ChatGPT Hidden Channel Sends Victims' Gmail Data to Attacker Accounts
Key Takeaways
- Check Point Research found a hidden channel that let data move between separate ChatGPT accounts.
- A planted prompt, shared conversation, or custom GPT could trigger the attack with one ordinary message.
- Exposed data included connected Gmail content, conversation history, and session files.
- OpenAI took the internal service offline; no user action was required.
- How long the channel was exploitable, and whether it was abused, has not been disclosed.
When Isolation Has a Back Door
ChatGPT runs each user's code and tools in isolated containers. Research reported by The Hacker News showed that a shared backend service quietly connected those containers, letting a malicious prompt in one account hand a victim's private data to another.
What We Know
Check Point Research identified the issue in June 2026 and published on September 8. An attacker could plant instructions through a prompt the user pasted, a shared conversation the user opened, or a custom GPT. Once triggered, the hidden task ran in the background during Thinking mode while the visible reply looked normal.
According to CSO Online, the attack used metadata in a shared Artifactory cache that was reachable from separate containers. That metadata became an unintended message channel between accounts. Exposed data included Gmail content from connected accounts, conversation history, and files in the session. The only sign was a small Talked to Gmail label after access had occurred. OpenAI took the internal service offline, and no client update was needed.
What Happened
This was a prompt injection that crossed a tenant boundary. Injected instructions are a known risk, but they normally stay within the victim's session. Here, a shared infrastructure component let the hijacked session write data where an attacker's own session could read it.
Connectors made the impact larger. Because ChatGPT could read Gmail on the user's behalf, the injection did not need to steal credentials. It simply asked the assistant to fetch mail and pass it through the hidden channel.
Why It Matters
Millions of people connect AI assistants to email, files, and business apps. This case shows that the assistant's permissions become the attacker's permissions once instructions are planted, and that platform isolation can fail in ways users cannot see.
For enterprises, it underlines the need to control which connectors assistants may use, inspect what data flows through them, and treat shared conversations and custom GPTs as untrusted input. Notification was also thin: a label after the fact is not meaningful consent.
PointGuard AI Perspective
AI assistants need data controls that work at the moment of use. PointGuard AI Data Protection inspects prompts, tool calls, and responses for sensitive content and can block or redact data before it leaves approved boundaries, including data retrieved through connectors such as email.
PointGuard AI Intelligent Guardrails detect injected instructions in pasted text, shared conversations, and custom assistants, stopping hidden tasks before they run. As assistants gain access to more business systems, trustworthy adoption depends on enforcing what they may read and where that data may go.
Incident Scorecard Details
Total AISSI Score: 6.1/10
Criticality: 7, Private email, conversations, and files of individual and business users could be exposed. AISSI weighting: 25%
Propagation: 6, The attack could spread through shared conversations and custom GPTs to many users. AISSI weighting: 20%
Exploitability: 5, Researchers demonstrated the full chain, with no confirmed abuse disclosed. AISSI weighting: 15%
Supply Chain: 6, The weakness sat in a third-party AI platform's shared backend infrastructure. AISSI weighting: 15%
Business Impact: 6, Fixed server-side, but the exposure window and any abuse remain unknown. AISSI weighting: 25%
Sources
Third-Party Sources
- The Hacker News: ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
- CSO Online: ChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channel
