ChatGPT Hidden Channel Sends Victims' Gmail Data to Attacker Accounts

Key Takeaways

  • Check Point Research found a hidden channel that let data move between separate ChatGPT accounts.
  • A planted prompt, shared conversation, or custom GPT could trigger the attack with one ordinary message.
  • Exposed data included connected Gmail content, conversation history, and session files.
  • OpenAI took the internal service offline; no user action was required.
  • How long the channel was exploitable, and whether it was abused, has not been disclosed.

When Isolation Has a Back Door

ChatGPT runs each user's code and tools in isolated containers. Research reported by The Hacker News showed that a shared backend service quietly connected those containers, letting a malicious prompt in one account hand a victim's private data to another.

What We Know

Check Point Research identified the issue in June 2026 and published on September 8. An attacker could plant instructions through a prompt the user pasted, a shared conversation the user opened, or a custom GPT. Once triggered, the hidden task ran in the background during Thinking mode while the visible reply looked normal.

According to CSO Online, the attack used metadata in a shared Artifactory cache that was reachable from separate containers. That metadata became an unintended message channel between accounts. Exposed data included Gmail content from connected accounts, conversation history, and files in the session. The only sign was a small Talked to Gmail label after access had occurred. OpenAI took the internal service offline, and no client update was needed.

What Happened

This was a prompt injection that crossed a tenant boundary. Injected instructions are a known risk, but they normally stay within the victim's session. Here, a shared infrastructure component let the hijacked session write data where an attacker's own session could read it.

Connectors made the impact larger. Because ChatGPT could read Gmail on the user's behalf, the injection did not need to steal credentials. It simply asked the assistant to fetch mail and pass it through the hidden channel.

Why It Matters

Millions of people connect AI assistants to email, files, and business apps. This case shows that the assistant's permissions become the attacker's permissions once instructions are planted, and that platform isolation can fail in ways users cannot see.

For enterprises, it underlines the need to control which connectors assistants may use, inspect what data flows through them, and treat shared conversations and custom GPTs as untrusted input. Notification was also thin: a label after the fact is not meaningful consent.

PointGuard AI Perspective

AI assistants need data controls that work at the moment of use. PointGuard AI Data Protection inspects prompts, tool calls, and responses for sensitive content and can block or redact data before it leaves approved boundaries, including data retrieved through connectors such as email.

PointGuard AI Intelligent Guardrails detect injected instructions in pasted text, shared conversations, and custom assistants, stopping hidden tasks before they run. As assistants gain access to more business systems, trustworthy adoption depends on enforcing what they may read and where that data may go.

Incident Scorecard Details

Total AISSI Score: 6.1/10

Criticality: 7, Private email, conversations, and files of individual and business users could be exposed. AISSI weighting: 25%

Propagation: 6, The attack could spread through shared conversations and custom GPTs to many users. AISSI weighting: 20%

Exploitability: 5, Researchers demonstrated the full chain, with no confirmed abuse disclosed. AISSI weighting: 15%

Supply Chain: 6, The weakness sat in a third-party AI platform's shared backend infrastructure. AISSI weighting: 15%

Business Impact: 6, Fixed server-side, but the exposure window and any abuse remain unknown. AISSI weighting: 25%

Sources

Third-Party Sources

PointGuard AI Sources

AI Security Severity Index (AISSI)

0/10

Threat Level

Criticality

7

Propagation

6

Exploitability

5

Supply Chain

6

Business Impact

6

Scoring Methodology

Category

Description

weight

Criticality

Importance and sensitivity of theaffected assets and data.

25%

PROPAGATION

How easily can the issue escalate or spread to other resources.

20%

EXPLOITABILITY

Is the threat actively being exploited or just lab demonstrated.

15%

SUPPLY CHAIN

Did the threat originate with orwas amplified by third-partyvendors.

15%

BUSINESS IMPACT

Operational, financial, andreputational consequences.

25%

Watch Incident Video

Learn More

Use Cases

Glossary

Products

Blogs

Subscribe for updates:

Subscribe

Ready to get started?

Our expert team can assess your needs, show you a live demo, and recommend a solution that will save you time and money.