Tenable Warns No-Code Agentic AI Can Enable Financial Fraud and Data Leaks

LOGO - Tenable-Logo2021-Reversed/ Tenable

The AI agent was supplied with demo customer data, including names, contact details, and credit card information, and was instructed to verify customer identities before sharing data or making changes.

Using a technique known as prompt injection, Tenable researchers were able to override those safeguards.

 

Sensitive Data Leaked, Financial Controls Bypassed

Through workflow manipulation, researchers successfully extracted sensitive payment card information and forced the AI agent to bypass identity verification protocols.

More critically, the agent’s permissions allowed researchers to modify financial fields.

By exploiting this access, they changed a trip’s cost to $0, effectively granting unauthorised free services.

Major Business and Regulatory Implications

Related News
Recent News
image
Techno Palo Alto Networks: Krisis Kepercayaan Data Jadi Tantangan Utama Keamanan AI Indonesia pada 2026
by Adrian Jasman2025-12-15 12:32:13

Palo Alto Networks prediksi 2026 jadi fase krusial AI, dengan krisis kepercayaan data.

image
Techno Xiaomi 12.12 Year End Festival: Diskon hingga Rp1,5 Juta, Awali 2026 dengan Smart Home
by Adrian Jasman2025-12-11 12:28:29

Xiaomi 12.12 Year End Festival: Diskon hingga Rp1,5 juta untuk ekosistem pintar & smart home!