{"id":73033,"date":"2025-08-18T21:14:58","date_gmt":"2025-08-18T20:14:58","guid":{"rendered":"https:\/\/www.cxtoday.com\/?p=73033"},"modified":"2025-10-19T10:09:56","modified_gmt":"2025-10-19T09:09:56","slug":"a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers","status":"publish","type":"post","link":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/","title":{"rendered":"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers"},"content":{"rendered":"<p>Microsoft has published many examples of how businesses can build AI agents in Copilot Studio to automate multi-step tasks, without a human in the loop.<\/p>\n<p>One such example, <a href=\"https:\/\/www.youtube.com\/watch?v=qxMi-tLg4MA\" target=\"_blank\" rel=\"noopener\">as shared on YouTube<\/a>, is a customer service agent built by McKinsey &amp; Co..<\/p>\n<p>The AI agent autonomously interacts with customers, scouring internal knowledge bases and data systems to share responses to their queries.<\/p>\n<p>Such a possibility represents a major leap for customer-facing chatbots, which, until recently, relied on rigid decision trees that broke whenever customers went off-script.<\/p>\n<p>Thanks to this tech advancement, <a href=\"https:\/\/www.cxtoday.com\/contact-center\/agentic-ai-gartner-predicts-80-of-customer-problems-solved-without-human-help-by-2029\/\" target=\"_blank\" rel=\"noopener\">Gartner has predicted that agentic AI will solve 80 percent of customer problems by 2029<\/a>.<\/p>\n<p><a href=\"https:\/\/www.cxtoday.com\/customer-data-platform\/what-is-microsoft-copilot-studio-and-how-can-i-create-a-custom-agent\/\" target=\"_blank\" rel=\"noopener\">Microsoft Copilot Studio<\/a> has quickly become a hallmark platform for building AI agents that converse with customers.<\/p>\n<p>Yet, researchers from Zenity, the security and governance platform provider, wanted to test how safe the customer-facing agents built on Copilot Studio are.<\/p>\n<p>As such, the firm created a replica of McKinsey&#8217;s model, hooked it to a Salesforce sandbox org, and started &#8220;<a href=\"https:\/\/labs.zenity.io\/p\/a-copilot-studio-story-2-when-aijacking-leads-to-full-data-exfiltration-bc4a\" target=\"_blank\" rel=\"noopener\">attacking it like it&#8217;s the last agent on earth<\/a>.&#8221;<\/p>\n<p>The result, shared at DEF CON 2025, proved nothing short of remarkable. Indeed, the researchers made the agent act without human verification, reveal private knowledge and internal tools, \u00a0and share complete Salesforce CRM records.<\/p>\n<p>Since then, the Zenity team has released a video of their attack, showcasing how it breached the AI agent, after Microsoft confirmed the injection no longer works.<\/p>\n<p><iframe loading=\"lazy\" title=\"Embedded post\" src=\"https:\/\/www.linkedin.com\/embed\/feed\/update\/urn:li:ugcPost:7359942914937937920?compact=1\" width=\"504\" height=\"399\" frameborder=\"0\" allowfullscreen=\"allowfullscreen\"><\/iframe><\/p>\n<p>However, while this attack may fail on Copilot Studio agents today, Zenity warns that over 3,500 public-facing agents remain wide open to similar prompt injections.<\/p>\n<p>As such, more examples of \u201cagent aijacking\u201d are just waiting to happen, and it may not be the good guys doing it next around.<\/p>\n<p>Summing up, <strong>Michael Bargury, Co-Founder &amp; CTO of Zenity<\/strong>, stated:<\/p>\n<blockquote><p>Agent aijacking is not a vulnerability you can fix. It\u2019s inherent to agentic AI systems, a problem we&#8217;re going to have to manage.<\/p><\/blockquote>\n<p>If businesses can\u2019t manage this vulnerability while granting AI agents access to internal systems, they risk large-scale data breaches.<\/p>\n<p>Indeed, the demo highlights how AI agents, without an overarching governance structure, can turn into data extraction tools, attacking CRMs, internal communications, and billing information.<\/p>\n<p>Taking note of this, <strong>David Villalon, Co-founder &amp; CEO of Maisa<\/strong>, <a href=\"https:\/\/www.linkedin.com\/posts\/davidvillalonpardo_microsofts-copilot-studio-agents-got-hijacked-activity-7362084839275016194-Npqb\/\" target=\"_blank\" rel=\"noopener\">warned on LinkedIn<\/a>:<\/p>\n<blockquote><p>For enterprises rushing to deploy autonomous AI: this is your warning. Every autonomous agent with data access is a potential attack vector. The convenience of &#8220;no human in the loop&#8221; becomes a catastrophic vulnerability when security fails.<\/p><\/blockquote>\n<p>&#8220;The gap between AI capability and AI security keeps widening,\u201d continued Maisa. \u201cWe&#8217;re building powerful autonomous systems on foundations that hackers can compromise with clever prompts.&#8221;<\/p>\n<p>Given this, Maisa suggested that it might be time for brands to reconsider what &#8220;autonomous&#8221; means in enterprise AI, especially regarding customer-facing use cases.