Skip to content
Menu
Menu

AI Coding Assistants Posted 13,000 Internal Company Screenshots Publicly, Security Firm Says

Glow Labs found the images in public GitHub accounts belonging to developers at more than 300 organizations, most of them outside the view of company security teams.

 

AI coding assistants posted more than 13,000 internal company screenshots that anyone on the internet could view, security company Glow said on Sept. 29. AI coding assistants are AI systems that write and change software at a developer’s instructions.

Glow’s research team, Glow Labs, traced the images to developers at more than 300 organizations, including one of the world’s largest technology companies, a company building some of the most powerful AI models, and a Fortune 500 travel company. Glow did not name any of them.

The images were on GitHub, the website where many companies store and review their software code. Glow found them in more than 900 separate project folders on the site.

The assistants made the images public after they could not attach them privately

Glow said each case began the same way. A developer asked an AI coding assistant to change how a screen in the company’s software looked, then to attach before-and-after screenshots so a colleague could check the change.

A person can attach a picture to a private project on GitHub through a web browser. AI coding assistants work by typing text commands instead of clicking in a browser. Glow said GitHub gives no way to attach a picture to a private project using text commands.

The assistants then created a new public folder on GitHub, put the screenshots there, and linked to them from the developer’s private project. Anyone can view or download what is in a public folder. Glow said the assistants did not consider the security consequences.

Screenshots showed customer billing records and money-transfer screens

At a manufacturer with more than 100,000 employees, an assistant posted screenshots of an internal billing screen showing billing records for a utility company. Glow said the images were still public when it notified the manufacturer.

At a financial services firm, the public images showed the internal screens staff uses to move money, a screen for withdrawing dollars from the account of a named institutional client, and two screen recordings that walked through the money-movement screens.

At a software vendor, assistants posted more than 1,000 screenshots and screen recordings of the company’s product, with written descriptions of features that were weeks or months from release.

Most images sat in employees’ personal accounts, where company security teams were not looking

In 93% of cases, Glow said, the images were in a folder created under the employee’s own GitHub username, not in the company’s GitHub account. At the manufacturer, the assistant ran on the employee’s laptop and posted to the employee’s personal account, and the company’s security team did not find the images.

Glow said the scanning software companies use to look for leaked information reads text, not pictures.

The practice spread through a free tool and from one assistant to others

At about a third of the affected organizations, developers were running gitshot, a small free program that posts screenshots publicly on GitHub so colleagues can view them. Glow said assistants at several large organizations found the program and used it to post the screenshots. Glow found more than 100 public accounts leaking internal work through gitshot, including four employees at one payments company.

At the software vendor, assistants working for several engineers began posting screenshots publicly in early July. Glow said that within a week, more than a dozen assistants had made public posting a standard step to repeat on every task.

Glow did not say which assistants were involved or whether outsiders saw the images

Glow did not identify the AI coding assistants used at the affected organizations. In its own test, Glow reproduced the public posting with Anthropic’s Claude Code running the Opus 5 model. Asked to change a header color in a private project and show the result, the assistant created a public folder for the screenshots.

Glow did not say whether anyone outside the affected organizations viewed or downloaded the images, or how many have been removed. Every number in Glow’s report is its own count. Glow sells software that blocks AI coding assistants from posting publicly, and it published advice for companies checking whether they are affected.

Glow began notifying affected organizations on Sept. 9 and said other organizations are probably affected.

Clayton Rifkind

Clayton Rifkind is the Founder and Senior Editor of AI Risk Today. He also advises on business development for ESG Today, a leading source of ESG investment news and research for institutional investors and corporate leaders. He has 20+ years of experience in B2B technology, leading strategy and execution of go-to-market plans across software, enterprise platforms, and mobile applications. He founded two consultancies advising startups and Fortune 1000 companies, including Autodesk, Intel, and Microsoft. He began his career in the San Francisco advertising scene working with brands such as Hewlett-Packard, Intel, Microsoft, Symantec, and Wells Fargo. Clayton launched AI Risk Today in 2025 after two decades of watching enterprises adopt transformative technologies, and seeing how often risk, governance, and compliance considerations lagged behind. His reporting draws on primary sources including regulatory filings, court documents, and official announcements, with a focus on what AI developments mean for the executives accountable for managing them. Reach him at Reach him at [email protected] or on LinkedIn.

Essential AI Risk Intelligence

Daily insights on AI governance, regulation, and enterprise risk management. Trusted by Chief Risk Officers and compliance leaders globally.

By subscribing, you agree to receive our daily newsletter. Unsubscribe anytime.

Advertise with AI RIsk Today, Today!