Seven Companies Breached After AI Assistants Tricked

Multiple firms breached after AI assistants were manipulated

Seven companies experienced security breaches when attackers exploited vulnerabilities in AI assistants, according to recent reports. These incidents reveal significant risks associated with AI-driven integrations across business environments.

AI Assistant Exploits Lead to Major Breaches

In a series of coordinated attacks, threat actors successfully tricked AI-powered assistants used by seven different organisations. The breaches were reported in June 2024, and affected companies span a range of sectors, though specific names have not been disclosed publicly. The incidents occurred as attackers manipulated AI agents into performing unauthorised actions or exposing sensitive information, bypassing standard security controls.

The attackers exploited the growing integration of AI agents within enterprise systems. These AI assistants, often designed to automate workflows or support customer queries, were tricked via crafted prompts or malicious data inputs. The result was the execution of commands or the sharing of confidential information without proper authorisation.

Timeline and Tactics

The breaches were detected in mid-June 2024, following unusual activity logs and unauthorised data access events. Investigations revealed that attackers targeted AI agents embedded in commonly used business applications. These AI assistants had been granted broad permissions to interact with internal systems, databases and third-party services.

  • June 2024: Attackers initiate contact with AI assistants, using crafted prompts to manipulate behaviour.
  • Within days: AI agents execute unauthorised actions, such as sharing internal data or modifying user permissions.
  • Detection: Security teams notice abnormal activity, including unexpected data exports and privilege escalations.
  • Response: Affected companies begin incident response, restricting AI assistant permissions and conducting forensic analysis.

At the time of reporting, the breaches have been contained but remain under investigation. There is ongoing analysis to determine the full scope of the data exposed and whether further exploitation has occurred.

How Attackers Manipulated AI Assistants

The core of these breaches lies in prompt injection, a technique where attackers craft inputs that persuade AI agents to override intended logic or ignore safeguards. By understanding how the AI interprets requests, the attackers managed to:

  • Request sensitive internal data, which the AI then retrieved and shared externally.
  • Instruct the AI to alter user permissions, granting attackers elevated access within company systems.
  • Trigger workflow automations that performed unauthorised actions, such as sending confidential documents to external accounts.

These attacks exploited the trust placed in AI agents and highlighted the lack of granular permission controls. In several cases, AI assistants were integrated with email, file storage, and customer databases with few restrictions, making it easier for attackers to pivot and access a broad range of resources.

Products and Versions Affected

While the specific AI platforms involved have not been identified in detail, the affected organisations were using a mix of commercially available AI assistants and custom-built integrations. The vulnerabilities stemmed from over-permissive access controls and insufficient monitoring of AI-driven activities, rather than flaws in the underlying AI models themselves. Both off-the-shelf and bespoke AI deployments proved susceptible to prompt injection and manipulation.

Current Exploitation Status

As of late June 2024, there is no evidence that the exploited vulnerabilities are being used in widespread, automated campaigns. However, the sophistication of the attacks and the speed at which multiple organisations were breached suggest that threat actors are actively probing for similar weaknesses elsewhere. Security researchers have warned that as AI adoption increases, so too will the frequency and complexity of these types of attacks.

Why These AI Assistant Breaches Matter

The events show that AI assistants, if not properly secured, can become high-value targets for cyber attackers. With business-critical data and workflow control increasingly entrusted to AI agents, prompt injection and social engineering against these systems present a new attack surface. The breaches at these seven companies serve as a stark warning that AI-driven automation must be accompanied by robust security controls.

Practical Steps for Organisations

In response to these incidents, organisations should:

  • Review the permissions granted to AI assistants and restrict them to the minimum necessary.
  • Monitor AI-driven activity for unusual behaviour, including unexpected data access or workflow execution.
  • Implement human-in-the-loop checks for sensitive actions initiated by AI agents.
  • Regularly update and audit AI integration points for emerging security vulnerabilities.

These targeted steps can reduce the risk of similar breaches and ensure AI assistants do not become a weak link in organisational defences.

Originally reported by Unknown.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call