Living reference · Updated July 10, 2026

Shadow AI Incidents: A Running List for MSPs

The shadow-AI incidents that actually hit the small and mid-size businesses MSPs serve: PHI pasted into chatbots, rogue meeting transcribers, breached AI vendors, and exploits in tools your clients already run. A sourced, running list, each with the MSP takeaway and CONFIRMED, ALLEGED, and VULNERABILITY carefully distinguished.

Current as of July 10, 2026.

Not legal advice. Verify CONFIRMED vs ALLEGED status against the linked primary source before repeating any claim.

By the numbers

The pattern behind the anecdotes

$670K

added to average breach cost where shadow AI was involved ($4.63M vs $3.96M)

IBM Cost of a Data Breach 2025

20%

of breached organizations were compromised through shadow AI

IBM Cost of a Data Breach 2025

97%

of AI-related breaches hit organizations lacking proper AI access controls

IBM Cost of a Data Breach 2025

39.7%

of AI interactions involve sensitive data

Cyberhaven 2026

223

GenAI data-policy violations per organization per month (more than double YoY)

Netskope Cloud & Threat Report 2026

46%

of US workers admitted uploading sensitive company info or IP to public AI

KPMG / Univ. of Melbourne 2025

48%

of employees who used unauthorized AI faced formal consequences

PagerDuty Shadow AI Survey 2026

700+

organizations hit through a single AI chat integration (Salesloft Drift)

Google GTIG / Mandiant

Incidents

Sensitive data leaving into AI tools

The core "shadow AI" harm. Employees paste code, IP, or regulated data into consumer AI tools, or unapproved AI tools quietly ingest it.

Grouped by category. Scan the list, then expand any incident for what happened, how the data left, and the MSP takeaway.

Ontario hospital (healthcare)

Confirmed

Reported breach Dec 17, 2024

A former physician’s personal Otter.ai AI scribe auto-joined a virtual hepatology rounds meeting via a stale calendar invite and emailed out a transcript containing protected health information. Reported to the Information and Privacy Commissioner of Ontario (Reported Breach HR24-00691). This is Canadian PHIPA, not HIPAA, but it is the cleanest documented case of an unapproved AI tool capturing real PHI through shadow-AI behavior.

Vector: An unapproved meeting transcriber auto-joining via a calendar integration that persisted after the physician offboarded.

The MSP takeaway

Meeting transcribers auto-join via calendar integrations and survive offboarding. Sells a "meeting-transcriber governance" offering plus an offboarding and integration audit, a concrete, underserved niche.

Source: McCarthy Tétrault TechLex ↗

Healthcare, general (widespread practice)

Confirmed

Ongoing (documented 2024–2025)

Academic sources (USC Price School) document clinicians routinely pasting "anonymized" patient data into ChatGPT (often incompletely de-identified) and characterize it as "technically, a data breach" because OpenAI servers are not HIPAA-compliant. This is a widespread practice, not a single discrete named incident.

Vector: Clinicians pasting PHI into ChatGPT. For HIPAA, intent does not matter.

The MSP takeaway

Healthcare is uniquely exposed. Sells healthcare-vertical AI governance: PHI-aware DLP, BAA-aware AI-tool selection, and staff training.

Source: USC Price School ↗

Samsung Electronics (semiconductor manufacturing)

Confirmed

Reported Apr–May 2023

Bloomberg and The Register reported that Samsung banned employee use of generative AI after discovering staff had uploaded sensitive source code into ChatGPT; the internal policy warned of discipline up to termination. The frequently-repeated specific detail ("three separate leaks in 20 days," involving semiconductor source code, defect-detection algorithms, and a recorded meeting transcript) traces to a single Korean outlet (Economist Korea) and should be attributed as reported, not stated as established fact. Samsung itself confirmed a ban and "an incident."

Vector: Employees pasting source code and a meeting transcript into ChatGPT via the web browser. Legacy DLP is blind to browser copy/paste into AI.

