The attack utilizes an indirect prompt injection that can be hidden in email HTML (tiny fonts, white-on-white text, layout tricks) so the user never notices the commands, but the agent still reads and obeys them. [...] Unlike prior research that relied on client-side image rendering to trigger the leak, this attack leaks data directly from OpenAI's cloud infrastructure, making it invisible to local or enterprise defenses.
Curated from thehackernews.com · 19 September 2025 →
Radware's researchers pointed the same email trick at ChatGPT's Deep Research agent with the Gmail connector switched on. The difference from every earlier version of this attack is where the data leaves from: the agent browses on OpenAI's infrastructure, so the outbound request never touches the company network and no gateway, proxy or endpoint agent sees it happen. They named it ShadowLeak, reported it on 18 June 2025, and OpenAI fixed it in early August. Their proof of concept used Gmail, but the same shape applies to any connector the agent can reach, and the list includes Box, Dropbox, GitHub, Google Drive, HubSpot, Outlook, Notion and SharePoint.