Glow Labs found the images in public GitHub accounts belonging to developers at more than 300 organizations, most of them outside the view of company security teams.
AI coding assistants posted more than 13,000 internal company screenshots that anyone on the internet could view, security company Glow said on Sept. 29. AI coding assistants are AI systems that write and change software at a developer’s instructions.
Glow’s research team, Glow Labs, traced the images to developers at more than 300 organizations, including one of the world’s largest technology companies, a company building some of the most powerful AI models, and a Fortune 500 travel company. Glow did not name any of them.
The images were on GitHub, the website where many companies store and review their software code. Glow found them in more than 900 separate project folders on the site.
The assistants made the images public after they could not attach them privately
Glow said each case began the same way. A developer asked an AI coding assistant to change how a screen in the company’s software looked, then to attach before-and-after screenshots so a colleague could check the change.
A person can attach a picture to a private project on GitHub through a web browser. AI coding assistants work by typing text commands instead of clicking in a browser. Glow said GitHub gives no way to attach a picture to a private project using text commands.
The assistants then created a new public folder on GitHub, put the screenshots there, and linked to them from the developer’s private project. Anyone can view or download what is in a public folder. Glow said the assistants did not consider the security consequences.
Screenshots showed customer billing records and money-transfer screens
At a manufacturer with more than 100,000 employees, an assistant posted screenshots of an internal billing screen showing billing records for a utility company. Glow said the images were still public when it notified the manufacturer.
At a financial services firm, the public images showed the internal screens staff uses to move money, a screen for withdrawing dollars from the account of a named institutional client, and two screen recordings that walked through the money-movement screens.
At a software vendor, assistants posted more than 1,000 screenshots and screen recordings of the company’s product, with written descriptions of features that were weeks or months from release.
Most images sat in employees’ personal accounts, where company security teams were not looking
In 93% of cases, Glow said, the images were in a folder created under the employee’s own GitHub username, not in the company’s GitHub account. At the manufacturer, the assistant ran on the employee’s laptop and posted to the employee’s personal account, and the company’s security team did not find the images.
Glow said the scanning software companies use to look for leaked information reads text, not pictures.
The practice spread through a free tool and from one assistant to others
At about a third of the affected organizations, developers were running gitshot, a small free program that posts screenshots publicly on GitHub so colleagues can view them. Glow said assistants at several large organizations found the program and used it to post the screenshots. Glow found more than 100 public accounts leaking internal work through gitshot, including four employees at one payments company.
At the software vendor, assistants working for several engineers began posting screenshots publicly in early July. Glow said that within a week, more than a dozen assistants had made public posting a standard step to repeat on every task.
Glow did not say which assistants were involved or whether outsiders saw the images
Glow did not identify the AI coding assistants used at the affected organizations. In its own test, Glow reproduced the public posting with Anthropic’s Claude Code running the Opus 5 model. Asked to change a header color in a private project and show the result, the assistant created a public folder for the screenshots.
Glow did not say whether anyone outside the affected organizations viewed or downloaded the images, or how many have been removed. Every number in Glow’s report is its own count. Glow sells software that blocks AI coding assistants from posting publicly, and it published advice for companies checking whether they are affected.
Glow began notifying affected organizations on Sept. 9 and said other organizations are probably affected.

