Adversa AIGet a demo

Top AI Security Incidents — 2025 Edition

  • Report
  • Agentic AI Security
  • LLM Security

Adversa AI · July 30, 2025

Real breaches. Real consequences. Lessons the industry can't afford to ignore.

Adversa AI published this incident-based report to expose how AI systems fail in the real world, why current defenses fall short, and what must change to secure the future of AI.

AI is already breaking — in ways most teams don’t see.

From chatbots leaking secrets to agents misfiring decisions, these risks aren’t hypothetical. They’ve already happened.

Why this report matters

This report was created for AI builders, defenders, and decision-makers. You’ll walk away with:

  • The most common security failure patterns in GenAI
  • How prompt injections and agent misalignment lead to real losses
  • Attack techniques used against APIs, memory, and control logic
  • Actionable defenses that go beyond basic input validation
  • Lessons from 16 real-world cases across industries

Key insights you can’t ignore

From prompt injection to flawed APIs, these incidents expose the most common ways AI systems fail — and what it costs when they do.

Prompt injection causes over 30% of AI security failures

[ 01 ]

Prompt-based exploits account for 35.3% of all documented AI incidents — making them the most common failure type, ahead of unsafe outputs and data leakage. Language is now the primary attack vector, and most AI systems still lack effective defenses.

Simple prompts are causing $100K+ in financial losses

[ 02 ]

Even basic prompt injections have triggered unauthorized crypto transfers, fake sales agreements, and brand-damaging behavior — causing losses over $100,000 across platforms like ElizaOS, AiXBT, and Chevrolet.

Technology firms lead, but no sector is safe

[ 03 ]

Nearly 35.3% of all documented AI security incidents involve technology companies, but finance, telecom, and retail are increasingly impacted. From crypto agents to airline chatbots to internal data leaks, AI failures are spreading across every sector.

70.6% of incidents involve generative AI — but agentic AI is the real threat

[ 04 ]

Generative AI accounts for the large majority of all known incidents, but the most irreversible attacks — including cross-tenant data exposure and autonomous crypto theft — are emerging from agentic AI systems with real-world action capabilities.

AI security incidents have more than doubled since 2024

[ 05 ]

AI-related breaches have skyrocketed in 2025, already surpassing prior years and showing no signs of slowing. The growth highlights a dangerous gap between AI adoption and security readiness across industries.

These incidents are more than technical failures — they’re signals

This report isn’t just a list of AI risks — it’s a practical guide built around real-world security breaches. Each page unpacks what went wrong, how it happened, and what defenders can do to prevent the same patterns from repeating. Here’s a look inside.

Report spread: a complete, structured breakdown of an actual cross-tenant data exposure, including root cause, impact, and prevention steps

Report spread: four breach trendlines — agentic risk, cross-layer failures, and critical sector exposure — alongside a timeline of escalation from toy use to real-world threats

Report spread: key incident trends, from top attack types like prompt injection to sector breakdowns showing how generative AI dominates breach reports

Report spread: the contents and executive summary, laying out the purpose of the report and the biggest takeaways from real incidents between 2023 and 2025

For the announcement and key findings, read the launch post.

Top AI Security Incidents — 2025 Edition

July 30, 2025

Related research