Submit incident
Documented

An AI Coding Agent Wiped DataTalks.Club's Production Infrastructure Because No One Verified the State File

February 26, 2026
Curated by Team Raidu · Reviewed by Shiva Ganesh
aiid:1424View source ↗
LinkedInX

What happened

In February 2026, the course platform behind DataTalks.Club went offline after an AI coding agent executed a Terraform destroy command against the production environment. The command removed the VPC, ECS cluster, load balancers, bastion host, RDS database, and automated snapshots from the live system, taking down a platform that had accumulated 2.5 years of data. AWS later restored a snapshot, but the deletion made that recovery uncertain for some period before it happened.

The sequence that made the deletion possible began with a state file. Terraform tracks its view of cloud resources in a state file, and the agent was working from a version that had been restored from an outdated copy. When it ran, the stale file described an environment that no longer matched what was live. From there, a destroy command was the natural result of reconciling what the state expected against what actually existed. The agent did not malfunction. It performed the action it had been authorized to perform.

DataTalks.Club runs online courses. The infrastructure that disappeared was not an isolated component or a test environment: it was the full production stack. Load balancers, database, networking, and the snapshots that should have served as a safety net all went with it. The platform was offline while AWS worked to restore what it had. The recovery succeeded, but it depended on a cloud-provider-level backup that the platform's operators had not confirmed was current at the time the command ran.

The conditions that made this possible were structural, not incidental. An AI agent had write access to production infrastructure. There was no confirmation step before destructive commands. There was no gate requiring a human to review the scope of a destroy before it executed. The stale state file added a second failure: the agent's model of the environment was wrong, but nothing in the workflow caught that mismatch before the command ran. Any system that combines write access, irreversible commands, and a stale state has removed the margin that human review would otherwise provide.

What the incident exposes is the absence of a verification step between an agent's plan and the execution of an irreversible action against a production system. The agent could authorize and execute a full infrastructure teardown without a logged human sign-off, without a confirmation that the state file was current, and without any record of who had reviewed the blast radius before the command ran. That is the gap accountability infrastructure is built to close: a provable record of what a system did, who confirmed it before execution, and whether the inputs it acted on had been verified.

Reported impact

Affected parties
Not publicly disclosed
Harm type
Not publicly disclosed
Scale
Not publicly disclosed
Financial impact
Not publicly disclosed
Regulatory action
Not publicly disclosed

Classification

Organization
Not publicly disclosed
AI system
Not publicly disclosed
Industry
Not publicly disclosed
Country
Not publicly disclosed
Provider
Not publicly disclosed
Incident type
Not publicly disclosed

Relevant governance controls

Governance control mapping is not available for this record.

  • No controls mappedNot publicly disclosed

Control mapping is analytical. It does not state that any control would have prevented the incident.

Sources and evidence

This record was researched and written by the Index. The event is also catalogued in the following database, which is listed for cross-reference.

AI Incident Database
Also catalogued in
An AI Coding Agent Wiped DataTalks.Club's Production Infrastructure Because No One Verified the State File
2026-02-26