The MSP takeaway

Visibility into what leaves the endpoint, not just network egress, is the gap. Opens the "AI exposure assessment": discover which AI tools employees use and whether code or IP is leaving. Sells endpoint DLP plus an acceptable-use policy with technical backing plus engineer-specific training.

Source: The Register ↗

Amazon (technology / retail)

Confirmed

January 2023

An Amazon lawyer warned employees over Slack not to share confidential information with ChatGPT, noting that outputs had "closely matched existing material." This is a documented hazard and internal warning, not a confirmed breach event.

Vector: Employees pasting code and confidential corporate information into ChatGPT.

The MSP takeaway

Prohibition-only warnings without technical controls do not stop the behavior. "We sent an email" is not a control. Sells the acceptable-use policy plus technical enforcement package.

Source: Gizmodo ↗

Corporate ChatGPT ban wave: JPMorgan, Bank of America, Citigroup, Deutsche Bank, Wells Fargo, Goldman Sachs, Verizon, Apple

Confirmed

February–May 2023

A wave of banks and large enterprises restricted or banned ChatGPT (and Copilot, in Apple’s case). The motivations were regulatory-risk and IP protection, largely pre-emptive rather than post-breach. JPMorgan reportedly could not determine how many employees were using ChatGPT or for what.

Vector: Employee use on unmanaged, personal accounts. The core problem was lack of visibility.

The MSP takeaway

Blanket blocking pushes usage onto personal devices and accounts, the definition of shadow AI. Sells AI discovery plus a "govern, don’t just block" managed-enablement service: approved tools routed through a monitored gateway.

Source: Forbes ↗

Incidents

AI vendors breached or misconfigured

Provider-side failures. The lesson is not "your employees leaked it." It is "don’t trust unvetted AI with sensitive data you can’t audit."

DeepSeek (AI vendor)

Confirmed

Disclosed Jan 29, 2025

Wiz research found DeepSeek had left a ClickHouse database publicly exposed and unauthenticated (ports 8123/9000), leaking over 1 million log lines including plaintext chat history, API keys and secrets, and backend metadata. Full database control was possible without authentication. DeepSeek secured it within hours of disclosure; no confirmed malicious third-party access.

Vector: A publicly accessible, unauthenticated ClickHouse database.

The MSP takeaway

When employees adopt a new AI tool, they entrust it with data before its security is proven. Sells an "AI vendor risk assessment" plus an approved-tool list; justifies blocking unvetted tools.

Source: Wiz Research ↗

Xsolis (healthcare AI vendor / Business Associate)

Confirmed

Access Jan 20–22, 2026; HHS notified June 5, 2026

A phishing-driven compromise of Xsolis, an AI utilization-management vendor, exposed the PHI of 1,396,519 individuals across 7 hospital systems: SSNs, insurance information, dates of birth, and treatment details. Filed on the HHS breach portal. Note: this is a phishing breach of an AI vendor, so the AI element is incidental to the attack vector.

Vector: Phishing compromise of a third-party AI vendor that is a HIPAA Business Associate.

The MSP takeaway

Third-party AI vendors are Business Associates that expand the attack surface. Sells third-party and vendor risk management plus BAA governance for healthcare clients.

Source: HealthExec ↗

OpenAI / ChatGPT (AI vendor)

Confirmed

March 20, 2023

A redis-py race condition in ChatGPT’s caching layer briefly exposed other users’ chat titles and first messages, and limited payment data (name, email, billing address, card type, and last four digits and expiry) for roughly 1.2% of ChatGPT Plus subscribers within a 9-hour window. No full card numbers were exposed; OpenAI notified affected users.

Vector: A caching bug creating cross-tenant leakage on a multi-tenant platform.

The MSP takeaway

Assume anything entered into a shared AI service could surface elsewhere. Reinforces the "no sensitive data in public AI" policy; sells the monitored-gateway alternative.

