Researchers have discovered vulnerabilities in AI-powered customer service agents, allowing attackers to bypass multi-factor authentication (MFA) and read sensitive data from third-party accounts. Specifically, they found that chatbots can be tricked into sending phishing emails by spoofing the "From" header, and that some IVR systems can be bypassed by using email address smuggling, which allows attackers to authenticate as themselves and read victim data. Additionally, they demonstrated that chatbots can be instructed to send emails to the victim's account, bypassing MFA and authentication. AI summary
Firehose
Filtered to Hacker News, tagged “customer service” · clear filters
Browse: People · Companies · Papers · Podcasts · Hacker News · Deep dives