Shadow AI Incidents
Real-world incidents, exposures and vulnerabilities that show what can happen when AI adoption moves faster than security, governance and data protection.
Continuously updated resource · Last reviewed August 2026
Incident Library
Explore real-world cases and the security lessons they reveal for organizations adopting generative AI, AI assistants, integrations and AI-enabled workflows.
11 incidents shown
Samsung Employees Shared Sensitive Information With ChatGPT
Samsung semiconductor employees reportedly entered proprietary source code, equipment-related information and confidential meeting material into ChatGPT during work tasks.
View incident
What happened?
Three separate incidents were reported shortly after Samsung allowed employees in its semiconductor business to use ChatGPT. Reported use cases included debugging and optimizing source code and converting a confidential meeting recording into notes.
Why it matters
A normal productivity workflow can become a data-exfiltration path when employees send proprietary information to an external AI service.
SecurePledge takeaway
AI controls should inspect the prompt itself—not just whether an employee accessed an AI website. Detect sensitive data, apply redaction or blocking policies, and maintain prompt-level audit visibility.
View source ↗ChatGPT Bug Exposed Other Users’ Chat Titles and Limited Payment Data
OpenAI disclosed a bug that allowed some users to see titles from another user's chat history and may have exposed limited payment-related information for a small subset of ChatGPT Plus users.
View incident
What happened?
OpenAI took ChatGPT offline after identifying a bug in an open-source library. The company said some users could see other users' chat titles and that limited payment-related information may have been visible during a specific nine-hour window.
Why it matters
Sensitive information sent to an external AI service ultimately depends on the provider's own security controls and isolation mechanisms.
SecurePledge takeaway
Combine AI vendor risk assessment with controls that reduce the amount of sensitive information sent to external AI systems in the first place.
View source ↗DeepSeek Database Exposed Chat History, Secrets and Operational Data
Wiz researchers discovered a publicly accessible DeepSeek database containing more than one million lines of log streams, including chat history, secret keys and backend information.
View incident
What happened?
The database was accessible without authentication and reportedly allowed extensive access to the underlying data and database operations. The exposure was secured after disclosure to DeepSeek.
Why it matters
Organizations can introduce AI risk through the security posture and infrastructure of the AI providers they use, not only through employee behavior.
SecurePledge takeaway
AI governance should include approved-tool policies, vendor assessment and controls that protect sensitive information before it reaches an external AI platform.
View source ↗Microsoft AI Research Data Exposure Reached Approximately 38 TB
A misconfigured Azure storage link used by Microsoft's AI research team exposed a much larger private data set than the team intended to share.
View incident
What happened?
The team intended to share AI training data, but an overly permissive access token provided access to considerably more information than intended, including internal data and credentials.
Why it matters
AI development depends on large datasets, cloud storage and automation. A single configuration mistake can expose data well beyond the intended training corpus.
SecurePledge takeaway
AI security extends beyond chat prompts into datasets, cloud storage, model infrastructure and development pipelines. Governance needs to cover the entire AI lifecycle.
View source ↗Ontario Hospital AI Transcription Tool Captured a Meeting Containing PHI
An Ontario hospital reported that an AI-powered transcription tool inadvertently recorded a virtual hepatology rounds meeting containing protected health information.
View incident
What happened?
According to Ontario's privacy regulator, a former physician's personal Otter.ai account remained connected to a personal calendar. The tool accessed the meeting invitation and recorded the meeting even though the hospital had not approved the transcription tool.
Why it matters
AI exposure can happen through integrations and connected applications—not only when an employee deliberately pastes data into a chatbot.
SecurePledge takeaway
Healthcare organizations need visibility into AI applications, integrations and permissions, with controls for sensitive-data interactions.
View source ↗Salesloft Drift Compromise Affected Hundreds of Organizations
A compromise involving the Salesloft Drift AI chat integration led to theft and misuse of OAuth tokens connected to enterprise systems.
View incident
What happened?
FINRA reported that attackers stole OAuth authentication tokens associated with the Drift integration and used them to access connected customer environments, including Salesforce and Google Workspace and, in some cases, Slack.
Why it matters
AI applications increasingly connect to CRM, messaging, cloud and business systems. A compromised integration can become a route into enterprise data.
SecurePledge takeaway
AI governance needs to cover connected applications, APIs, OAuth permissions and non-human identities—not just employee chatbot usage.
View source ↗Microsoft 365 Copilot Vulnerability Enabled Potential Information Disclosure
CVE-2025-32711 was recorded for Microsoft 365 Copilot as an AI command-injection vulnerability that could allow an unauthorized attacker to disclose information over a network.
View incident
What happened?
The vulnerability demonstrated how malicious content can interact with AI assistants and influence how connected information is processed. The vulnerability was tracked in the National Vulnerability Database and Microsoft issued an advisory.
Why it matters
Enterprise AI assistants can operate with access to organizational information. Vulnerabilities in the AI interaction layer can therefore create data-disclosure risks.
SecurePledge takeaway
AI security requires layered controls around access, prompts, connected data and policy enforcement—not just endpoint protection.
View source ↗Italy’s Data Protection Authority Blocked DeepSeek
Italy's Garante ordered an immediate limitation on the processing of Italian users' personal data by DeepSeek and opened an investigation.
View incident
What happened?
On January 30, 2025, the Italian Data Protection Authority said the information provided by DeepSeek about its processing was insufficient and ordered an immediate limitation on processing Italian users' data.
Why it matters
AI adoption creates privacy and compliance questions alongside cybersecurity risks, particularly when organizations use external AI services to process personal information.
SecurePledge takeaway
AI governance should connect security, privacy and compliance. Organizations need clear controls over what data can be sent to which AI services.
View source ↗Google Warned Employees Not to Enter Confidential Material Into AI Chatbots
Google cautioned employees about entering confidential material into AI chatbots, including its own Bard, while continuing to develop and promote generative AI.
View incident
What happened?
Public reporting in June 2023 described Google's internal guidance around confidential information and chatbot use. The company confirmed the caution as part of its existing information-safeguarding policies.
Why it matters
The case highlights the tension between rapid AI adoption and traditional confidentiality controls.
SecurePledge takeaway
Employee guidance is important, but organizations can strengthen it with technical controls that detect sensitive information and enforce AI policies at the point of interaction.
View source ↗Samsung Restricted Generative AI After Internal Data Exposure
After reports of employees entering sensitive information into ChatGPT, Samsung introduced restrictions on generative AI use and warned employees about the security risks.
View incident
What happened?
Samsung's internal response followed reports that employees had entered confidential source code and other internal information into ChatGPT.
Why it matters
Blocking AI can reduce immediate exposure, but it can also push employees toward less visible shadow AI workflows.
SecurePledge takeaway
A more sustainable model is governed AI adoption: allow useful workflows while detecting, redacting, blocking or escalating risky data-sharing events.
View source ↗Financial Institutions Restricted Public Generative AI Tools
Major financial institutions and large enterprises restricted employee access to public generative AI tools as they assessed data, compliance and confidentiality risks.
View incident
What happened?
Public reporting in 2023 documented restrictions or heightened controls at major financial and technology organizations as generative AI adoption accelerated.
Why it matters
Blocking AI can reduce immediate exposure, but it does not necessarily eliminate employees' desire to use AI. Unmanaged alternatives can create shadow AI.
SecurePledge takeaway
Organizations can move from blanket blocking to policy-based control: allow approved workflows, redact sensitive data, block high-risk interactions and maintain audit visibility.
View source ↗Use AI without losing control of your data.
SecurePledge sits between employees and AI tools to detect, redact, control and log sensitive information before it reaches external AI systems.