<\/p>\n<h2>More Attacks on Salesforce Data<\/h2>\n<p>While the ethical attack on the Copilot-built AI agent may not have spewed out any real Salesforce records, other recent not-so-ethical attacks have.<\/p>\n<p>Crucially, these are not the fault of Salesforce\u2019s security posture. Instead, they target the people using Salesforce\u2019s software through more conventional human-centric means.<\/p>\n<p>The latest attack targeted Workday. As shared in <a href=\"https:\/\/blog.workday.com\/en-us\/protecting-you-from-social-engineering-campaigns-update-from-workday.html\" target=\"_blank\" rel=\"noopener\">a company blog post<\/a> last week, bad actors contacted employees &#8220;pretending to be from human resources or IT.&#8221;<\/p>\n<p>In doing so, they stole \u201csome information from our third-party CRM platform\u201d, which Bleeping Computer has since asserted was Salesforce.<\/p>\n<p>The week prior, another Salesforce instance was breached, <a href=\"https:\/\/www.cxtoday.com\/crm\/the-google-salesforce-customer-data-breach-what-really-happened\/\" target=\"_blank\" rel=\"noopener\">this time at Google<\/a>.<\/p>\n<p>Yet, the attack method was different. In this case, the fraudsters tricked admins into installing a malicious version of Salesforce Data Loader.<\/p>\n<p>The fake solution mimicked Data Loader, extracting, updating, and deleting Salesforce data. But it also allowed attackers to quietly lift sensitive data from the backend.<\/p>\n<p>Both attacks, which notably breached two enterprise tech giants, are a reminder that any organization can fall victim to such attacks.<\/p>\n<p>Indeed, this isn&#8217;t a dig at Salesforce. Every customer database is vulnerable, and \u2013 unfortunately \u2013 the tools available to attackers are multiplying.<\/p>\n<p>Whether through AI-generated deepfakes or manipulating new attack surfaces, the pressure on cybersecurity teams is reaching new heights.<\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft has published many examples of how businesses can build AI agents in Copilot Studio to automate multi-step tasks, without a human in the loop. One such example, as shared on YouTube, is a customer service agent built by McKinsey &amp; Co.. The AI agent autonomously interacts with customers, scouring internal knowledge bases and data [&hellip;]<\/p>\n","protected":false},"author":4063,"featured_media":73035,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[61014,62063],"class_list":["post-73033","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-crm","category-marketing-sales-technology","tag-agentic-ai","tag-agentic-ai-in-customer-service","tag-ai-agent","tag-ai-agents","tag-autonomous-agents","tag-chatbots","tag-crm","tag-virtual-agent","brands_to_track-microsoft","brands_to_track-salesforce","editorial_type-news","intent-loyalty","target_audience-dual"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v25.3.1 (Yoast SEO v25.3.1) - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers - CX Today<\/title>\n<meta name=\"description\" content=\"CX Today covers CRM &amp; Customer Data Management news including Agentic AI, Agentic AI in Customer Service\u200b, AI Agent, AI Agents, Autonomous Agents, Chatbots, CRM, Virtual Agent and more.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers\" \/>\n<meta property=\"og:description\" content=\"CX Today covers CRM &amp; Customer Data Management news including Agentic AI, Agentic AI in Customer Service\u200b, AI Agent, AI Agents, Autonomous Agents, Chatbots, CRM, Virtual Agent and more.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/\" \/>\n<meta property=\"og:site_name\" content=\"CX Today\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/CXTodayNews\/\" \/>\n<meta property=\"article:published_time\" content=\"2025-08-18T20:14:58+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-10-19T09:09:56+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"850\" \/>\n\t<meta property=\"og:image:height\" content=\"425\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Charlie Mitchell\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@cxtodaynews\" \/>\n<meta name=\"twitter:site\" content=\"@cxtodaynews\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Charlie Mitchell\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/\"},\"author\":{\"name\":\"Charlie Mitchell\",\"@id\":\"https:\/\/www.cxtoday.com\/#\/schema\/person\/4deb7a9ecd0b93d7461a492a1b54b8b9\"},\"headline\":\"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers\",\"datePublished\":\"2025-08-18T20:14:58+00:00\",\"dateModified\":\"2025-10-19T09:09:56+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/\"},\"wordCount\":701,\"publisher\":{\"@id\":\"https:\/\/www.cxtoday.