Sunday, 13 September 2026
8 agent hacks today 8 vs yesterday (0)

Deep Research agent leaked Gmail data from inside OpenAI's cloud

Because the agent made the outbound request itself, nothing crossed the victim's network for a security tool to catch.

By The Agentic Times ·

OpenAI's Deep Research agent could be made to read a user's Gmail and send personal details to an attacker without the user clicking anything, Radware disclosed in September 2025. The company named the flaw ShadowLeak and said OpenAI fixed it in August after being notified in June.

Deep Research is ChatGPT's long-running browsing agent, and users can connect it to Gmail and other services. Radware sent a target an email whose body contained instructions, disguised as routine HR text, telling the agent to look up specific personal data in the mailbox and submit it to a URL. When the user later asked Deep Research to review their inbox, the agent followed the instructions and made the request from OpenAI's own infrastructure.

Radware called this a service-side leak. Earlier exfiltration demonstrations relied on the user's browser rendering an image or link, which enterprise proxies could in principle block. Here the request originated from OpenAI's servers, so the user's endpoint and network controls never saw it.

The researchers reported that getting the agent to comply took persuasion: the prompt asserted the agent had full authorisation, insisted that the request was urgent, and instructed it to encode the data so that a URL would look harmless. They said the same approach should apply to any connector the agent can reach, including Google Drive, Outlook and GitHub.

OpenAI confirmed the fix. Radware recommended that companies treat agent connectors as a new data flow that needs logging and monitoring on the provider side.

Sources

  1. radware.comhttps://www.radware.com/blog/threat-intelligence/shadowleak/