Skip to main content
VerifiedExfiltration

ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud

Radware disclosed on 18 September 2025 that one crafted email could make the ChatGPT deep research agent extract inbox data with no view, open or click by the victim. Because the agent ran in the vendor's cloud rather than the user's browser, the theft left no evidence on the enterprise network. Radware reported it in June 2025 and the vendor confirmed a fix in September.

The verdict

Verified

The document exists. The ledger fetched it at its publisher and quotes it.

Key facts

What the sources say

Record ID
AIL-2026-0010
Kind
Exfiltration
Jurisdiction
United States
Last verified
Added
  • Radware states that the deep research agent, executing in the vendor's cloud, performed the sensitive data exfiltration autonomously from those servers.
  • The injected instructions hid in email HTML using tiny fonts, white on white text and layout tricks, so the user never saw them.
  • Reporting of the research records the agent being steered to encode the extracted personal data into a URL before fetching it.
  • Because execution was service side, the attack left no local or enterprise network evidence for defenders to find.
  • Radware reported the issue on 18 June 2025 and states the vendor notified it of the fix on 3 September 2025.

Dimension by dimension

7 dimensions, each one stated, silent or open

Identity, Authorization, Delegation, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.

IdentitySilent
Any external sender's email became agent instructions with no identity check on the instruction channel.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
AuthorizationSilent
The mailbox connector's read scope was reachable by injected text, with no separate authorization for the outbound call.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
DelegationSilent
The agent held the user's connector permissions wholesale, and the researchers note the same path extends to other connected services.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
Human approvalSilent
There was no click and therefore no approval step anywhere in the chain.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
Logging and auditSilent
This is the sharpest finding: server side execution meant the customer's own logs could not see the exfiltration at all.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
RevocationStated
The vendor fixed it on its own service and confirmed the fix to the researchers, closing it for everyone at once.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
AccountabilityOpen
The vendor acknowledged and fixed the issue, but no CVE or public vendor advisory was issued, so the record rests on the researcher.The Hacker News, ShadowLeak zero click flaw leaks Gmail data, secondary source, 20 September 2025.

What it changes

For a team deploying an agent

If the agent runs in the vendor's cloud, your monitoring is blind to what it does. Logging is the control you cannot supply yourself, so make it a purchasing question: ask for a per action audit record of every tool call an agent makes on your behalf, exportable to your own systems. Until you have that, do not connect a research agent to a mailbox that carries anything you would not publish.

Sources

What this record was verified against

  1. Radware press release, first zero click service side vulnerability in ChatGPTPrimary · 18 September 2025
  2. The Hacker News, ShadowLeak zero click flaw leaks Gmail dataSecondary · 20 September 2025

Related

Cite this record

Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0010 is permanent and is never reused.

In a sentence
According to the GAGE Agent Incident Ledger (as of 15 September 2026), shadowleak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud.
APA
GAGE (Global Academy of Generative-AI Education). (2026). ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0010-shadowleak-chatgpt-deep-research-gmail-exfiltration
MLA
"ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0010-shadowleak-chatgpt-deep-research-gmail-exfiltration.
Chicago
GAGE (Global Academy of Generative-AI Education). "ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0010-shadowleak-chatgpt-deep-research-gmail-exfiltration.
Permalink
https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0010-shadowleak-chatgpt-deep-research-gmail-exfiltration

Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.

Back to the full ledger, or every record for United States and every exfiltration record.

GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.