Source: OpenAI incident report ↗

Microsoft AI research (technology)

Confirmed

Disclosed Sept 2023 (token live from 2020)

Wiz found Microsoft’s own AI research team had exposed 38TB of private data via an overpermissive Azure SAS token in a public GitHub AI-training repo: disk backups of two employees’ workstations, secrets, private keys, passwords, and 30,000+ internal Teams messages. The token granted full control over the entire storage account. Microsoft revoked it and said no customer data was exposed.

Vector: An overpermissive Azure SAS token committed to a public GitHub repository.

The MSP takeaway

Even sophisticated AI teams mismanage credentials. Sells cloud security posture management, secret scanning, and least-privilege review of AI data pipelines.

Source: Wiz Research ↗

Incidents

Agentic AI & integration supply-chain

The emerging frontier. EchoLeak and ForcedLeak were researcher-discovered and patched with no confirmed in-the-wild exploitation; treat them as vulnerabilities, not breaches.

Microsoft 365 Copilot (enterprise AI)

Vulnerability

Disclosed June 2025 · CVE-2025-32711 · CVSS 9.3

Aim Security (Aim Labs) researchers Pavan Reddy and Aditya Sanjay Gujral disclosed the first known zero-click prompt-injection data-exfiltration flaw in a production LLM. Microsoft’s advisory described it as "AI command injection in M365 Copilot allows an unauthorized attacker to disclose information over a network." Microsoft patched it server-side and found "no evidence" it was exploited maliciously in the wild.

Vector: Zero-click indirect prompt injection via a crafted email, exploiting RAG context inheritance, reaching anything in Copilot’s scope: emails, OneDrive, SharePoint, Teams.

The MSP takeaway

Agentic and RAG assistants inherit trust-boundary risks and need the same patch, config, and monitoring discipline as any enterprise app. Sells managed patching and config-hardening for Copilot plus agentic-AI monitoring.

Source: The Hacker News ↗

Salesforce Agentforce (enterprise AI CRM)

Vulnerability

Reported Jul 28, 2025 · disclosed Sept 25, 2025 · CVSS 9.4

Noma Labs demonstrated the same class of flaw in Salesforce Agentforce: an indirect prompt injection hidden in a Web-to-Lead form’s "Description" field, chained with a content-security-policy bypass via an expired allowlisted domain that researchers re-registered for about $5. Salesforce patched it via Trusted URL enforcement on Sept 8, 2025.

Vector: Prompt injection via an ingested lead form, plus a CSP bypass through a lapsed allowlisted domain, reaching CRM data: customer PII, pipeline, internal communications.

The MSP takeaway

Autonomous agents execute attacker instructions hidden in ingested data. Treat all external data feeding an agent as untrusted. Sells agentic-AI security posture reviews, prompt-injection testing, and integration hardening.

Source: Noma Security ↗

Salesloft Drift + 700+ downstream orgs (incl. Cloudflare, Palo Alto Networks, Proofpoint, Zscaler)

Confirmed

Aug 8–18, 2025 (disclosed late Aug 2025)

Google GTIG / Mandiant reported that the actor tracked as UNC6395 used stolen OAuth and refresh tokens from the Drift AI chat integration to reach Salesforce customer instances at "over 700 potentially impacted organizations." Attackers harvested Salesforce data and secrets: AWS keys, Snowflake credentials, and tokens for Slack, Google Workspace, S3, Azure, and OpenAI. Salesforce and Salesloft revoked tokens and pulled Drift from AppExchange; Cloudflare confirmed 104 API tokens compromised.

Vector: Stolen OAuth / refresh tokens from an AI chat integration, a non-human identity with broad SaaS-to-SaaS scope.

The MSP takeaway

AI chat integrations are non-human identities with broad OAuth scope. Sells SaaS and OAuth integration discovery plus non-human-identity governance, a fast-growing, high-value service.

Source: Google Threat Intelligence ↗

Incidents

Regulatory enforcement

Regulators are active, primarily in the EU. Outcomes shift: the Garante’s €15M OpenAI fine was later annulled, and no AI-specific HHS-OCR HIPAA fine exists as of mid-2026.

