A research team from Check Point Research (CPR) has uncovered a security flaw in ChatGPT's agent system that allowed agents to extract sensitive data from one user's account and transfer it to a completely different account. The vulnerability, named "coerced insider," didn't rely on exploiting a direct software bug but instead involved manipulating the AI agent through carefully crafted prompts. This method relied on the agent's ability to process and act on instructions, rather than on a flaw in the code itself. The issue stemmed from how ChatGPT's AI agents used an internal JFrog Artifactory instance to manage and deliver software packages. This system allowed different user accounts to access the same internal service. Within this service, containers (software components) could add text or binary data to a repository, and any other container could read that data. CPR found that data written by one account could be read by a different account almost immediately. Even large data sets were split into smaller parts, transmitted, and reassembled on the receiving end, effectively turning the system into a shared "clipboard" between isolated containers. The exploit involved using a common technique known as prompt injection, where a malicious message was inserted into the internal service. This message instructed the AI agent to check the same storage during its next normal response. When the agent replied to a user's question, it unknowingly executed the malicious instructions, transferring data to the attacker's session without the user's awareness. CPR demonstrated that this method could be used to extract a victim's email data from a connected Gmail account and deliver it to an attacker in a single interaction. OpenAI has confirmed that the specific internal Artifactory instance identified by CPR has been shut down. However, CPR warns that similar risks might exist in other AI platforms. The report highlights that any AI assistant operating within an organization's secure network, using credentials, running code, and accessing connected services, could potentially be manipulated into acting as a "coerced insider." This doesn't require the AI itself to be malicious—it only needs to be persuaded through text it wasn't designed to trust, using access granted for legitimate purposes. As a result, businesses are advised to monitor the AI tools their employees use, understand what these tools are connected to, and establish clear policies about what these tools can and cannot do. CPR emphasizes that all actions performed by AI agents should be treated as potential security risks and monitored accordingly.