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg\",\"keywords\":[\"Agentic AI\",\"Agentic AI in Customer Service\u200b\",\"AI Agent\",\"AI Agents\",\"Autonomous Agents\",\"Chatbots\",\"CRM\",\"Virtual Agent\"],\"articleSection\":[\"CRM &amp; Customer Data Management\",\"Marketing &amp; Sales Technology\"],\"inLanguage\":\"en-GB\",\"copyrightYear\":\"2025\",\"copyrightHolder\":{\"@id\":\"https:\/\/www.cxtoday.com\/#organization\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/\",\"url\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/\",\"name\":\"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers - CX Today\",\"isPartOf\":{\"@id\":\"https:\/\/www.cxtoday.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg\",\"datePublished\":\"2025-08-18T20:14:58+00:00\",\"dateModified\":\"2025-10-19T09:09:56+00:00\",\"description\":\"CX Today covers CRM &amp; Customer Data Management news including Agentic AI, Agentic AI in Customer Service\u200b, AI Agent, AI Agents, Autonomous Agents, Chatbots, CRM, Virtual Agent and more.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#primaryimage\",\"url\":\"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg\",\"contentUrl\":\"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg\",\"width\":850,\"height\":425,\"caption\":\"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.cxtoday.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"CRM &amp; Customer Data Management\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.cxtoday.com\/#website\",\"url\":\"https:\/\/www.cxtoday.com\/\",\"name\":\"CX Today\",\"description\":\"Customer Experience Technology News\",\"publisher\":{\"@id\":\"https:\/\/www.cxtoday.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.cxtoday.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.cxtoday.com\/#organization\",\"name\":\"CX Today\",\"url\":\"https:\/\/www.cxtoday.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.cxtoday.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2022\/03\/CX_Today_FullLogo.png\",\"contentUrl\":\"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2022\/03\/CX_Today_FullLogo.png\",\"width\":2606,\"height\":1154,\"caption\":\"CX Today\"},\"image\":{\"@id\":\"https:\/\/www.cxtoday.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/CXTodayNews\/\",\"https:\/\/x.com\/cxtodaynews\",\"https:\/\/www.linkedin.com\/company\/69192959\/\",\"https:\/\/www.youtube.com\/channel\/UCZSpkvnZtjGc7UAP1r-MRoA\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.cxtoday.com\/#\/schema\/person\/4deb7a9ecd0b93d7461a492a1b54b8b9\",\"name\":\"Charlie Mitchell\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\/\/www.cxtoday.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/7139362ec21f711b1aa0300faf312a167a42ac97b312b0385523913782254ea5?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/7139362ec21f711b1aa0300faf312a167a42ac97b312b0385523913782254ea5?s=96&d=mm&r=g\",\"caption\":\"Charlie Mitchell\"},\"description\":\"Charlie Mitchell is an award-winning journalist specializing in tech, customer experience, and contact centers. As Features Editor at his previous publisher, he led its editorial strategy, doubled its traffic, and earned recognition as a winner at the 2020 AOP Digital Publishing Awards. Then, as an independent copywriter, he crafted content for several prominent players in enterprise communications. Until October 2025, he was Head of Publication at CX Today.\u00a0\",\"url\":\"https:\/\/www.cxtoday.com\/author\/charlie-mitchell\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers - CX Today","description":"CX Today covers CRM &amp; Customer Data Management news including Agentic AI, Agentic AI in Customer Service\u200b, AI Agent, AI Agents, Autonomous Agents, Chatbots, CRM, Virtual Agent and more.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/","og_locale":"en_GB","og_type":"article","og_title":"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers","og_description":"CX Today covers CRM &amp; Customer Data Management news including Agentic AI, Agentic AI in Customer Service\u200b, AI Agent, AI Agents, Autonomous Agents, Chatbots, CRM, Virtual Agent and more.","og_url":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/","og_site_name":"CX Today","article_publisher":"https:\/\/www.facebook.com\/CXTodayNews\/","article_published_time":"2025-08-18T20:14:58+00:00","article_modified_time":"2025-10-19T09:09:56+00:00","og_image":[{"width":850,"height":425,"url":"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg","type":"image\/jpeg"}],"author":"Charlie Mitchell","twitter_card":"summary_large_image","twitter_creator":"@cxtodaynews","twitter_site":"@cxtodaynews","twitter_misc":{"Written by":"Charlie Mitchell","Estimated reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#article","isPartOf":{"@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/"},"author":{"name":"Charlie