{"id":93133,"date":"2025-08-19T00:47:09","date_gmt":"2025-08-19T00:47:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/us\/93133\/"},"modified":"2025-08-19T00:47:09","modified_gmt":"2025-08-19T00:47:09","slug":"a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/us\/93133\/","title":{"rendered":"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers"},"content":{"rendered":"<p>Microsoft has published many examples of how businesses can build AI agents in Copilot Studio to automate multi-step tasks, without a human in the loop.<\/p>\n<p>One such example, <a href=\"https:\/\/www.youtube.com\/watch?v=qxMi-tLg4MA\" target=\"_blank\" rel=\"noopener nofollow\">as shared on YouTube<\/a>, is a customer service agent built by McKinsey &amp; Co..<\/p>\n<p>The AI agent autonomously interacts with customers, scouring internal knowledge bases and data systems to share responses to their queries.<\/p>\n<p>Such a possibility represents a major leap for customer-facing chatbots, which, until recently, relied on rigid decision trees that broke whenever customers went off-script.<\/p>\n<p>Thanks to this tech advancement, <a href=\"https:\/\/www.cxtoday.com\/contact-center\/agentic-ai-gartner-predicts-80-of-customer-problems-solved-without-human-help-by-2029\/\" target=\"_blank\" rel=\"noopener nofollow\">Gartner has predicted that agentic AI will solve 80 percent of customer problems by 2029<\/a>.<\/p>\n<p><a href=\"https:\/\/www.cxtoday.com\/customer-data-platform\/what-is-microsoft-copilot-studio-and-how-can-i-create-a-custom-agent\/\" target=\"_blank\" rel=\"noopener nofollow\">Microsoft Copilot Studio<\/a> has quickly become a hallmark platform for building AI agents that converse with customers.<\/p>\n<p>Yet, researchers from Zenity, the security and governance platform provider, wanted to test how safe the customer-facing agents built on Copilot Studio are.<\/p>\n<p>As such, the firm created a replica of McKinsey\u2019s model, hooked it to a Salesforce sandbox org, and started \u201c<a href=\"https:\/\/labs.zenity.io\/p\/a-copilot-studio-story-2-when-aijacking-leads-to-full-data-exfiltration-bc4a\" target=\"_blank\" rel=\"noopener nofollow\">attacking it like it\u2019s the last agent on earth<\/a>.\u201d<\/p>\n<p>The result, shared at DEF CON 2025, proved nothing short of remarkable. Indeed, the researchers made the agent act without human verification, reveal private knowledge and internal tools, \u00a0and share complete Salesforce CRM records.<\/p>\n<p>Since then, the Zenity team has released a video of their attack, showcasing how it breached the AI agent, after Microsoft confirmed the injection no longer works.<\/p>\n<\/p>\n<p>However, while this attack may fail on Copilot Studio agents today, Zenity warns that over 3,500 public-facing agents remain wide open to similar prompt injections.<\/p>\n<p>As such, more examples of \u201cagent aijacking\u201d are just waiting to happen, and it may not be the good guys doing it next around.<\/p>\n<p>Summing up, Michael Bargury, Co-Founder &amp; CTO of Zenity, stated:<\/p>\n<p>Agent aijacking is not a vulnerability you can fix. It\u2019s inherent to agentic AI systems, a problem we\u2019re going to have to manage.<\/p>\n<p>If businesses can\u2019t manage this vulnerability while granting AI agents access to internal systems, they risk large-scale data breaches.<\/p>\n<p>Indeed, the demo highlights how AI agents, without an overarching governance structure, can turn into data extraction tools, attacking CRMs, internal communications, and billing information.<\/p>\n<p>Taking note of this, David Villalon, Co-founder &amp; CEO of Maisa, <a href=\"https:\/\/www.linkedin.com\/posts\/davidvillalonpardo_microsofts-copilot-studio-agents-got-hijacked-activity-7362084839275016194-Npqb\/\" target=\"_blank\" rel=\"noopener nofollow\">warned on LinkedIn<\/a>:<\/p>\n<p>For enterprises rushing to deploy autonomous AI: this is your warning. Every autonomous agent with data access is a potential attack vector. The convenience of \u201cno human in the loop\u201d becomes a catastrophic vulnerability when security fails.<\/p>\n<p>\u201cThe gap between AI capability and AI security keeps widening,\u201d continued Maisa. \u201cWe\u2019re building powerful autonomous systems on foundations that hackers can compromise with clever prompts.\u201d<\/p>\n<p>Given this, Maisa suggested that it might be time for brands to reconsider what \u201cautonomous\u201d means in enterprise AI, especially regarding customer-facing use cases.<\/p>\n<p>More Attacks on Salesforce Data<\/p>\n<p>While the ethical attack on the Copilot-built AI agent may not have spewed out any real Salesforce records, other recent not-so-ethical attacks have.<\/p>\n<p>Crucially, these are not the fault of Salesforce\u2019s security posture. Instead, they target the people using Salesforce\u2019s software through more conventional human-centric means.<\/p>\n<p>The latest attack targeted Workday. As shared in <a href=\"https:\/\/blog.workday.com\/en-us\/protecting-you-from-social-engineering-campaigns-update-from-workday.html\" target=\"_blank\" rel=\"noopener nofollow\">a company blog post<\/a> last week, bad actors contacted employees \u201cpretending to be from human resources or IT.\u201d<\/p>\n<p>In doing so, they stole \u201csome information from our third-party CRM platform\u201d, which Bleeping Computer has since asserted was Salesforce.<\/p>\n<p>The week prior, another Salesforce instance was breached, <a href=\"https:\/\/www.cxtoday.com\/crm\/the-google-salesforce-customer-data-breach-what-really-happened\/\" target=\"_blank\" rel=\"noopener nofollow\">this time at Google<\/a>.<\/p>\n<p>Yet, the attack method was different. In this case, the fraudsters tricked admins into installing a malicious version of Salesforce Data Loader.<\/p>\n<p>The fake solution mimicked Data Loader, extracting, updating, and deleting Salesforce data. But it also allowed attackers to quietly lift sensitive data from the backend.<\/p>\n<p>Both attacks, which notably breached two enterprise tech giants, are a reminder that any organization can fall victim to such attacks.<\/p>\n<p>Indeed, this isn\u2019t a dig at Salesforce. Every customer database is vulnerable, and \u2013 unfortunately \u2013 the tools available to attackers are multiplying.<\/p>\n<p>Whether through AI-generated deepfakes or manipulating new attack surfaces, the pressure on cybersecurity teams is reaching new heights.<\/p>\n<p>\u00a0<\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"Microsoft has published many examples of how businesses can build AI agents in Copilot Studio to automate multi-step&hellip;\n","protected":false},"author":2,"featured_media":93134,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[45],"tags":[182,3298,181,507,4320,63360,74,63361],"class_list":{"0":"post-93133","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-artificial-intelligence","8":"tag-ai","9":"tag-ai-agents","10":"tag-artificial-intelligence","11":"tag-artificialintelligence","12":"tag-chatbots","13":"tag-crm","14":"tag-technology","15":"tag-virtual-agent"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/93133","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/comments?post=93133"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/posts\/93133\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media\/93134"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/media?parent=93133"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/categories?post=93133"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/us\/wp-json\/wp\/v2\/tags?post=93133"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}