5 min read
Incident Reports A UK insurer's AI chatbot, due to an IDOR vulnerability and excessive tool permissions, allowed authenticated users to retrieve policy data for unrelated customers. 80,000 records exposed.
AI security incidents reconstructed from documented attack patterns to inform defence.
A UK insurer's AI chatbot, due to an IDOR vulnerability and excessive tool permissions, allowed authenticated users to retrieve policy data for unrelated customers. 80,000 records exposed.
Post-mortem of a multi-stage intrusion using LLM-generated spear phishing, AI-assisted credential stuffing, and automated recon to compromise a mid-market wealth management firm.
A UK law firm's misconfigured AI document assistant was exploited to systematically extract privileged client communications and M&A due diligence files over six weeks.