Unauthorized Agent Action or Data Exfiltration
An agent reads, writes, executes, sends, publishes, transfers, or changes a resource outside intended authority or user intent.
Trigger: An agent reads, writes, executes, sends, publishes, transfers, or changes a resource outside intended authority or user intent.
Severity guide: Severity 1 for customer data, secrets, code, cloud control planes, destructive action, cross-tenant effect, or external disclosure.
First 15 minutes
- Stop or suspend the affected agent and high-risk tools without destroying logs.
- Preserve trajectory, prompts or references, retrieved content, tool calls, policy decisions, credentials, and downstream effects.
- Identify the initiating user, workload, content source, and first unauthorized effect.
- Revoke or constrain delegated credentials and network egress.
- Engage the owner of the affected resource.
First 60 minutes
- Reconstruct identity-to-effect chain and separate direct user intent from indirect influence.
- Identify every similar agent, tool, credential, tenant, and resource path.
- Review policy decisions, approval prompts, retries, and fallback routes.
- Hunt for memory writes, untrusted retrieval, tool-definition drift, or cross-agent delegation before the action.
- Preserve external destination evidence and contact provider where appropriate.
- Establish known data, code, or resource impact.
Evidence checklist
- initiating identity and session
- agent, model, prompt or context reference
- retrieval and memory events
- tool and MCP definition hash
- credential and authorization decision
- file, process, repository, network, cloud, and business effects
- destination and transfer volume
- EDR, DLP, CASB, and SIEM alerts
Containment options
- suspend agent or tool
- revoke delegated credentials
- block destination or egress category
- require human approval for high-risk actions
- quarantine affected data or repository
- isolate endpoint or container
- disable fallback routes that bypass policy
Recovery and durable controls
- least-privilege per-tool identity
- content trust labeling
- policy before effect
- trajectory retention
- high-risk action allowlist
- egress controls and DLP
- safe replay and regression tests
- SOC runbook and kill switch
Communications
- Legal, privacy, and customer trust are mandatory for external disclosure.
- Avoid attributing intent to the model. Describe initiating content, authorization, and observed effect.
- Coordinate with the primary IR provider for broad enterprise scope.
Closure criteria
- Unauthorized effect is stopped and scoped.
- Affected data and systems are remediated.
- The failed boundary is fixed and validated.
- Detection and containment are tested.
- Customer and regulatory decisions are complete.
Required conversion to practice
Before closure, produce:
- one updated attack-path or trajectory diagram
- one root-cause finding
- one production or candidate hunt analytic
- one safe replay or regression test
- one remediation-validation memo
- one owner and residual-risk decision
How to use these. They are generic by design: they do not know your environment, your provider, or your legal obligations. Free to use and adapt inside your organization; keep the source line if you republish. Version 1.0, 27 August 2026. Every runbook ends with the same rule: before closure, convert the incident into a diagram, a root-cause finding, a hunt analytic, a regression test, a validation memo, and an owner. That conversion is the part most teams skip, and it is the part we are hired for.
- Leaked AI or Model API Credential
- Inference Cost Spike or Token-Jacking
- MCP Tool Poisoning, Impersonation, or Rug Pull
- Persistent Memory or RAG Poisoning
- Shadow or Exposed AI Infrastructure
- Malicious Model, Artifact, Skill, Plugin, or Extension
- Confidential or Sovereign AI Boundary Failure
- AI Provider or Model Gateway Third-Party Incident
- AI Coding Agent Repository or CI Compromise
Happening now?
Send a project inquiry and set timing to active incident. Joey Victorino reads those first and answers the same business day, US Pacific. Put no credentials, prompts, or customer data in the form.