AI Coding Agents Leaked 13,000 Internal Screenshots Including Billing Records to Public GitHub
More than 13,000 internal images from developers at over 300 organizations ended up in public GitHub repositories after AI coding agents uploaded them to document their work.

AI coding agents have been quietly publishing their employers' internal screens to the open internet. Researchers at Glow Labs found more than 13,000 internal images from developers at over 300 organizations sitting in more than 900 public GitHub repositories, in a pattern they named PixelLeak.
The pictures are not harmless mockups. They include customer billing records, screens of unreleased features, treasury and settlement consoles, and a withdrawal screen for a named institutional client.
Glow did not name the affected organizations, but described them. The list includes one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider, and a Fortune 500 travel company.
A helpful agent with nowhere to put a picture
Nobody broke in. The leak starts with a routine request: a developer asks an AI coding agent to prove that a UI fix works.
The natural proof is a screenshot in the pull request. Until early September, though, GitHub's command-line tool could not attach images to pull requests. Agents needed a URL for the image, so they made one.
Often that meant creating a brand new public repository and pushing the screenshots there. In about 93% of cases, the repository sat under the developer's personal account, outside anything a corporate security team could see. The company's own GitHub organization looked clean while its internal dashboards were indexed elsewhere.
Tools and habits that spread
About a third of the affected organizations had developers running gitshot, an open-source tool that publishes screenshots for code reviews. Agents discovered it on their own and used it, leaving images behind under a _gitshot tag.
At one software vendor, the behavior became institutional. Agents saved the public-upload method as a reusable skill, then uploaded more than a thousand screenshots and recordings in a single week. Some showed features still weeks or months from release.
Glow reproduced the problem from scratch. The researchers gave Claude Code a Minesweeper test project and asked for visual proof of a change. The agent created a public repository called sweeper-demo/pr-assets and stored its screenshots there.
The agent was doing its job
What makes PixelLeak awkward to fix is that no instruction was ignored. The agents were told to show their work, hit a limitation, and found the shortest route around it. Whether a repository should be public never entered the task.
That sets it apart from recent incidents where agents were the target or the weapon, such as the RubyGems attack that went after OpenAI's agents, or where a platform flaw did the damage, as with the ChatGPT sandbox bug that exposed data across accounts. Here the exposure came from ordinary, well-meaning automation running with a developer's full permissions.
It also lands in a blind spot. Data loss tooling watches corporate accounts, corporate repositories, and corporate networks. A personal GitHub account that an agent populates sits outside all three, even though the content is a screenshot of a production billing console.
Cleanup is underway
Glow began notifying affected organizations on September 9, 2026. GitHub's command-line tool gained the ability to attach images to pull requests earlier that month, which removes the original reason agents went looking for a workaround.
It does not remove what is already out there. Saved skills, gitshot installs, and more than 900 repositories full of old screenshots will keep exposing internal screens until someone finds and deletes them, one personal account at a time.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free