2026-10-11 16:37 UTC

Intigriti researchers claim deployed customer-service agents confuse email identity and authorization boundaries, enabling unauthorized tool actions and confidential-data disclosure and requiring controls outside the language model.

state: seedheat: lowuncertainty: highknownscott: lowagentic-security customer-service-agents authenticationIntigritiAyoubInti De Ceukelaire

What is this?

Intigriti is promoting a research article, “Hacking AI customer service agents,” and its social snippet describes attacks involving email spoofing, sensitive-data leakage, and unauthorized tool calls. Its AI security page separately identifies customer-facing assistants exposing data and agents invoking tools or changing state as testing targets. The supplied snippets do not establish the article’s detailed demonstrations, affected deployments, or the roles of Ayoub and Inti De Ceukelaire; separate Stack Overflow and Cloud Security Alliance commentary supports authorization enforcement outside the model, but does not establish that recommendation as a finding of this Intigriti article.

Why it matters to Scott

The reported spoofing, unauthorized tool calls and data leakage illustrate failure modes Scott already addresses in Agent Provenance Stack and SiloOS: independently verify who authorised an action and structurally constrain capabilities and data access. The supplied material establishes neither a new mechanism affecting his builds nor Intigriti’s adoption of his external-enforcement position, so this is another example of an already-held position, not demonstrated consequential convergence; the radar tracks related authorization failures but no supplied page covers this exact article.
ip:framework.agent-provenance-stackip:framework.siloosradar:concept.agent-authorizationradar:concept.agent-authenticationradar:agent-context-privilege-escalationradar:flock-reservation-impersonation-incident
queries asked of Scott's wikis
  • agent tool authorization enforced outside language model
  • email identity verification user impersonation trust boundaries
  • agent harness scoped credentials least privilege tool execution
  • prompt injection confused deputy runtime policy enforcement
  • RAG confidential data access permissions

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 962h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-01 14:00⭐ origin echo-reconstructedReports customer-service agent attacks involving email spoofing, unauthorized tool calls, authentication bypasses, and secret disclosure, wi
Ayoub and Inti De Ceukelaire on blog (echo) · attributed from hn.story.49699526
—
09-14 16:26first on hacker news · published · +314.4hHacking AI customer service agents
snikolaev
—
09-14 16:26amplified on hacker news 👑hn.story.49699526
snikolaev
peak 36 · 5 comments · 100% of case engagement
09-14 17:22our radar first saw it · +315.4hdiscovery anchor: hn.story.49699526—
pace: p61 vs 519 stories at the 720h mark (now 962h old) — ahead of aipass-false-success-fixes (1.0x), behind holaos-shared-agent-workspace (0.9x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnHacking AI customer service agents
Retrieved article excerpt

Open article · Retrieved 2026-09-14T17:24:43.524520+00:00

# Hacking AI customer service agents

By Ayoub and Inti De Ceukelaire

September 2, 2026

[Download](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents.pdf)

Table of contents

- [Weaponizing chatbots via email](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#weaponizing-chatbots-via-email)
  - [Sending phishing emails from support@](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#sending-phishing-emails-from-support)
  - [Invoking tool calls](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#invoking-tool-calls)
  - [Multiple From email headers](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#multiple-from-email-headers)
  - [Sending signed e-mails to the agent as the victim](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#sending-signed-e-mails-to-the-agent-as-the-victim)
- [Bypassing multi-factor authentication (2-FA/MFA) in AI agents](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-multi-factor-authentication-2-famfa-in-ai-agents)
- [Bypassing multi-factor authentication (2-FA/MFA) in Interactive Voice Responses (IVR)](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-multi-factor-authentication-2-famfa-in-interactive-voice-responses-ivr)
- [Bypassing authentication via email address smuggling](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-authentication-via-email-address-smuggling)
- [Exfiltrating OTPs from third-party accounts with AI agents](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#exfiltrating-otps-from-third-party-accounts-with-ai-agents)
- [1. Instructing the AI agent](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#1-instructing-the-ai-agent)
  - [2. Exfiltrating the OTP](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#2-exfiltrating-the-otp)
  - [OTP exfiltration via Chrome's AI assistant](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#otp-exfiltration-via-chromes-ai-assistant)
- [Exploiting AI agent's KBs](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#exploiting-ai-agents-kbs)
  - [1. Asymmetric Messaging](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#1-asymmetric-messaging)
  - [2. Context & Conversation](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#2-context-and-conversation)
  - [3. Identity & Audience](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#3-identity-and-audience)
- [Conclusion](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#conclusion)

[Add us as a preferred source on](https://www.google.com/preferences/source?q=intigriti.com)

Table of contents

- [Weaponizing chatbots via email](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#weaponizing-chatbots-via-email)
  - [Sending phishing emails from support@](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#sending-phishing-emails-from-support)
  - [Invoking tool calls](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#invoking-tool-calls)
  - [Multiple From email headers](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#multiple-from-email-headers)
  - [Sending signed e-mails to the agent as the victim](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#sending-signed-e-mails-to-the-agent-as-the-victim)
- [Bypassing multi-factor authentication (2-FA/MFA) in AI agents](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-multi-factor-authentication-2-famfa-in-ai-agents)
- [Bypassing multi-factor authentication (2-FA/MFA) in Interactive Voice Responses (IVR)](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-multi-factor-authentication-2-famfa-in-interactive-voice-responses-ivr)
- [Bypassing authentication via email address smuggling](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-authentication-via-email-address-smuggling)
- [Exfiltrating OTPs from third-party accounts with AI agents](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#exfiltrating-otps-from-third-party-accounts-with-ai-agents)
- [1. Instructing the AI agent](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#1-instructing-the-ai-agent)
  - [2. Exfiltrating the OTP](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#2-exfiltrating-the-otp)
  - [OTP exfiltration via Chrome's AI assistant](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#otp-exfiltration-via-chromes-ai-assistant)
- [Exploiting AI agent's KBs](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#exploiting-ai-agents-kbs)
  - [1. Asymmetric Messaging](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#1-asymmetric-messaging)
  - [2. Context & Conversation](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#2-context-and-conversation)
  - [3. Identity & Audience](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#3-identity-and-audience)
- [Conclusion](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#conclusion)

