ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud
Radware disclosed on 18 September 2025 that one crafted email could make the ChatGPT deep research agent extract inbox data with no view, open or click by the victim. Because the agent ran in the vendor's cloud rather than the user's browser, the theft left no evidence on the enterprise network. Radware reported it in June 2025 and the vendor confirmed a fix in September.
The verdict
Verified
The document exists. The ledger fetched it at its publisher and quotes it.
Key facts
What the sources say
- Record ID
- AIL-2026-0010
- Kind
- Exfiltration
- Jurisdiction
- United States
- Last verified
- Added
- Radware states that the deep research agent, executing in the vendor's cloud, performed the sensitive data exfiltration autonomously from those servers.
- The injected instructions hid in email HTML using tiny fonts, white on white text and layout tricks, so the user never saw them.
- Reporting of the research records the agent being steered to encode the extracted personal data into a URL before fetching it.
- Because execution was service side, the attack left no local or enterprise network evidence for defenders to find.
- Radware reported the issue on 18 June 2025 and states the vendor notified it of the fix on 3 September 2025.
Dimension by dimension
7 dimensions, each one stated, silent or open
Identity, Authorization, Delegation, Human approval, Logging and audit, Revocation, Accountability. Stated means the document you can open below says it; silent means the ledger read the document and it does not.
- IdentitySilent
- Any external sender's email became agent instructions with no identity check on the instruction channel.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
- AuthorizationSilent
- The mailbox connector's read scope was reachable by injected text, with no separate authorization for the outbound call.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
- DelegationSilent
- The agent held the user's connector permissions wholesale, and the researchers note the same path extends to other connected services.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
- Human approvalSilent
- There was no click and therefore no approval step anywhere in the chain.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
- Logging and auditSilent
- This is the sharpest finding: server side execution meant the customer's own logs could not see the exfiltration at all.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
- RevocationStated
- The vendor fixed it on its own service and confirmed the fix to the researchers, closing it for everyone at once.Radware press release, first zero click service side vulnerability in ChatGPT, primary source, 18 September 2025.
- AccountabilityOpen
- The vendor acknowledged and fixed the issue, but no CVE or public vendor advisory was issued, so the record rests on the researcher.The Hacker News, ShadowLeak zero click flaw leaks Gmail data, secondary source, 20 September 2025.
What it changes
For a team deploying an agent
If the agent runs in the vendor's cloud, your monitoring is blind to what it does. Logging is the control you cannot supply yourself, so make it a purchasing question: ask for a per action audit record of every tool call an agent makes on your behalf, exportable to your own systems. Until you have that, do not connect a research agent to a mailbox that carries anything you would not publish.
Sources
What this record was verified against
- Radware press release, first zero click service side vulnerability in ChatGPTPrimary · 18 September 2025
- The Hacker News, ShadowLeak zero click flaw leaks Gmail dataSecondary · 20 September 2025
Related
Records that sit beside this one
EchoLeak, a zero click chain that pulled tenant data out of Microsoft 365 Copilot
United States · verified 15 September 2026
Microsoft's advisory for CVE-2025-32711 states the vulnerability has already been fully mitigated and that there is no action for users of the service to take.
A chat assistant was steered into searching a user's own history and uploading it through an allowed endpoint
United States · verified 15 September 2026
The research states that the code execution sandbox restricts outbound network access but allows connections to the vendor's own interface endpoint.
A vendor's own red team made a browser agent send a resignation letter for the user, then showed the fixed agent refusing
United States · verified 15 September 2026
The vendor's own account states that the out of office reply never gets written and the agent resigns on behalf of the user instead.
A support agent invented a policy its company did not have, and customers cancelled over it
United States · verified 15 September 2026
A company representative stated publicly that there is no such policy and that users are free to use the product on multiple machines.
A browser agent read the local file system and shipped it out while still answering the user normally
United States · verified 15 September 2026
The research states the agent autonomously accesses the local file system and exfiltrates the contents to an attacker controlled endpoint while still returning the expected response.
GitLost, where a platform's own workflow agent posted private repository contents into a public issue when asked politely
United States · verified 15 September 2026
The Register reports that the attacker hides the commands in plain English in the issue body and the agent then posts the data as a public comment.
Cite this record
Free to reuse under CC BY 4.0, with attribution. The record ID AIL-2026-0010 is permanent and is never reused.
- In a sentence
- According to the GAGE Agent Incident Ledger (as of 15 September 2026), shadowleak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud.
- APA
- GAGE (Global Academy of Generative-AI Education). (2026). ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud. Agent Incident Ledger. Retrieved 15 September 2026, from https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0010-shadowleak-chatgpt-deep-research-gmail-exfiltration
- MLA
- "ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud." Agent Incident Ledger, GAGE (Global Academy of Generative-AI Education), 15 September 2026, https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0010-shadowleak-chatgpt-deep-research-gmail-exfiltration.
- Chicago
- GAGE (Global Academy of Generative-AI Education). "ShadowLeak, a research agent that exfiltrated mailbox data from inside the vendor's own cloud." Agent Incident Ledger. Last modified 15 September 2026. https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0010-shadowleak-chatgpt-deep-research-gmail-exfiltration.
- Permalink
- https://www.gage.academy/tools/agent-incident-ledger/records/AIL-2026-0010-shadowleak-chatgpt-deep-research-gmail-exfiltration
Last updated . Every record re verified . The ledger is checked weekly, every Monday, and the same day for any vendor disclosure.
Back to the full ledger, or every record for United States and every exfiltration record.
GAGE briefings tell you which AI regulation deadlines are coming, what they actually require of you, and when a program opens.