Close Menu
Finsider

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Could Your Social Security Payments Be Garnished Due to Unpaid Debts? What To Know First

    March 14, 2026

    PSA: Don’t buy a $4,400 gray market Samsung TriFold on eBay

    March 14, 2026

    HELOC and home equity loan rates Saturday, March 14, 2026: Declining rates boost affordability

    March 14, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Could Your Social Security Payments Be Garnished Due to Unpaid Debts? What To Know First
    • PSA: Don’t buy a $4,400 gray market Samsung TriFold on eBay
    • HELOC and home equity loan rates Saturday, March 14, 2026: Declining rates boost affordability
    • Gross Profit vs. Operating Profit vs. Net Income Explained
    • ‘Not built right the first time’ — Musk’s xAI is starting over again, again
    • Stocks Extend Weekly Losing Streak: Stock Market Today
    • I asked ChatGPT if the FTSE 100 would hit 12,000 before 2027
    • This little-known energy company’s stock is rallying as Trump invokes 1950 powers for offshore California drilling
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Finsider
    • Markets & Ecomony
    • Tech & Innovation
    • Money & Wealth
    • Business & Startups
    • Visa & Residency
    Finsider
    Home»Tech & Innovation»Security researchers swiped secrets from Gmail. A ChatGPT agent helped
    Tech & Innovation

    Security researchers swiped secrets from Gmail. A ChatGPT agent helped

    FinsiderBy FinsiderSeptember 20, 2025No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Security researchers swiped secrets from Gmail. A ChatGPT agent helped
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Security researchers employed ChatGPT as a co-conspirator to plunder sensitive data from Gmail inboxes without alerting users. The vulnerability exploited has been closed by OpenAI but it’s a good example of the new risks inherent to agentic AI.

    The heist, called Shadow Leak and published by security firm Radware this week, relied on a quirk in how AI agents work. AI Agents are assistants that can act on your behalf without constant oversight, meaning they can surf the web and click on links. AI companies laud them as a massive timesaver after users authorize their access to personal emails, calendars, work documents, etc.

    Radware researchers exploited this helpfulness with a form of attack called a prompt injection, instructions that effectively get the agent to work for the attacker. The powerful tools are impossible to prevent without prior knowledge of a working exploit and hackers have already deployed them in creative ways including rigging peer review, executing scams, and controlling a smart home. Users are often entirely unaware something has gone wrong as instructions can be hidden in plain sight (to humans), for example as white text on a white background.

    The double agent in this case was OpenAI’s Deep Research, an AI tool embedded within ChatGPT that launched earlier this year. Radware researchers planted a prompt injection in an email sent to a Gmail inbox the agent had access to. There it waited.

    When the user next tries to use Deep Research, they would unwittingly spring the trap. The agent would encounter the hidden instructions, which tasked it with searching for HR emails and personal details and smuggling these out to the hackers. The victim is still none the wiser.

    Getting an agent to go rogue — as well as managing to successfully get data out undetected, which companies can take steps to prevent — is no easy task and there was a lot of trial and error. “This process was a rollercoaster of failed attempts, frustrating roadblocks, and, finally, a breakthrough,” the researchers said.

    Unlike most prompt injections, the researchers said Shadow Leak executed on OpenAI’s cloud infrastructure and leaked data directly from there. This makes it invisible to standard cyber defenses, they wrote.

    Radware said the study was a proof-of-concept and warned that other apps connected to Deep Research — including Outlook, GitHub, Google Drive, and Dropbox — may be vulnerable to similar attacks. “The same technique can be applied to these additional connectors to exfiltrate highly sensitive business data such as contracts, meeting notes or customer records,” they said.

    OpenAI has now plugged the vulnerability flagged by Radware in June, the researchers said.

    Agent ChatGPT Gmail Helped researchers secrets security swiped
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleHere’s How Much More You’ll Pay
    Next Article The Five Best Cruise Lines for Retirees
    Finsider
    • Website

    Related Posts

    Money & Wealth

    Could Your Social Security Payments Be Garnished Due to Unpaid Debts? What To Know First

    March 14, 2026
    Tech & Innovation

    PSA: Don’t buy a $4,400 gray market Samsung TriFold on eBay

    March 14, 2026
    Tech & Innovation

    ‘Not built right the first time’ — Musk’s xAI is starting over again, again

    March 14, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Cursor snaps up enterprise startup Koala in challenge to GitHub Copilot

    July 18, 2025

    What is Mistral AI? Everything to know about the OpenAI competitor

    July 18, 2025

    Analyst Report: Kinder Morgan Inc

    July 18, 2025
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Using Gen AI for Early-Stage Market Research

    July 18, 2025

    Cursor snaps up enterprise startup Koala in challenge to GitHub Copilot

    July 18, 2025

    What is Mistral AI? Everything to know about the OpenAI competitor

    July 18, 2025
    news

    Could Your Social Security Payments Be Garnished Due to Unpaid Debts? What To Know First

    March 14, 2026

    PSA: Don’t buy a $4,400 gray market Samsung TriFold on eBay

    March 14, 2026

    HELOC and home equity loan rates Saturday, March 14, 2026: Declining rates boost affordability

    March 14, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    © 2020 - 2026 The Finsider . Powered by LINC GLOBAL Inc.
    • Contact us
    • Guest Post Policy
    • Privacy Policy
    • Terms of Service

    Type above and press Enter to search. Press Esc to cancel.