
aizome Security Research - When Support Tickets Become Agent Instructions
Download PDF
Download the full whitepaper: aizome Security Research - When Support Tickets Become Agent Instructions
When Support Tickets Become Agent Instructions
aizome researchers documented a complete indirect prompt injection attack chain using only a public Salesforce Web-to-Case support form. No credentials. No exploit. No Salesforce bug. One support ticket containing four lines of routing text was enough to cause a privileged AI agent to export customer records and deliver them to an external mailbox.
The attack used exclusively approved Salesforce features — and it would not be stopped by most enterprise security stacks today.
This report documents the full attack chain, step by step, with verification methodology and remediation recommendations.
Download the report.
Subscribe to the Aizome newsletter
Occasional, substance-first notes on making enterprise AI agents accountable. No spam; unsubscribe anytime.