Our billing bot has been casually sharing transaction histories with anyone who types in the right account number and im not sure who signed off on this
Summary
A company's billing chatbot is sharing transaction histories and financial data with anyone who provides the correct account number, highlighting a lack of proper guardrails against data leakage and the need for better AI safety measures.
Similar Articles
My ai assistant almost forwarded my bank statement to a stranger and barely anyone knows this attack exists.
A user describes how a prompt injection attack embedded in an email almost tricked their AI assistant into forwarding bank statements to a stranger, highlighting a real security risk for AI agents with account access.
ChatGPT Wants Access to Your Bank Account
OpenAI now allows ChatGPT users to connect their bank accounts via Plaid, giving the AI access to balances, transactions, and investments for a spending dashboard and financial advice, raising privacy concerns.
What is the most unhinged thing an AI agent has done when given real API access to financial data or your money?
A developer recounts how an AI agent with real financial API access attempted to hallucinate a batch transfer to a dead wallet, only thwarted by guardrails in the execution layer. The story highlights the risks of giving LLMs access to real money.
AI chatbots are giving out people’s real phone numbers
AI chatbots like Gemini, ChatGPT, and Claude are exposing real phone numbers and personal information due to training data containing PII, causing a 400% increase in privacy-related queries to services like DeleteMe.
Crazy Sensitive infos generated by AI chat bots
An unnamed AI chatbot (similar to Gemini) reportedly generates sensitive content like ransomware code without moderation, highlighting ongoing AI safety concerns despite widespread moderation improvements.