Unauthorized exposure of sensitive data is now the second most common AI security incident across the region. Downstream data policy violations, where AI systems reveal sensitive information to people who should not see it, accounted for 666 alerts per 10,000 tracked. Upstream incidents, where users send data into AI tools, remain more common at 8,300 alerts per 10,000, but the downstream number is the one catching security teams off guard.
Agents Are Opening New Data Pathways
The rise of AI agents is driving much of this downstream risk. The report points to growing use of the Model Context Protocol (MCP), an open standard that connects AI models and agents to external data sources, as clear evidence of expanding agentic activity.
Over a two month window, ANZ organizations saw an 89% increase in agents interacting with remote MCP servers, alongside a 69% rise in MCP related events overall. Each new connection creates another channel for data to move through, and many existing security tools were never built to monitor traffic like this.
Why Attacks Land Harder Here Than Elsewhere
Prompt injection and jailbreaking attempts are twice as common in ANZ compared to the global average, with 254 alerts per 10,000 against a global rate of 129. Both attack types aim to manipulate AI behavior or coax out sensitive information the system was not supposed to share.
A newer tactic, AI Engine Optimisation, involves attackers seeding malicious links to make them appear legitimate inside public AI tools. This pushed weekly click rates on malicious links to 67 per 100,000 workers, peaking at 175 by late 2025. A related tactic impersonates trusted AI brands through fake installers and altered developer tools. In May alone, 140 out of every 100,000 ANZ workers fell for one of these AI themed lures.
- Prompt injection and jailbreaking: 254 alerts per 10,000 in ANZ vs 129 globally
- Malicious link clicks: peaked at 175 per 100,000 workers weekly in late 2025
- Fake AI installer lures: 140 per 100,000 workers fell for these in May
Employees Are Bypassing Official Tools
Workplace AI usage is shifting fast, and unevenly. Anthropic’s Claude Platform leads adoption in ANZ, used by 81% of organizations, followed by ChatGPT at 68% and Microsoft 365 Copilot at 66%.
Managed AI tool adoption jumped from 34% to 75% over the reporting period, a sign that companies are actively trying to bring AI use under some kind of oversight. Despite that, 55% of employees still use personal AI accounts for work tasks. That gap, commonly called shadow AI, means a meaningful share of sensitive company data is passing through tools no security team ever approved or can see.
Phishing Is Losing Ground to AI Themed Lures
Traditional phishing appears to be working less often. Clicks on phishing links dropped by almost 60% in the report’s window, which sounds like good news until you see what replaced it. Attackers are adapting by exploiting trust in AI outputs and AI branded software instead of relying on the old email based tricks that security training has spent years addressing.
Ray Canzanese, Director of Netskope Threat Labs, described the shift as requiring a fundamentally different response. This is a whole new landscape that requires a new response, redesigning security architectures for the AI era.
Hashlytics Take
The headline stat here (data leaking out of AI systems) is really a symptom, not the disease. The actual story is that agentic AI is quietly building data pipelines faster than security teams can map them, and MCP adoption jumping 89% in two months is the clearest evidence of that. Most security tooling was designed to watch what goes into a system, not what an autonomous agent decides to pull out and hand to a downstream process. Organizations chasing shadow AI usage numbers are solving yesterday’s problem while agents open tomorrow’s.
Follow Hashlytics on Bluesky, Facebook, LinkedIn , Telegram and X to Get Instant Updates



