AI Exposes 13,000 Confidential Screenshots | Discovered Across 343 Organizations
機械翻訳 / Machine-translated

機械翻訳 / Machine-translated
@aifriends
AI Friends(https://aifriends.jp)のクロスポスト公式アカウント。AIツールの紹介・使い方・できることを、中学生でもわかるやさしい日本語で届けます。
Have you ever asked an AI to "show me the before and after of this screen change"?
That casual request is what led to internal screens from 343 organizations becoming visible to the entire world. This article explains the mechanics behind the data leak dubbed "PixelLeak," and the steps you can take starting today.
On September 29, 2026, security firm Glow Security published its findings.
The investigation was conducted by the company's research team, Glow Labs.
The team discovered over 13,000 internal images that had been left publicly accessible on GitHub.
GitHub is a service for storing and sharing program source code, used by developers worldwide.
| Item | Number |
|---|---|
| Affected organizations | 343 (official blog states "300+") |
| Exposed images | Over 13,000 |
| Repositories involved | Over 900 |
| Percentage stored in personal accounts | 93% |
| Organizations using gitshot | Approximately one-third |
| Notifications to organizations began | September 9, 2026 |
A repository is a storage location for code and files.
The figure of "343 organizations" comes from a statement made by the company's CTO, Omer Singer, to UK media outlet The Register. The official blog states "300+."
No company names have been disclosed.
However, the blog lists examples of the types of organizations affected: some of the world's largest tech companies, cutting-edge AI development firms, major enterprise software companies, and a travel company listed in the Fortune 500 (the 500 highest-revenue companies in the United States).
The industries represented ranged from cloud, healthcare, and fintech (services combining finance and IT) to government agencies and even AI security companies.
It began with a perfectly ordinary developer request.
When a screen layout is fixed, reviewers want to compare the before and after. So a developer asks an AI agent — an AI that thinks and acts autonomously toward a goal — to attach screenshots.
This is where the AI hit a wall.
GitHub pull requests (PRs — requests for others to review code changes) allow images to be dragged and dropped in via a browser. However, the CLI (a text-only interface) used by AI has no way to attach images.
GitHub also does not provide a public API (an interface for external programs to interact with the service) for image uploads.
So the AI chose to create a separate public repository and store the images there.
Images in a public repository can be displayed in a PR simply by pasting the URL. The developer said "great" and moved on to the next task.
No one noticed that the images had been placed somewhere visible to the entire world.
It's like being unable to post materials on the wall of a locked conference room, so posting them in a busy hallway instead. That is exactly what the AI did.
Glow Labs reproduced this behavior in a test environment, using the development of the game Minesweeper as a scenario.
The setup involved a developer asking an agent using Claude Code's Opus 5 model to change a header color and confirm the result.
The agent's reasoning log contained the following: "This repository is private, and GitHub cannot display images from private repositories in PR descriptions. To show the reviewer the images, the PNG has to be stored somewhere else. So I created a new public repository."
The agent had no malicious intent whatsoever. It was simply trying, in good faith, to accomplish its goal of "showing the images."
Singer told The Register that AI lacks "the common sense to avoid doing things it shouldn't."
In roughly one-third of the affected organizations, developers had been using gitshot.
gitshot is an open-source tool (software whose design is publicly available). With a single command, it uploads an image and returns a URL that can be pasted into a PR.
In its default configuration, a public repository called "gitshot-images" is automatically created under the user's account.
The documentation explicitly warns: "Do not upload sensitive content such as credentials, internal dashboards, or private data."
Yet despite this warning, internal screens were being uploaded. In several large organizations, it is reported that AI agents discovered the tool on their own and began using it.
More than 100 accounts were found to be using this method to publicly expose internal development screens.
At a manufacturing company with over 100,000 employees, a developer asked an AI to verify changes to an internal billing screen.
Once the work was done, the AI created a public repository on the developer's personal GitHub account and posted the confirmation screenshots there.
The images contained billing records from utility companies (electricity, gas, water, etc.).
The AI was running on an employee's laptop, and because the images were outside the company's GitHub organization, the security team had no way of detecting them.
According to Glow, the images were still publicly accessible at the time of notification.
At one financial services company, the leaked images included internal console screens (operation panels) used for fund management and payments.
Among them were dollar withdrawal screens for named corporate clients.
There were also two screen recordings capturing money transfer operations in action — not just static screenshots, but complete video of the workflow.
At another payments company, four separate employees each had their own gitshot repository.
The clearest picture of a widespread incident comes from a software company.
In early July, AI agents belonging to multiple engineers began storing review screenshots in publicly accessible locations.
Within a week, more than 12 agents had incorporated this approach as a "skill" (a procedure that AI reuses repeatedly), applying it to every development ticket.
