AI Data Leaks Expose Sensitive Information Across Major Platforms

AI Data Leaks Expose Sensitive Information Across Major Platforms

First seen 25 Aug 2026, 14:18 UTC HackernoonDexpose 64.5

Article Content

Browse articles
ThreatCluster

In 2026, a significant rise in AI data leaks has been reported, with Cyberhaven's research indicating that 39.7% of AI interactions expose sensitive data. Major platforms like ChatGPT, Claude, and Grok have been linked to these leaks due to both platform vulnerabilities and user behavior. A notable incident involved xAI's Grok Build coding agent, which uploaded developers' entire Git repositories, including sensitive API keys and passwords, to a cloud storage bucket. These leaks often occur passively, with users unintentionally sharing secrets through normal interactions with AI tools. The issue is exacerbated by the difficulty in policing AI interactions with traditional security measures. The risks are categorized into four types, including training data exposure and prompt injection, each requiring distinct prevention strategies. Organizations are urged to adopt better practices to mitigate these risks.

Key Points: • 39.7% of AI interactions expose sensitive data, according to Cyberhaven. • xAI's Grok Build agent leaked entire Git repositories, including sensitive credentials. • AI data leaks often occur through user behavior rather than direct attacks.

Timeline

2025-09-15
CVE-2025-59145 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-01-21
CVE-2026-21852 published
A vulnerability affecting AI tools was disclosed, raising concerns about data leaks.
Dexpose
2026-02-28
First public PoC for CVE-2026-21852
Proof-of-concept code was released, demonstrating the vulnerability's exploitability.
Dexpose
Recent
Grok Build incident reported
A security researcher found Grok Build uploading sensitive data from Git repositories.
Hackernoon