Zendoric
← Back to the day · July 25, 2026

A single ChatGPT link was enough to slip in an infiltrated AI agent with your employee permissions

🕒 Published on Zendoric: July 25, 2026 · 00:23

Zenity Labs found a flaw in ChatGPT's agent builder that allowed, with a single click on a seemingly innocuous link, the creation of an autonomous agent with the victim's full access to Outlook, Teams, Slack or SharePoint. OpenAI fixed it in four days, but the case foreshadows a structural problem: agents that act as employees need security controls that almost no one has today.

🎧 Listen to the analysis

By The Register · July 23, 2026.

A click on what looked like a normal ChatGPT link could plant, inside a company's workspace, an AI agent controlled by an attacker and with access to the employee's connected accounts. So documented Zenity Labs, the security firm that dubbed the flaw "AgentForger" after demonstrating that it was possible to secretly create, configure, publish and schedule a malicious agent inside the victim's ChatGPT account.

The key to the flaw lay in ChatGPT's "agent builder," the feature that lets users assemble assistants capable of operating across email, chat, calendars and other enterprise applications. According to Zenity, the agent builder accepted hidden instructions embedded in a normal-looking link: a single click was enough for the system to, on the attacker's behalf, connect the victim's already-linked accounts, disable approval prompts, publish the new agent and schedule it to run on its own. If the employee had Outlook, Teams, Slack, SharePoint or Google Drive linked —and the organization allowed those actions— the agent inherited that access.

The most unsettling part of the design was not the access itself, but the remote-control mechanism. Instead of reaching out to conventional command-and-control infrastructure, the agent simply scanned the victim's inbox for emails from the attacker with "TASK" in the subject line: each message became a new order, whether digging through corporate files, gathering sensitive documents or emailing out the results. In its proofs of concept, Zenity used the agent to map an organization's people and projects by combing Outlook, Slack, Teams, calendars and file repositories, to hunt for passwords and API keys leaked in conversations, and to send convincing phishing messages from the victim's own Teams account, including business email compromise (BEC) variants.

"This isn't a forged request, it's a forged insider," summed up Michael Bargury, co-founder and chief technology officer of Zenity, to The Register. "With one click, an attacker gets a fully autonomous agent inside your company, with the identity and access of your people, and no barriers. Attackers no longer have to break in to steal your data: they can manufacture an insider to go and get it for them."

Zenity reported the flaw to OpenAI through Bugcrowd on June 4; the company acknowledged it the next day and fixed it four days later by removing the URL parameter that enabled the attack, before it became public. OpenAI did not respond to The Register's questions about the case.

The incident itself was resolved quickly and with no known harm, thanks to a responsible disclosure that worked as it should. But the flaw matters less for what it was than for what it foreshadows: as AI agents stop merely answering questions and begin acting on real corporate systems —email, chat, shared files—, the attack surface stops looking like software and starts looking like staff. An agent with employee permissions does not need to steal a password or hijack a browser session: it is enough for it to exist within the perimeter of trust the organization already granted to that person.

This is, as we read it, the most immediate and least glamorous face of agentic AI risk, and it connects with something we have already been pointing out: the urgent danger is not some distant superintelligence, but the industrialization of fraud and espionage through agents that act under someone else's identity, at scale and without fatigue. Current security controls —based on detecting anomalous access from stolen credentials— were not designed to recognize an agent operating with legitimate permissions because an employee, with no ill intent, tacitly handed over the key. It is a failure of trust in the agent, not a password failure, and it demands a different model: instant revocation of agents, permissions that expire, and treating each autonomous assistant as if it were one more employee that has to be onboarded, audited and dismissed.

In the long run we remain convinced that delegating administrative and routine tasks to agents is precisely the path toward that abundance which frees people from the routine chores of the back office. But that future only arrives if the governance of agents matures at the same pace as their ability to act. Cases like AgentForger are the proof, still manageable, that this governance work has barely begun.

🔗 Related on Zendoric

Sources & references