An IBM Consulting expert demonstrated how employees sharing production source code with public AI tools can inadvertently expose proprietary algorithms and sensitive business logic. When such code is submitted to generative AI platforms, the information may be incorporated into the model's training data, potentially allowing similar code or formulas to be revealed to other users in the future. This risk is exacerbated by insufficient employee awareness, weak governance, and the absence of robust AI usage policies, making it critical for organizations to implement clear guidelines, approved tool lists, and targeted training to prevent inadvertent data leaks.
Separately, SAS Institute, a major analytics and AI software provider, experienced a breach in which threat actors claimed to have stolen source code and documentation. While the compromised files were reportedly outdated, dating from 2003 to 2011, the exposure of source code—even if old—remains a significant risk, as attackers may use such information to develop exploits or target customers. These incidents underscore the persistent threat posed by both inadvertent and malicious source code leaks, highlighting the need for comprehensive data protection strategies and vigilant monitoring of both employee behavior and external threats.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Help Net Security published coverage warning that a quick AI-related check could expose a company's secrets, framing the issue as an intellectual property and data leakage risk. The reference provided does not describe a specific incident, victim, or remediation event.
A reported breach involving SAS Institute surfaced, with claims that outdated information had been stolen. The available reference does not provide further details on the timing, scope, or affected individuals.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.