Karsten Wenzlaff, Advisor
August 26th, 2025
Mar 26, 2026 | NCFA Insight | Artificial Intelligence And Data

On March 1, 2026, CodeWall, a security research firm focused on AI systems, privately reported security gaps to McKinsey. The firm said its agent found 22 unauthenticated endpoints, then chained a SQL injection issue and other weaknesses to gain read and write access across the production environment. CodeWall said the reachable data included 46.5 million chat messages, 728,000 files, 57,000 user accounts, 384,000 AI assistants, and 94,000 workspaces. It also said prompts, model configurations, and RAG related data were reachable.
On March 2, 2026, McKinsey acknowledged the findings and patched the unauthenticated endpoints the same day.
On March 9, 2026, CodeWall publicly shared research on vulnerabilities in McKinsey’s internal AI platform Lilli.
On March 11, McKinsey released this statement about the vulnerability and that a third party forensic review found no evidence that unauthorized parties accessed client data or client confidential information.
Public API documentation appears to have exposed a map of the system. Some endpoints reportedly required no authentication. One of them allegedly allowed database manipulation through JSON keys, which opened the door to SQL injection. From there, CodeWall said it could determine live production data and reach much deeper parts of the platform.
This incident doesn't point first to a model failure. It points to ordinary application security weaknesses around an AI system that had become deeply embedded in internal work.
McKinsey didn't confirm the full scale of the researcher claims. Instead, it focused on the response. The company said it fixed the issue quickly and found no evidence that unauthorized parties accessed client data or client confidential information.
Having said that, the reported scale of reachable internal material was large enough to raise questions about internal knowledge exposure, employee work patterns, and intellectual property concentration in one system.
CodeWall said prompt and configuration layers were reachable. If true, it means a bad actor could have potentially altered how the system retrieves information or generates answers. In an internal AI tool, that can create wrong outputs that look normal to staff.
That's where this type of incident becomes more useful for fintechs and financial firms. A publicly visible outage gets noticed whereas quietly altered outputs may not. In regulated environments, that can affect approvals, reviews, client treatment, policy interpretation, and internal decision support before anyone spots the pattern.
Banks, lenders, insurers, wealth firms, and fintechs are building similar internal AI layers right now. They connect those tools to policy documents, research, support logs, internal files, and customer related workflows because it saves time and helps staff move faster.
But that convenience comes with risk given that AI often pulls sensitive access into one place. If permissions are weak, endpoints are exposed, or prompt controls aren't protected, one internal tool can become a wider point of failure.
A key lesson founders and operators should take from this case, is to ask whether the application around it is locked down, whether prompts and retrieval rules are treated as sensitive assets, whether permissions are tight, and whether anyone has tested the system the way an attacker would.
Enterprise AI doesn't erase old security mistakes. It can magnify them by concentrating data, access, and trust inside a single interface.
The National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create a vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org
![]() | ![]() | ![]() |
|---|---|---|
![]() | ![]() | ![]() |
Leave a Reply