AML.T0085.001 sub-technique demonstrated
AI Agent Tools
Sub-technique of AML.T0085 — Data from AI Services
Adversaries may prompt the AI service to invoke various tools the agent has access to. Tools may retrieve data from different APIs or services in an organization.
> curated attacks (2)
Incident high 2025-09-18
ShadowLeak: Zero-Click Gmail Theft via ChatGPT Deep Research Agent
A hidden prompt in an email made OpenAI's ChatGPT Deep Research agent collect inbox data and exfiltrate it from OpenAI's own cloud — a service-side, zero-click leak invisible to local or enterprise defenses.
Research high 2025-06-01
Data Exfiltration via Agent Tools in Microsoft Copilot Studio
Researchers showed that a Copilot Studio customer-service agent could be enumerated, fingerprinted, and then driven by prompt injection to collect and exfiltrate an organization's data through its own connected tools.