Mitchell","@id":"https:\/\/www.cxtoday.com\/#\/schema\/person\/4deb7a9ecd0b93d7461a492a1b54b8b9"},"headline":"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers","datePublished":"2025-08-18T20:14:58+00:00","dateModified":"2025-10-19T09:09:56+00:00","mainEntityOfPage":{"@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/"},"wordCount":701,"publisher":{"@id":"https:\/\/www.cxtoday.com\/#organization"},"image":{"@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg","keywords":["Agentic AI","Agentic AI in Customer Service\u200b","AI Agent","AI Agents","Autonomous Agents","Chatbots","CRM","Virtual Agent"],"articleSection":["CRM &amp; Customer Data Management","Marketing &amp; Sales Technology"],"inLanguage":"en-GB","copyrightYear":"2025","copyrightHolder":{"@id":"https:\/\/www.cxtoday.com\/#organization"}},{"@type":"WebPage","@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/","url":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/","name":"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers - CX Today","isPartOf":{"@id":"https:\/\/www.cxtoday.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#primaryimage"},"image":{"@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#primaryimage"},"thumbnailUrl":"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg","datePublished":"2025-08-18T20:14:58+00:00","dateModified":"2025-10-19T09:09:56+00:00","description":"CX Today covers CRM &amp; Customer Data Management news including Agentic AI, Agentic AI in Customer Service\u200b, AI Agent, AI Agents, Autonomous Agents, Chatbots, CRM, Virtual Agent and more.","breadcrumb":{"@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#primaryimage","url":"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg","contentUrl":"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2025\/08\/microsoft-copilot-studio-attack-850.jpg","width":850,"height":425,"caption":"A Customer Service AI Agent Spits Out Complete Salesforce Records in an Attack by Security Researchers"},{"@type":"BreadcrumbList","@id":"https:\/\/www.cxtoday.com\/crm\/a-customer-service-ai-agent-spits-out-complete-salesforce-records-in-an-attack-by-security-researchers\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.cxtoday.com\/"},{"@type":"ListItem","position":2,"name":"CRM &amp; Customer Data Management"}]},{"@type":"WebSite","@id":"https:\/\/www.cxtoday.com\/#website","url":"https:\/\/www.cxtoday.com\/","name":"CX Today","description":"Customer Experience Technology News","publisher":{"@id":"https:\/\/www.cxtoday.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.cxtoday.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Organization","@id":"https:\/\/www.cxtoday.com\/#organization","name":"CX Today","url":"https:\/\/www.cxtoday.com\/","logo":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.cxtoday.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2022\/03\/CX_Today_FullLogo.png","contentUrl":"https:\/\/www.cxtoday.com\/wp-content\/uploads\/2022\/03\/CX_Today_FullLogo.png","width":2606,"height":1154,"caption":"CX Today"},"image":{"@id":"https:\/\/www.cxtoday.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/CXTodayNews\/","https:\/\/x.com\/cxtodaynews","https:\/\/www.linkedin.com\/company\/69192959\/","https:\/\/www.youtube.com\/channel\/UCZSpkvnZtjGc7UAP1r-MRoA"]},{"@type":"Person","@id":"https:\/\/www.cxtoday.com\/#\/schema\/person\/4deb7a9ecd0b93d7461a492a1b54b8b9","name":"Charlie Mitchell","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/www.cxtoday.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/7139362ec21f711b1aa0300faf312a167a42ac97b312b0385523913782254ea5?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7139362ec21f711b1aa0300faf312a167a42ac97b312b0385523913782254ea5?s=96&d=mm&r=g","caption":"Charlie Mitchell"},"description":"Charlie Mitchell is an award-winning journalist specializing in tech, customer experience, and contact centers. As Features Editor at his previous publisher, he led its editorial strategy, doubled its traffic, and earned recognition as a winner at the 2020 AOP Digital Publishing Awards. Then, as an independent copywriter, he crafted content for several prominent players in enterprise communications. Until October 2025, he was Head of Publication at CX Today.\u00a0","url":"https:\/\/www.cxtoday.com\/author\/charlie-mitchell\/"}]}},"_links":{"self":[{"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/posts\/73033","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/users\/4063"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/comments?post=73033"}],"version-history":[{"count":3,"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/posts\/73033\/revisions"}],"predecessor-version":[{"id":73052,"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/posts\/73033\/revisions\/73052"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/media\/73035"}],"wp:attachment":[{"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/media?parent=73033"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cxtoday.com\/wp-json\/wp\/v2\/categories?post=73033"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}