OpenAI / ChatGPT (Italy, Garante)

Confirmed

Ban Mar 2023 · €15M fine Dec 2024 · fine annulled Mar 18, 2026

Italy’s Garante temporarily banned ChatGPT in March 2023 (lifted April 2023 after remediation) and later fined OpenAI €15 million in December 2024 over data processing and training without a clear legal basis, and for not reporting the March 2023 breach to the regulator. Crucially, the Tribunale di Roma (Judgment no. 4153/2026, judge Damiana Colla) annulled the €15M fine on March 18, 2026, on jurisdictional grounds (Ireland’s DPC became lead authority Feb 15, 2024), not on the merits. Always cite the fine and its annulment together.

Vector: Data processing and model-training on personal data without a documented lawful basis under GDPR.

The MSP takeaway

Data protection authorities treat AI training data as regulated personal data. Sells GDPR / AI compliance-readiness assessments for EU-exposed clients using or building AI.

Source: The Hacker News ↗

Luka Inc. / Replika (Italy, Garante)

Confirmed

Ban Feb 2023 · €5M fine 2025

The Garante fined Replika’s maker €5 million for processing personal data without a legal basis and without age verification, and reaffirmed its ban in April 2025, citing risks to minors.

Vector: AI companion chatbot processing personal data, with no age verification.

The MSP takeaway

AI companion and chatbot data handling draws regulatory fire, especially regarding minors. Reinforces the "know what your AI tools collect" assessment.

Source: IAPP ↗

DeepSeek (Italy, Garante)

Confirmed

Jan 30, 2025

The Garante imposed a definitive limitation on processing Italian users’ personal data by DeepSeek, citing inadequate GDPR answers and data stored in China; the app was pulled from Italian app stores.

Vector: A fast-adopted foreign AI tool with data residency in China and inadequate GDPR responses.

The MSP takeaway

Fast-adopted foreign AI tools may be legally unusable for EU-data clients. Sells AI-tool vetting including data-residency and jurisdiction analysis.

Source: Bird & Bird ↗

Rite Aid (retail pharmacy, US FTC)

Confirmed

Dec 19, 2023

The FTC settled with Rite Aid over AI facial-recognition surveillance deployed without accuracy or bias controls, imposing a five-year ban on facial recognition for surveillance and ordering deletion of the data and models. It was the FTC’s first "algorithmic unfairness" action. Rite Aid disputed the allegations.

Vector: AI a client deploys (facial recognition) rather than AI a client uses.

The MSP takeaway

AI deployed without accuracy testing or bias controls creates FTC Section 5 liability. Governance covers AI a client deploys, not just AI it uses. Sells AI-deployment risk review for clients building AI features.

Source: FTC press release ↗

FTC 6(b) inquiry: Alphabet, Character.AI, Instagram, Meta, OpenAI, Snap, xAI

Confirmed

Sept 11, 2025

The FTC issued 6(b) study orders to seven companies operating consumer AI companion chatbots, examining data handling and child safety. This is an inquiry, not an enforcement action, but it may inform future rules or cases.

Vector: Consumer AI companion chatbots and their handling of user and minors’ conversation data.

The MSP takeaway

Signals the US regulatory direction on AI data handling and minors. Positions the MSP as a regulatory-horizon advisor for clients.

Source: FTC press release ↗

Otter.ai, Brewer v. Otter.ai (In re Otter.AI Privacy Litigation)

Alleged

Filed Aug 15, 2025 · consolidated Oct 22, 2025

A class action alleges that Otter’s Notetaker / OtterPilot auto-joined Zoom, Meet, and Teams calls and recorded them without all-party consent, and that transcripts were used to train models, bringing ECPA, CFAA, and CIPA claims (plus alleged biometric voiceprints under Illinois BIPA). Otter filed a motion to dismiss in January 2026 denying interception. There has been no ruling on the merits; these are unproven allegations.

Vector: Alleged: a meeting transcriber auto-joining calls and recording without all-party consent.

The MSP takeaway

Meeting transcribers create all-party-consent liability, especially in two-party-consent states. Sells the meeting-transcriber governance offering: consent configuration, allowlisting, and policy.

