AI news story

An AI agent hacked McKinsey's internal AI platform in two hours using a decades-old technique

Security firm Codewall turned an offensive AI agent loose on McKinsey's internal AI platform Lilli, a system used by over 43,0…

  • AI
  • Source: The Decoder
  • Published: 2026-03-11

Editor's take

An offensive AI agent successfully infiltrated McKinsey's internal AI platform, Lilli, within two hours, leveraging a known, albeit older, security vulnerability.

This incident is significant because it highlights the immediate and tangible risks posed by AI agents to even sophisticated corporate systems. McKinsey's reliance on Lilli for critical functions like client research and strategy development means such breaches could compromise sensitive business intelligence and client data, impacting the firm's reputation and competitive edge. It underscores a growing concern for AI security, as generative models can now be weaponized with alarming efficiency.

Going forward, the focus will be on how quickly companies like McKinsey can implement robust defenses against AI-driven attacks, moving beyond traditional cybersecurity measures. The speed of this exploit, using a "decades-old technique," suggests that AI agents may be able to bypass current security protocols by finding novel combinations of known weaknesses, demanding a proactive and adaptive security posture.