Global fintech and funding innovation ecosystem

ShadowLeak Shows Zero Click AI Agent Risk

Cybersecurity | Sep 23, 2025

Freepik DC Studio, AI Agent security

Image: Freepik/DC Studio

Radware Reveals How A Hidden Email Prompt Made A ChatGPT Agent Leak Gmail Data

On September 18, 2025, researchers at Radware disclosed a zero click indirect prompt injection called ShadowLeak that caused ChatGPT Deep Research to leak Gmail data after it encountered a booby trapped email.  It's a new class of risk where hidden instructions can manipulate agents while being invisible to users, so NCFA wants to ensure that fintechs and key stakeholders are aware of how attackers can turn AI helpers into data thieves in a way that users including developer's can't see.

ShadowLeak AI Agent Risk

Radware’s analysis shows that the leak originated from OpenAI’s own cloud infrastructure rather than a user’s device. A malicious email carried hidden HTML instructions such as white text on a white background. When the user later asked the agent to summarize emails, the agent followed the invisible prompt and sent private details to an attacker controlled URL.

Because the action happened in the cloud, the victim’s network defenses never saw it.

See:  Elliptic Report Shows Cross-Chain Crime Reaches $21.8B

The researchers warned that the same trick could work on other connectors including Google Drive, Dropbox, Outlook, calendars, and GitHub. That means sensitive business data such as financial contracts, HR records, and meeting notes could also be exposed.

Radware reported the issue on June 18, 2025. OpenAI deployed fixes by early August and closed the case on September 3. An OpenAI spokesperson told Recorded Future News that the company continually improves safeguards against exploits like prompt injections.

Other Recent AI Agent Exploits

ShadowLeak is not the only case of an AI agent being manipulated into acting against its user.

At Black Hat in August 2025, researchers demonstrated an attack called AgentFlayer that used a poisoned Google Drive document to leak secrets through ChatGPT connectors. The document contained hidden instructions that looked harmless to a person but were machine readable. When the agent processed the file, it followed the malicious prompt and attempted to extract sensitive data.

See:  BlackRock Tests Multi Agent AI in Equity Portfolios

On August 20, 2025, security researchers at Brave (website browser company) disclosed a similar flaw in Perplexity’s Comet browser. They showed how a hidden Reddit prompt could read Gmail one time passcodes and expose them to an attacker.

On September 13, 2025, Tom's Hardware wrote about a malicious Google Calendar invite method could steer ChatGPT agents with connectors enabled to leak sensitive data, again by embedding hidden instructions in content that appears ordinary to the user.

Guidance and Protection

From Radware’s advisory and government sources such as the U.S. National Institute of Standards and Technology, here are some suggested practices.

  • Limit connector permissions and revoke unused access
  • Sanitize incoming content to strip hidden instructions before agents process it
  • Log all agent actions and monitor for suspicious behaviour
  • Restrict or block external connections to unknown URLs
  • Use layered defenses including prompt injection filters, HTML sanitization, and user confirmations for risky tasks
  • Review connectors regularly to ensure only required apps are linked
  • Train staff on the risks of connecting agents to sensitive systems
  • Use multiple layered defenses (don't rely on a single point of failure)

Why It Matters for Fintech

AI agents are being connected to sensitive systems at a time when fintech firms face increasing scrutiny over privacy and security.

If a connector exploit can quietly leak contracts, loan records, or customer identifiers, the implications are massive, such as regulatory fines, reputational loss, and reduced trust from partners and investors.

In Canada, where regulators are preparing rules on open banking and digital identity, firms cannot afford to treat agent security as an afterthought. Research shows that 57% to 80% of injection attempts succeed when attackers repeat them (i.e. 25 times), which is why layered defenses are essential.

See:  AI Psychosis Threatens Trust in Innovation

Banks and financial technology firms must implement agent safeguards into compliance frameworks, risk models, and vendor contracts that will protect customer trust and reduce liability. Canadian fintechs should approach agent security not only as a technical concern but part of core competitiveness functionality.

Board oversight is also critical, as regulators and investors will expect firms to demonstrate how they manage AI risks.


NCFA Jan 2018 resizeThe National Crowdfunding & Fintech Association (NCFA Canada) is a financial innovation ecosystem that provides education, market intelligence, industry stewardship, networking and funding opportunities and services to thousands of community members and works closely with industry, government, partners and affiliates to create aa vibrant and innovative fintech and funding industry in Canada. Decentralized and distributed, NCFA is engaged with global stakeholders and helps incubate projects and investment in fintech, alternative finance, crowdfunding, peer-to-peer finance, payments, digital assets and tokens, artificial intelligence, blockchain, cryptocurrency, regtech, and insurtech sectors. Join Canada's Fintech & Funding Community today FREE! Or become a contributing member and get perks. For more information, please visit: www.ncfacanada.org

NCFA Financial Innovation MapNCFA Innovation Opportunity BriefsNCFA Fintech Insights
NCFA Fintech WhispererNCFA Fintech Fridays PodcastNCFA Weekly Newsletter

 

Leave a Reply

Your email address will not be published. Required fields are marked *