Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
ai-platform-securitydata-exfiltration-methodcloud-service-vulnerabilityidentity-impersonation-fraud

ChatGPT Vulnerabilities Enable Data Exfiltration via ShadowLeak and ZombieAgent

Updated 2d agoFirst seen Jan 8, 20264 sources

Security researchers at Radware have uncovered critical vulnerabilities in OpenAI's ChatGPT platform, specifically targeting its Connectors and Memory features. These flaws, named ShadowLeak and ZombieAgent, allow attackers to exfiltrate sensitive data from connected services such as Gmail, Outlook, and GitHub without user interaction. The attacks exploit the AI's tendency to follow embedded malicious instructions, enabling zero-click and one-click data theft, persistent access through memory modification, and even propagation to other users by harvesting email addresses. OpenAI initially attempted to mitigate these vulnerabilities by restricting dynamic URL modifications, but researchers demonstrated effective bypasses using pre-built static URLs, reviving the threat under the new moniker ZombieAgent.

The vulnerabilities highlight the inherent risks of integrating AI assistants with external systems and storing long-term user data for personalization. Attackers can embed hidden prompts in emails or files—using techniques like white text or tiny fonts—that are executed when ChatGPT processes the content, leading to stealthy data leaks via OpenAI's own servers. Despite OpenAI's efforts to patch the flaws, the reactive nature of these fixes has left the platform susceptible to new variants, underscoring the ongoing challenge of securing AI-driven services against prompt injection and data exfiltration attacks.

Share:
ChatGPT Vulnerabilities Enable Data Exfiltration via ShadowLeak and ZombieAgent
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

6 events from the most recent confirmed update back to the earliest known activity.

6 EVENTS
Jan 8, 20266mo ago

Researchers publicly disclose ShadowLeak and ZombieAgent findings

Multiple outlets reported Radware's public disclosure of the ShadowLeak and ZombieAgent attacks, detailing how ChatGPT could be abused to exfiltrate sensitive data and plant persistent memory entries. The reports emphasized that OpenAI had patched specific issues but that systemic weaknesses in agentic AI security remained unresolved.

Dec 16, 20257mo ago

OpenAI deploys broader fixes for ShadowLeak and ZombieAgent issues

OpenAI addressed the full set of reported issues with additional mitigations on December 16, 2025. The fixes targeted the connector and memory abuse techniques Radware had demonstrated, though researchers said underlying prompt-injection risks remained.

Sep 30, 20259mo ago

Radware reports broader ChatGPT connector and memory issues to OpenAI

Radware disclosed the fuller set of vulnerabilities to OpenAI in September, including techniques for persistent memory manipulation, server-side exfiltration, and organizational propagation. The report showed attackers could leak data, alter stored information, and create worm-like spread through connected services.

Sep 4, 202510mo ago

Radware finds ZombieAgent bypass of OpenAI's initial mitigations

After OpenAI's first fix, Radware discovered a bypass called ZombieAgent that revived the data-exfiltration risk. The new technique used static URLs and abused ChatGPT's memory and connectors to enable stealthy, persistent, zero-click or one-click attacks.

Sep 3, 202510mo ago

OpenAI patches ShadowLeak after responsible disclosure

Following Radware's disclosure, OpenAI implemented a fix for the ShadowLeak issue by restricting dynamic URL modification and related attack paths. The mitigation was intended to stop prompt-injection-driven data exfiltration through ChatGPT connectors.

Radware discovers ShadowLeak prompt-injection flaw in ChatGPT

Radware identified an initial vulnerability, dubbed ShadowLeak, in ChatGPT's Deep Research and connector functionality. The flaw allowed hidden prompts in connected content and services to trigger unauthorized actions and leak sensitive data from sources such as Gmail, Outlook, Google Drive, and GitHub.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Affected products
16 linked
ChatgptTeamsGoogle DriveOutlookJiraGithubGmailOnedriveGithubJiraGmailGoogle DriveGoogle DriveGmailGmailGoogle Drive
Organizations
3 linked
OpenaiTenableRadware
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.