Retrieved article excerpt
Open article · Retrieved 2026-09-14T17:24:43.524520+00:00
# Hacking AI customer service agents
By Ayoub and Inti De Ceukelaire
September 2, 2026
[Download](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents.pdf)
Table of contents
- [Weaponizing chatbots via email](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#weaponizing-chatbots-via-email)
- [Sending phishing emails from support@](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#sending-phishing-emails-from-support)
- [Invoking tool calls](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#invoking-tool-calls)
- [Multiple From email headers](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#multiple-from-email-headers)
- [Sending signed e-mails to the agent as the victim](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#sending-signed-e-mails-to-the-agent-as-the-victim)
- [Bypassing multi-factor authentication (2-FA/MFA) in AI agents](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-multi-factor-authentication-2-famfa-in-ai-agents)
- [Bypassing multi-factor authentication (2-FA/MFA) in Interactive Voice Responses (IVR)](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-multi-factor-authentication-2-famfa-in-interactive-voice-responses-ivr)
- [Bypassing authentication via email address smuggling](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-authentication-via-email-address-smuggling)
- [Exfiltrating OTPs from third-party accounts with AI agents](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#exfiltrating-otps-from-third-party-accounts-with-ai-agents)
- [1. Instructing the AI agent](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#1-instructing-the-ai-agent)
- [2. Exfiltrating the OTP](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#2-exfiltrating-the-otp)
- [OTP exfiltration via Chrome's AI assistant](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#otp-exfiltration-via-chromes-ai-assistant)
- [Exploiting AI agent's KBs](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#exploiting-ai-agents-kbs)
- [1. Asymmetric Messaging](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#1-asymmetric-messaging)
- [2. Context & Conversation](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#2-context-and-conversation)
- [3. Identity & Audience](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#3-identity-and-audience)
- [Conclusion](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#conclusion)
[Add us as a preferred source on](https://www.google.com/preferences/source?q=intigriti.com)
Table of contents
- [Weaponizing chatbots via email](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#weaponizing-chatbots-via-email)
- [Sending phishing emails from support@](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#sending-phishing-emails-from-support)
- [Invoking tool calls](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#invoking-tool-calls)
- [Multiple From email headers](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#multiple-from-email-headers)
- [Sending signed e-mails to the agent as the victim](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#sending-signed-e-mails-to-the-agent-as-the-victim)
- [Bypassing multi-factor authentication (2-FA/MFA) in AI agents](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-multi-factor-authentication-2-famfa-in-ai-agents)
- [Bypassing multi-factor authentication (2-FA/MFA) in Interactive Voice Responses (IVR)](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-multi-factor-authentication-2-famfa-in-interactive-voice-responses-ivr)
- [Bypassing authentication via email address smuggling](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#bypassing-authentication-via-email-address-smuggling)
- [Exfiltrating OTPs from third-party accounts with AI agents](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#exfiltrating-otps-from-third-party-accounts-with-ai-agents)
- [1. Instructing the AI agent](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#1-instructing-the-ai-agent)
- [2. Exfiltrating the OTP](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#2-exfiltrating-the-otp)
- [OTP exfiltration via Chrome's AI assistant](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#otp-exfiltration-via-chromes-ai-assistant)
- [Exploiting AI agent's KBs](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#exploiting-ai-agents-kbs)
- [1. Asymmetric Messaging](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#1-asymmetric-messaging)
- [2. Context & Conversation](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#2-context-and-conversation)
- [3. Identity & Audience](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#3-identity-and-audience)
- [Conclusion](https://www.intigriti.com/researchers/blog/hacking-tools/hacking-ai-customer-service-agents#conclusion)
[Add us as a preferred source on](https://www.google.com/preferences/source?q=intigriti.com)
As AI agents are deployed to automate more tasks, they become more capable. And as the famous quote goes: "With great power comes great responsibility." Assuming that humans in the loop can mitigate that risk turns out to be.