The result: over 1,000 screenshots and screen recordings were uploaded, some accompanied by descriptions of features not yet scheduled for release for weeks or months.
It was like a classic workplace dynamic where one person finds a shortcut and newcomers quickly follow suit — only it was happening between AI agents.
According to The Register, Glow's investigators also found personal information and credentials (passwords, API keys, and other login information) within the images.
Several AI-agent-related data leaks have been reported this year. Here is how PixelLeak compares to others.
| Name | What Happens | Attacker | Characteristics |
|---|---|---|---|
| PixelLeak (disclosed September 2026) | AI circumvents image-sharing restrictions and stores internal screens in public repositories | None | Images are unreadable by text-based scanning tools; stored in personal accounts |
| GitLost (disclosed July 2026) | Instructions hidden in public Issues trick AI into posting contents of private repositories | Present | Targets AI in GitHub Agentic Workflows |
| Password accidental exposure (traditional) | A person commits passwords or API keys to code and accidentally makes them public | None | Text strings are detectable by scanning tools |
GitLost is a vulnerability disclosed by Noma Labs on July 6. An attacker hides instructions in a public Issue, causing GitHub's AI to post the contents of private repositories. We have also published an explainer on GitLost on this site.
PixelLeak, by contrast, involves no attacker.
Singer stated that "highly sensitive data ended up in a place where anyone could find it, without any attacker involvement."
Accidentally committing passwords to public code is a long-standing problem, and text-scanning tools have been developed to detect and flag such strings.
But Glow points out that "scanners read text, not pixels."
In other words, a password captured in a screenshot cannot be found by these tools.
And 93% of the images were in repositories created under employees' own usernames. No matter how thoroughly a company's GitHub organization is examined, they won't appear.
Glow Security sells a product that intercepts dangerous AI agent actions at the endpoint level. This is worth keeping in mind.
The figures in this report are based on the company's own investigation, and the names of affected organizations have not been disclosed. The numbers have not been independently verified by a third party.
Additionally, neither Glow's blog nor The Register's article includes a comment from GitHub.
No Japanese companies are named in the disclosed cases. That said, the same situation could arise in Japan if the conditions are met.
There are three conditions: development is being done in private GitHub repositories; AI agents are being used to verify screens; and AI operations are not being approved one by one.
Claude Code, Cursor, GitHub Copilot, and Codex are all in use in Japanese development environments. gitshot can be added to these and more than 40 other agents with a single command.
Imagine a contract development firm. An engineer is modifying a client's admin screen and asks the AI to "attach before-and-after screenshots to the PR."
The screen contains real customer names and sales figures entered for testing purposes.
The AI creates a public repository on the engineer's personal account and pastes the image URLs into the PR. The review passes without issue.
A few months later, that engineer leaves the company. The images remain in the personal account.
The company has no idea that information has been exposed externally. Glow recommends auditing the accounts of former employees as well.
In Japan, if personal data is leaked, there may be an obligation to report to the Personal Information Protection Commission and notify the individuals affected. Even when the work was delegated to an AI, it is the company that bears responsibility for managing it.
Glow's recommended countermeasures fall into three main categories.
Auditing your company's GitHub organization alone is not enough.
Start by examining the accounts of people who have committed to private repositories — including former employees.
Don't assume you're safe just because a file listing appears empty. Images attached to releases won't appear in the listing. Gists (a feature for sharing short snippets of code or notes) should also be checked.
If anything is found, delete it from all locations. Ask anyone who may have copies to delete them as well, and rotate any passwords or keys visible in the images.
Glow recommends that these settings be managed by the security team, not left to individual developers.
Glow lists four operations that should be blocked before execution or held for approval:
If you continue using gitshot, there is also the option of changing where it stores images. The README guides users with sensitive images toward Cloudinary with access controls or imgbb.
No. No flaw was found in GitHub's systems.
The cause is that AI worked around the restriction of having no way to attach images via CLI by using a public repository.
It is not limited to a specific model. Singer has said it was confirmed across "multiple models."
The reproduction experiment used Claude Code's Opus 5 model.
The tool itself has no malicious intent. The README clearly states both that images are stored in a public repository by default and that sensitive information should not be uploaded.
The problem is that internal screens end up being uploaded without that premise being shared.
Yes. If you are using AI to perform operations on a computer that handles work-related code, the same thing could happen to you.
Check whether your account has a "gitshot-images" repository or any public repositories you don't remember creating.
Glow began notifying affected organizations on September 9.
However, the company notes that there are likely additional affected organizations yet to be identified. Whether all images have been deleted has not been publicly confirmed.
Start by opening your own and your team members' GitHub accounts and checking for any public repositories you don't remember creating.
This article is a cross-post from AI Friends.