[Add us as a preferred source on](https://www.google.com/preferences/source?q=intigriti.com)

As AI agents are deployed to automate more tasks, they become more capable. And as the famous quote goes: "With great power comes great responsibility." Assuming that humans in the loop can mitigate that risk turns out to be.

At Bug Bounty Village during DEF CON 34, [Inti De Ceukelaire](https://www.linkedin.com/in/intidc/), Founding Member of Intigriti, delivered a talk on how attackers can abuse today's AI agents in ways most defenders haven't thought about yet, from tricking agents into spilling secrets to forcing them to carry out unauthorized actions on behalf of the victim. This resulted in over $50,000+ in bounties in just a few weekends, without actually poking the target with Burp Suite or any automated scanners.

Let's dive in!

#### Special thanks to @intidc!

Special thanks to [Inti De Ceukelaire](https://www.linkedin.com/in/intidc/) for his extensive research and delivering the talk at BBV during DEF CON 34. Access the full slides through the following link: [go.intigriti.com/HHITLS2026](https://go.intigriti.com/HHITLS2026)

## Weaponizing chatbots via email

You've certainly come across AI chatbots before. Most are capable of retrieving data from the company's knowledge base and providing answers based on your questions. However, some of them are also equipped with additional context or actions that can be misused if access is not correctly enforced.

Let's take a look at an example whereby we can trick an agent into composing and sending phishing emails.

Most chatbots, whether AI-powered or not, allow you to send a recap or transcript of your chat conversation. The underlying function copies your entire chat and emails it to your end. This feature can be abused, for instance, to send phishing emails.

Example of a prompt injection in LLMs

While this may work, most security teams would approach such findings as informative rather than an impactful bug that requires immediate attention. However, we've also noticed that most email transcript services are also susceptible to some form of email spoofing. In practice, this would mean that we can trick the AI agent responsible for processing incoming emails into believing that we're sending from the victim's email inbox. And of course, this goes paired with all sorts of attacks.

### Sending phishing emails from support@

In one case, we came across a chatbot that allows interaction in both ways. It allowed us to receive transcripts while also keeping the conversation going through email. The validation also turned out to be flawed, as spoofing the `From` email header made the chatbot think the email originated from the victim. In combination with a simple prompt, it allowed us to send a phishing email to the victim from the support email.

When the victim opens the email, the `From` header will appear as trusted and make the email look less suspicious.

Using transcripts as payload delivery

### Invoking tool calls

Now suppose the bot also has capabilities to perform authorized actions such as editing your profile details, reading your billing statements, or even transferring data or money to another account. With spoofing, we've already proven that some chatbots will fail to correctly verify the sender with the account owner. But would it also be possible for us to read the response sent to the victim's email?

Invoking tool calls in LLM chatbots

In some instances, we've noticed that this is possible. And we actually have multiple ways to do so. One notable method is to simply include our own email within the CC of the spoofed email. That would ensure the chatbot includes us in the CC of the reply, resulting in us receiving a copy of the confidential data.

Reading unauthorized LLM tool invocation response via email

### Multiple From email headers

So far, we've been spoofing the `From` header to make the agent believe the email came from the victim. But what if the target enforces email authentication, making spoofing impossible? Let's take a deeper dive into how the email protocol itself can be turned against us.

Digging deeper into RFCs, we can see that [RFC 822 allows](https://datatracker.ietf.org/doc/html/rfc822) sending an email with multiple `From` headers. In practice, this would mean sending an email with a **Header From**, which is what you see rendered in your mail client, and an **Envelope From**, which is what mail servers actually use during delivery and authentication. SPF and DKIM validate the Envelope From. The agent, however, reads the From header to determine whose account to look up, and responds to whichever address it's told to reply to.

An attacker can exploit this by crafting an email with two `From` addresses and a `Sender` header:

Sending emails with multiple From addresses

The email authentication layer runs SPF on the first `From` address, `[email protected]`, a domain the attacker controls, and passes successfully. The agent's action layer then looks up the account associated with the last `From` address, `[email protected]`, and retrieves the victim's data. Finally, the agent replies to the `Sender` header, delivering the response straight to `[email protected]`.

Sending emails with multiple From addresses

Using this method, we can pass the email verification checks and act on behalf of the victim to query and receive his/her data. There's another scenario which we'll explore shortly that goes even a step further in the event this logic flaw cannot be reproduced, leaving you with the only option to send the email as the victim.

### Sending signed e-mails to the agent as the victim

There's another scenario that goes even a step further in the event the previous logic flaw could not be reproduced. In such cases, we be 
snikolaev365
🟧 echo.blog ⭐Reports customer-service agent attacks involving email spoofing, unauthorized tool calls, authentication bypasses, and secret disclosure, wiAyoub and Inti De Ceukelaire——

Interpretation history

Decision trace