At Bug Bounty Village during DEF CON 34, [Inti De Ceukelaire](https://www.linkedin.com/in/intidc/), Founding Member of Intigriti, delivered a talk on how attackers can abuse today's AI agents in ways most defenders haven't thought about yet, from tricking agents into spilling secrets to forcing them to carry out unauthorized actions on behalf of the victim. This resulted in over $50,000+ in bounties in just a few weekends, without actually poking the target with Burp Suite or any automated scanners.
Let's dive in!
#### Special thanks to @intidc!
Special thanks to [Inti De Ceukelaire](https://www.linkedin.com/in/intidc/) for his extensive research and delivering the talk at BBV during DEF CON 34. Access the full slides through the following link: [go.intigriti.com/HHITLS2026](https://go.intigriti.com/HHITLS2026)
## Weaponizing chatbots via email
You've certainly come across AI chatbots before. Most are capable of retrieving data from the company's knowledge base and providing answers based on your questions. However, some of them are also equipped with additional context or actions that can be misused if access is not correctly enforced.
Let's take a look at an example whereby we can trick an agent into composing and sending phishing emails.
Most chatbots, whether AI-powered or not, allow you to send a recap or transcript of your chat conversation. The underlying function copies your entire chat and emails it to your end. This feature can be abused, for instance, to send phishing emails.
Example of a prompt injection in LLMs
While this may work, most security teams would approach such findings as informative rather than an impactful bug that requires immediate attention. However, we've also noticed that most email transcript services are also susceptible to some form of email spoofing. In practice, this would mean that we can trick the AI agent responsible for processing incoming emails into believing that we're sending from the victim's email inbox. And of course, this goes paired with all sorts of attacks.
### Sending phishing emails from support@
In one case, we came across a chatbot that allows interaction in both ways. It allowed us to receive transcripts while also keeping the conversation going through email. The validation also turned out to be flawed, as spoofing the `From` email header made the chatbot think the email originated from the victim. In combination with a simple prompt, it allowed us to send a phishing email to the victim from the support email.
When the victim opens the email, the `From` header will appear as trusted and make the email look less suspicious.
Using transcripts as payload delivery
### Invoking tool calls
Now suppose the bot also has capabilities to perform authorized actions such as editing your profile details, reading your billing statements, or even transferring data or money to another account. With spoofing, we've already proven that some chatbots will fail to correctly verify the sender with the account owner. But would it also be possible for us to read the response sent to the victim's email?
Invoking tool calls in LLM chatbots
In some instances, we've noticed that this is possible. And we actually have multiple ways to do so. One notable method is to simply include our own email within the CC of the spoofed email. That would ensure the chatbot includes us in the CC of the reply, resulting in us receiving a copy of the confidential data.
Reading unauthorized LLM tool invocation response via email
### Multiple From email headers
So far, we've been spoofing the `From` header to make the agent believe the email came from the victim. But what if the target enforces email authentication, making spoofing impossible? Let's take a deeper dive into how the email protocol itself can be turned against us.
Digging deeper into RFCs, we can see that [RFC 822 allows](https://datatracker.ietf.org/doc/html/rfc822) sending an email with multiple `From` headers. In practice, this would mean sending an email with a **Header From**, which is what you see rendered in your mail client, and an **Envelope From**, which is what mail servers actually use during delivery and authentication. SPF and DKIM validate the Envelope From. The agent, however, reads the From header to determine whose account to look up, and responds to whichever address it's told to reply to.
An attacker can exploit this by crafting an email with two `From` addresses and a `Sender` header:
Sending emails with multiple From addresses
The email authentication layer runs SPF on the first `From` address, `[email protected]`, a domain the attacker controls, and passes successfully. The agent's action layer then looks up the account associated with the last `From` address, `[email protected]`, and retrieves the victim's data. Finally, the agent replies to the `Sender` header, delivering the response straight to `[email protected]`.
Sending emails with multiple From addresses
Using this method, we can pass the email verification checks and act on behalf of the victim to query and receive his/her data. There's another scenario which we'll explore shortly that goes even a step further in the event this logic flaw cannot be reproduced, leaving you with the only option to send the email as the victim.
### Sending signed e-mails to the agent as the victim
There's another scenario that goes even a step further in the event the previous logic flaw could not be reproduced. In such cases, we be