Source: NPR ↗

Incidents

AI output liability: a different harm class

Included for completeness and clearly labeled separately: the harm here is inaccurate AI output, not leakage of sensitive data. Do not present these as data-exposure incidents.

Levidow, Levidow & Oberman (law firm), Mata v. Avianca

Confirmed

Sanctions Jun 22, 2023

Two attorneys and their firm were sanctioned $5,000 under Rule 11 for submitting a brief containing six fabricated case citations produced by ChatGPT, and were ordered to notify the judges named in the fake opinions. The harm is output fabrication (hallucination), not data exposure.

Vector: ChatGPT used for legal research, producing hallucinated citations. Not a data leak.

The MSP takeaway

An AI-use policy must address output verification, not just data input. Sells the acceptable-use policy and training that cover accuracy and verification obligations.

Source: Mata v. Avianca (Wikipedia) ↗

Air Canada (airline), Moffatt v. Air Canada

Confirmed

Ruling Feb 14, 2024

The BC Civil Resolution Tribunal found Air Canada liable for negligent misrepresentation after its website customer-service chatbot gave a passenger wrong bereavement-fare information, awarding C$812.02. The tribunal rejected the argument that the chatbot was a "separate legal entity." The harm is misrepresentation, not data exposure.

Vector: A client-facing chatbot giving inaccurate information. Not a data leak.

The MSP takeaway

Companies are liable for their AI’s statements. Client-facing chatbots need accuracy governance and disclaimers. Sells governance and testing for client-deployed chatbots.

Source: ABA Business Law ↗

The opportunity

How an MSP turns these into a service

Every incident above maps to a concrete, billable offering. The response is a four-stage program, and the risk is the demand signal.

01

Discovery

Run an AI-usage discovery assessment for every client: inventory which AI tools, accounts (personal vs managed), browser extensions, and SaaS/OAuth integrations are in use. The single highest-leverage first step, it directly answers the IBM finding that 97% of AI-breached orgs lacked access controls. Benchmark: if more than 20% of AI use is on personal accounts (Netskope’s 2026 figure is 47%), escalate immediately.

02

Policy + enforcement

Deliver an acceptable-use policy backed by technical controls, not email warnings alone (the Amazon lesson). Deploy DLP that inspects browser paste and upload, not just network egress, route approved AI through a monitored gateway, and allowlist sanctioned tools. Netskope found only half of orgs have GenAI DLP; closing that gap is the sale.

03

Specialized governance

Add meeting-transcriber governance (consent config, calendar-integration and offboarding hygiene: the Otter / Ontario lesson), non-human-identity and OAuth inventory (the Salesloft Drift lesson), and agentic-AI posture reviews with prompt-injection testing (the EchoLeak / ForcedLeak lesson). For healthcare clients, layer PHI-aware DLP and BAA management (the Xsolis lesson).

04

Training + vetting

Recurring end-user training covering both data-input discipline and output-verification obligations (Mata v. Avianca). Formal AI-vendor vetting including security posture, data residency, and jurisdiction (DeepSeek). Re-run discovery quarterly; a rising share of sanctioned-vs-shadow usage is the KPI that shows the program is working.

Where MSP responsibility sits

  • AI a client uses (ChatGPT, Copilot, transcribers): the MSP owns visibility, enforcement, and training.
  • AI a client deploys (customer chatbots, facial recognition, agents): the role extends to accuracy and bias testing and liability governance (the Rite Aid and Air Canada lesson).
  • AI vendors in the supply chain: the MSP owns third-party risk management and integration and token governance (the Salesloft Drift and Xsolis lesson).

Frequently asked

Shadow AI incidents, answered

What is shadow AI and why is it a security risk?

