Publish date
July 29, 2026
{x} minute read
Written by
Reviewed by
Table of contents

“The call is coming from inside the house.” It’s one of horror’s oldest lines, and you already know how the scene goes. The team scrambles, rechecks every firewall, audits every login, hunting for an intruder.

Then the trace comes back, and there isn’t one because there is no malware or forced entry. Just an employee, at their own desk, with their own login, who pasted a confidential spreadsheet into an unapproved AI tool to save 10 minutes before a deadline. It’s tempting to file that under mistake rather than breach, but the numbers say otherwise.

IBM's 2026 Cost of a Data Breach Report found that security incidents involving shadow AI (unapproved AI tools employees use without IT's knowledge) jumped to 43% this year, more than double last year's share. Those incidents cost organizations an average of $5.39 million, and nearly half (49%) resulted in data loss or compromise.

That's the part worth sitting with. Nothing about these incidents looks like an attack while it's happening because nothing was attacked. It's an employee under a deadline, not an adversary. They don't think of what they're doing as a breach; they think of it as getting through their to-do list faster. It's the pattern behind every entry on this list: 10 Shadow AI leaks where the security team went looking for a hacker, and found a coworker instead.

1. The engineers who pasted Samsung's secrets into ChatGPT

Date: March - April 2023 

Category: Source code exposure

Three Samsung semiconductor engineers had the same idea within 20 days of each other: paste code into ChatGPT to debug it faster, or to summarize a meeting recording instead of writing notes by hand. There was no intrusion to investigate and no malware to trace. However, proprietary source code, yield optimization data, and an internal recording simply became part of a public model’s training data the moment they hit send.

The fix: an enterprise AI gateway with prompt inspection that flags source code before it reaches an external model. At the time, Samsung banned generative AI company-wide within weeks. This was one of the first incidents to demonstrate that a company’s crown-jewel intellectual property could leave the building through a completely unremarkable channel, a browser tab, for instance. It's become the reference case cited in nearly every corporate generative AI policy written since.

2. The banker who wanted cleaner slides at CB Financial Services 

Date: May 2026

Category: Regulatory disclosure

An employee at CB Financial Services needed a customer presentation finished quickly and turned to an AI tool nobody in IT approved. No system was breached, and no credentials were stolen, but customer names, Social Security numbers, and dates of birth still went into the tool willingly.

The fix: a cloud access security broker policy blocking unsanctioned SaaS destinations, paired with Shadow AI discovery tools monitoring for unapproved web traffic, is the kind of control built to catch exactly this pattern. CB Financial’s case went on to settle a question boards had been quietly avoiding. Does an employee's AI shortcut count as a real breach? Its Securities and Exchange Commission Item 1.05 disclosure, the first ever triggered by unauthorized AI use rather than an external cyberattack, gave regulators an answer: yes. It now sits alongside ransomware and stolen credentials as a disclosable cybersecurity event.

3. The developer who clicked "Accept All Permissions" at Vercel

Date: April 2026 

Category: Open authorization (OAuth) compromise

A malware infection at Context.ai, an AI plugin used to speed up workflows, started the chain. But what turned a vendor problem into a company-wide incident was an OAuth token a Vercel employee had approved with sweeping, unreviewed permissions. Attackers used that access to exfiltrate customer environment variables and demand two million dollars in extortion.

The fix: automated OAuth consent monitoring, flagging, and revoking overprivileged tokens before they sit dormant for months. An employee pasting proprietary material into a chatbot is only one entry point now. The sprawl of AI plugins and integrations quietly granted standing access to production systems is another, and it’s now treated as a governance category worth auditing with the same rigor as employee access itself.

4. The contractors who saw everyone else's conversations at Meta 

Date: 2024-2025

Category: Vendor pipeline failure

Contractors hired to fine-tune Meta's generative AI models for safety and accuracy found something they weren't supposed to see. That is unredacted personal information, including full names, phone numbers, and home addresses, in up to 70% of chat logs one contractor reviewed. And nobody broke in to get that data.

The fix: automated classification and masking of personally identifiable information (PII), applied at the point of ingestion so no human reviewer ever sees a raw conversation. Instead, internal pipelines routed user conversations straight to contractor dashboards with no scrubbing step in between. This one is structural; it was an AI development pipeline exposing its users by design, illustrating why Shadow AI governance has to extend backward into how a company builds its own AI products, not just how employees use someone else's.

5. The cybersecurity chief who used the wrong tool at CISA

Date: January 2026

Category: Government data exposure

The interim director of the Cybersecurity and Infrastructure Security Agency (CISA) needed federal contracting documents reviewed quickly and uploaded at least four files marked “For Official Use Only” (FOUO) to public ChatGPT under a personal exception. The upload triggered the agency’s own security sensors and the U.S. Department of Homeland Security review. 

