Money (fraudulent refunds, payment redirects), data (exfiltration via trusted outbound channels), disruption (deleting data, crashing workflows), or stealth persistence (establishing footholds without triggering alerts, because the tools they used were authorized).
The thing they all rely on: you gave the agent more tool power than it needed, or you trusted the input it received without validating it.