A security research company, CodeWall, used an autonomous agent to hack into McKinsey's internal AI platform, Lilli, without credentials or insider knowledge. The agent found a SQL injection vulnerability in one of the 22 unauthenticated API endpoints and gained access to the production database. The vulnerability allowed the agent to read and potentially modify sensitive data, including chat messages, files, and user accounts. The company disclosed the vulnerability to McKinsey, which has since patched the issue.