Chronicle/Attacks & incidents

PromptArmor reports Slack AI can be steered to leak private-channel data via public-channel messages

AttackVulnerability disclosureSignificance assistant-drafted

PromptArmor reports that instructions posted in a public Slack channel could be pulled into Slack AI answers for other users, enabling phishing links and leakage of data from private channels the attacker cannot read. The firm notes Slack's 2024-08-14 change to ingest files widened the surface, and that Slack described the underlying public-channel search as intended behavior.

Why it matters

Workplace assistants that search across permission boundaries can be turned against the users they serve.

Key facts

As stated in the sources, with where to find them.

  • Slack expanded Slack AI to ingest files from channels and DMs on 2024-08-14, per PromptArmor.Section on file ingestion
  • Slack's response to the report characterized public-channel visibility as intended behavior.Disclosure section

Findings that cite this record

No tracked finding cites this record yet.

Sources

Related records