McKinsey & Company remediated a SQL injection flaw in its internal generative AI platform, Lilli, after security startup CodeWall said its autonomous agent compromised the system in about two hours. According to the reports, the agent obtained full read and write access to the production database, exposing millions of employee messages and thousands of files, and potentially allowing modification of the chatbot's core instructions. The issue affected a platform reportedly used by roughly three quarters of McKinsey's more than 40,000 employees for strategy work, research, and document analysis.
CodeWall said it disclosed the issue to McKinsey's security team on March 1, after which the firm patched exposed access points and took the development environment offline by March 2. The reporting indicates the weakness was a longstanding web application class of bug rather than a novel AI-specific exploit, underscoring that enterprise AI systems remain vulnerable to conventional application security failures when connected to sensitive data stores and production workflows.

Track how attackers are adapting to this technology.
5 events from the most recent confirmed update back to the earliest known activity.
On March 13, 2026, reporting surfaced that CodeWall had disclosed its autonomous agent's alleged compromise of McKinsey's internal AI platform, Lilli. Independent experts said the attack chain appeared technically plausible while questioning whether the full claimed impact had been sufficiently evidenced.
McKinsey stated that a third-party forensic investigation found no evidence that client data or confidential client information had been accessed by the researcher or any other unauthorized party. This statement accompanied public reporting on the incident and challenged the extent of the claimed impact.
By March 2, 2026, McKinsey had reportedly patched the exposed access points used in the reported attack chain and taken the affected development environment offline. These actions were described as immediate containment measures following notification.
McKinsey was notified on March 1, 2026, about CodeWall's reported access to Lilli and its production database. The disclosure prompted McKinsey to begin response actions.
CodeWall said its autonomous AI security agent compromised McKinsey & Company's internal generative AI platform, Lilli, in about two hours by finding exposed documentation, identifying unauthenticated endpoints, and exploiting a vulnerable search endpoint. The reported access provided read and write access to the production database and potentially exposed tens of millions of chat messages, hundreds of thousands of files, user accounts, AI assistants, and workspaces.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.