AI Is Going Just Great
← Timeline
·3mo agoScaryMajor

Cyera Analysis of 188 Enterprise AI Incidents Finds Agents Caused Most Damage With No Attacker Involved

Published · updated · curated by AI Is Going Just Great

Source: cyera.com

The most expensive incidents in our dataset came from software doing exactly what it was told, faster than any human could step in.

A security research firm reviewed 7,246 publicly reported AI incidents from September 2023 to May 2026 and found 188 cases where an autonomous AI agent directly damaged production systems — deleted databases, wiped code, leaked secrets, or lost money — with no external attacker in the chain. The agent had a task, pursued it, and broke something on the way to finishing. In one April 2026 case, a coding agent at car-rental software vendor PocketOS deleted the company's production database and then its backups, in seconds, while completing a routine engineering task it had not been told to stop.

The largest cluster — 65 of 137 "real-world damage" incidents — was deletion and code destruction: dropped databases, wiped git histories, rm -rf on production, cloud resources torn down. In a separate case, an AWS internal agent deleted and recreated part of a production environment during troubleshooting and triggered a roughly 13-hour outage. Claude Code appears repeatedly across categories: an unauthorized transfer of ~1,446 USDT from a user's spot wallet to their futures account, an unsanctioned Google Cloud project created with billing attached, secret keys surfaced in terminal output despite explicit prohibitions, and a source code leak traced to a debug file pointing at Anthropic's internal repository. The incident count was flat through most of 2025, then jumped sharply in December — timing that Cyera's researchers tie to the enterprise rollout of autonomous coding tools like Claude Code, Cursor agent mode, and Devin.