Shadow AI is employee use of unsanctioned AI tools: pasting code, customer data, or regulated information into consumer chatbots, or letting unapproved AI tools like meeting transcribers auto-join calls, without IT visibility or controls. It is a measurable, top-tier breach driver, not a hypothetical: IBM’s 2025 Cost of a Data Breach Report found 20% of breached organizations were compromised through shadow AI, that a high level of shadow AI added about $670,000 to the average breach cost, and that 97% of AI-related breaches hit organizations lacking proper AI access controls. The risk is that legacy DLP is blind to browser copy/paste into AI tools, so data leaves the endpoint with no record.

Has shadow AI actually caused data breaches?

Yes, and the incidents split into distinct harm classes that should not be conflated. Sensitive data has left organizations into AI tools (Samsung’s ChatGPT code leak; a former physician’s personal Otter.ai scribe capturing PHI at an Ontario hospital, reported Dec 2024). AI vendors have themselves been breached or misconfigured (DeepSeek’s exposed ClickHouse database; Microsoft’s 38TB Azure SAS-token exposure; the ChatGPT redis-py bug). And the Salesloft Drift OAuth compromise hit 700+ organizations through an AI chat integration. Some researcher-found flaws (EchoLeak, ForcedLeak) were patched with no confirmed in-the-wild exploitation, and should be described as vulnerabilities rather than breaches.

What was the Samsung ChatGPT incident?

Bloomberg and The Register reported in May 2023 that Samsung banned employee use of generative AI after discovering staff had uploaded sensitive source code into ChatGPT, with the internal policy warning of discipline up to termination. Samsung confirmed a ban and "an incident." The widely-repeated specific detail ("three separate leaks in 20 days" involving source code, defect-detection algorithms, and a meeting transcript) traces to a single Korean outlet (Economist Korea) and should be attributed as reported, not stated as established fact.

Are AI meeting transcribers a compliance risk?

Yes. AI transcribers connect to calendars and auto-join meetings, and those integrations can persist after an employee offboards. In the cleanest documented case, a former physician’s personal Otter.ai scribe auto-joined a virtual hospital rounds meeting via a stale calendar invite and emailed out a transcript containing PHI (reported to Ontario’s privacy commissioner, Dec 2024). Separately, Brewer v. Otter.ai (an unproven class action filed in August 2025, with a motion to dismiss pending) alleges transcribers recorded calls without all-party consent, a live risk in two-party-consent states. The governance response is consent configuration, transcriber allowlisting, and offboarding and calendar-integration audits.

What is EchoLeak / prompt-injection in AI assistants?

EchoLeak (CVE-2025-32711, CVSS 9.3) was the first documented zero-click prompt-injection data-exfiltration flaw in a production LLM, Microsoft 365 Copilot. A crafted email could plant hidden instructions that the assistant inherited through its RAG context, potentially exfiltrating anything in Copilot’s scope. Aim Security researchers disclosed it; Microsoft patched it server-side and found no evidence of malicious exploitation in the wild. ForcedLeak (CVSS 9.4) demonstrated the same class in Salesforce Agentforce. Both were researcher-found vulnerabilities, not confirmed breaches. The lesson is that agentic and RAG assistants need the same patch, config, and monitoring discipline as any enterprise app, and all external data feeding an agent must be treated as untrusted.

How should an MSP respond to shadow AI risk?

In four stages. Discovery: inventory the AI tools, accounts, extensions, and OAuth integrations in use across each client. Policy plus enforcement: an acceptable-use policy backed by DLP that inspects browser paste and upload, not just network egress, with approved tools routed through a monitored gateway. Specialized governance: meeting-transcriber controls, non-human-identity and OAuth inventory, agentic-AI posture reviews, and PHI-aware DLP for healthcare. Training plus vetting: recurring user training on data-input and output-verification, and formal AI-vendor vetting for security posture, data residency, and jurisdiction. Responsibility maps cleanly: for AI a client uses, the MSP owns visibility, enforcement, and training; for AI a client deploys, it extends to accuracy and bias testing; for AI vendors in the supply chain, it is third-party risk and token governance.

See what your clients are actually pasting into AI

ShadowLock discovers shadow AI use, classifies sensitive data at the point of paste, and produces the audit evidence these incidents make unavoidable, across every tenant.