The fix: endpoint data loss prevention blocking uploads of classified or FOUO-marked files to unsanctioned AI domains, with no personal-use carve-out for anyone, is the exact control required for this scenario. This incident made headlines because the person who triggered it was also the person whose job was to prevent it. A reminder that Shadow AI discipline has to reach the top of the organizational chart, exemptions and all.

6. The contractor racing to help flood victims through Australia's Resilient Homes Program

Date: October 2025

Category: Government contractor exposure

A contractor working to process disaster relief applications for three thousand flood survivors under Australia’s Resilient Homes Program needed to sort the data faster. They uploaded an entire unredacted spreadsheet to ChatGPT, over twelve thousand rows of names, addresses, dates of birth, and sensitive medical details, all at once.

The fix: endpoint controls blocking browser upload dialogs from sending structured spreadsheet data to unapproved AI tools are built to catch exactly this kind of upload. This incident matters because it hit flood survivors who were already dealing with the aftermath of a disaster, whose private health information became collateral damage of someone else’s productivity shortcut. It’s a reminder that Shadow AI risk follows government contractors and vendors just as easily as employees, and that this program didn’t have the safeguards to catch it.

7. The AI research team that shared a little too much information at Microsoft

Date: June 2023

Category: Cloud misconfiguration

Microsoft’s own AI research division wanted to publish an open-source image recognition model for the research community. To share the files, a researcher generated an Azure access token scoped to “full control” of the entire storage account instead of a single folder. The token sat exposed on GitHub for three years, quietly granting access to 38 terabytes of unrelated data such as employee workstation backups, over 30,000 internal Teams messages, and private keys.

The fix: automated cloud security posture management, flagging overprivileged storage tokens before a public repository goes live. This incident is a useful counterexample to the rest of this list because while nobody pasted anything into a chatbot, the exposure resulted from the infrastructure behind the AI research itself. It's a clear illustration that AI initiatives inherit every existing cloud misconfiguration risk, and then some, since sharing open models often requires exactly the kind of broad access token that's easiest to overscope.

8. The venture capital partners who forgot the bot was still listening

Date: September 2024

Category: Meeting assistant overreach

A founder’s pitch call ended with a venture capital firm, or so he thought. Otter.ai’s notetaker, still connected after he left, captured the investors’ private post-meeting discussion about him and emailed the full transcript to every invitee, founder included.

The investors apologized, and the deal was canceled. Otter.ai now faces a 2025 lawsuit alleging its tools recorded meetings without every participant’s consent, in violation of California wiretap law. 

The fix: a meeting-bot governance policy, requiring explicit host approval for AI notetakers and an automatic disconnect the moment a host ends the call, is the safeguard this scenario points to. This entry opens up a category of risk unique on this list, since no employee pasted anything anywhere; an AI tool kept doing its job long after the humans in the room assumed it had stopped. Any company running meetings through an AI notetaker carries the same exposure.

9. The engineers who made their own legal team nervous at Amazon 

Date: 2023

Category: Source code exposure

Amazon developers debugging backend code found ChatGPT a faster way to work through problems. Amazon’s own legal team noticed the tool producing outputs that closely resembled internal, unpublished code and warned staff company-wide not to paste proprietary material into the tool.

The fix: an internal AI proxy, routing developer prompts through a layer that strips proprietary code signatures before they reach a third-party model, is the kind of control that removes the need for a warning after the fact. What makes this one notable is timing. An Amazon lawyer told employees in an internal Slack channel that ChatGPT's output had "already" started to closely resemble existing internal material, catching the exposure through pattern recognition rather than an external researcher or regulator. It's an early example of legal and compliance teams acting as a frontline defense against Shadow AI simply by noticing when an AI's answer knows a little too much.

10. The click that turned private ChatGPT chats into Google results 

Date: August 2025

Category: Search-engine exposure

OpenAI let users click “Share” on a ChatGPT conversation and, if they left one box checked, make it “discoverable.” Most people had no idea what that meant. By the time Search Engine Land reported it, a search for shared conversations was turning up sensitive business details, personal names, roles, and strategies, including one indexed chat that publicly listed a senior consultant's full name, age, and job description alongside her client work. This leak included proprietary strategies and client work, alongside people's PII.

The fix: a policy limiting AI conversations to an approved, access-controlled tool, paired with basic training on what "share" actually does in consumer AI products. Unlike every other entry on this list, this wasn’t one company’s mistake. It was thousands of individual share links, each assumed private, becoming searchable at once. This incident shows that even sharing a link, the single most ordinary action on the internet, can be the door left unlocked.