: Agent Incident Ledger. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/kinds/exfiltration
- MLA
- "Exfiltration: Agent Incident Ledger." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/kinds/exfiltration.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "Exfiltration: Agent Incident Ledger." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/kinds/exfiltration.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/kinds/exfiltration
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.