Slide 5 · The Outcomes
What actually goes wrong — anchored to real events
Four documented outcomes, each tied to a real incident.
📤
Data exfiltration without access
An attacker read the contents of a victim's Microsoft 365 mailbox — including password reset emails and sensitive documents — without ever logging in. The agent carried the data out. EchoLeak, CVE-2025-32711, June 2025.
🔑
Credential theft via routine task
A victim asked their AI browser to accept a calendar invite. Hidden instructions in the invite redirected the agent to open their password manager and extract stored credentials. The user saw a meeting accepted. PerplexedBrowser / PleaseFix, Zenity Labs, March 2026.
🗂️
Local file system access
The same calendar invite attack caused the agent to navigate the victim's local file system, locate sensitive files, and transmit their contents to an attacker-controlled server — encoded silently into a URL. PerplexedBrowser / PleaseFix, Zenity Labs, March 2026.
🏢
Full platform compromise
In a controlled red-team exercise, an autonomous agent was used to compromise McKinsey's internal AI platform "Lilli," gaining broad system access across multiple connected services in under two hours. McKinsey red team, 2025.
The human cost
In every one of these incidents, the victim did nothing wrong. They used their AI assistant the way it was designed to be used. Someone else's malicious content reached that assistant first — and the assistant obeyed it instead.
When someone's private data leaks through their own AI — they're harmed. Even if they never know it happened.