Hacker News·4 min read·medium

Hacking AI customer service agents

S
snikolaev
Hacking AI customer service agents
AI Summary

This article details how AI customer service agents can be exploited by attackers to spill secrets or perform unauthorized actions, as presented at DEF CON 34 by Inti De Ceukelaire. It highlights vulnerabilities like tricking agents into sending phishing emails via chat transcript features or email spoofing.

Why it matters

As AI agents become more capable and widely deployed, understanding and mitigating these security vulnerabilities is critical to prevent data breaches, unauthorized actions, and maintain user trust. The research demonstrates practical attack vectors that yield significant bounties.

Dive DeeperCreate a free account to unlock

As AI agents are deployed to automate more tasks, they become more capable. And as the famous quote goes: "With great power comes great responsibility." Assuming that humans in the loop can mitigate that risk turns out to be.

At Bug Bounty Village during DEF CON 34, Inti De Ceukelaire , Founding Member of Intigriti, delivered a talk on how attackers can abuse today's AI agents in ways most defenders haven't thought about yet, from tricking agents into spilling secrets to forcing them to carry out unauthorized actions on behalf of the victim. This resulted in over $50,000+ in bounties in just a few weekends, without actually poking the target with Burp Suite or any automated scanners.

Special thanks to @intidc! Special thanks to Inti De Ceukelaire for his extensive research and delivering the talk at BBV during DEF CON 34. Access the full slides through the following link: go.intigriti.com/HHITLS2026

Continue reading on Headlinne

Create a free account to read the full article.

Read full article →
technologyai

Get smarter about the news

Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.

Create free account

Already have an account? Sign in