Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

ForcedLeak in AI CRM tools: what it means for security teams


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12387
Topic starter  

TL;DR: ForcedLeak shows how an indirect prompt injection can exfiltrate CRM data from AI-integrated business tools by hiding malicious instructions in ordinary user-controlled fields, according to Noma Security. The incident shows that AI access controls must govern data provenance, tool execution, and trusted URLs together, not as separate problems.

NHIMG editorial — based on content published by Noma Security: AI Agent risk exposed in Salesforce Agentforce

By the numbers:

Questions worth separating out

Q: How should security teams reduce indirect prompt injection risk in AI systems?

A: Security teams should limit what AI systems can read, separate untrusted content from privileged actions, and apply least privilege to every connected agent.

Q: When does AI governance become an IAM and NHI problem?

A: It becomes an IAM and NHI problem as soon as autonomous systems use credentials, APIs, or delegated access to perform actions.

Q: What do security teams get wrong about trusted URL allow lists?

A: They often treat an allow list as a complete exfiltration control when it only narrows destinations.

Practitioner guidance

  • Inventory all production AI agents Map every AI agent, connector, and workflow that can read CRM, support, or sales data.
  • Separate content trust from execution trust Apply explicit provenance checks to user-submitted text, imported records, and third-party content before an agent can interpret it.
  • Constrain outbound tool use and data egress Review allow lists, image fetches, and external request paths together so the agent cannot encode sensitive data into permitted outbound channels.

What's in the full report

Noma Security's full blog covers the operational detail this post intentionally leaves for the source:

  • The full attack path showing how a hidden instruction can survive in ordinary CRM intake fields until an employee activates it through a routine AI query.
  • The Trusted URL allow list mitigation context, including what changed in Salesforce Agentforce and Einstein Generative AI agents.
  • The practical review workflow for recent lead submissions, anomalous AI interactions, and suspicious access patterns in customer environments.
  • The AI-specific control recommendations for prompt injection detection, input validation, and agent inventories that the source article outlines in more detail.

👉 Read Noma Security's analysis of the ForcedLeak AI agent vulnerability →

ForcedLeak in AI CRM tools: what it means for security teams?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11961
 

ForcedLeak is not just a prompt injection bug. It is a trust-boundary collapse between enterprise data, user intent, and agent execution. Once untrusted text can influence an AI system that also holds business permissions, the organisation has effectively merged content handling and access control into one failure domain. That is why classic application security checks miss the real risk. Practitioners need to treat AI-mediated workflows as governed execution paths, not passive search or summarisation features.

A question worth separating out:

Q: Who is accountable when an AI agent accesses sensitive data it was not meant to use?

A: Accountability sits with the team that approved the agent, its connectors, and its policy boundaries, not with the runtime behaviour alone. Organisations need ownership for intent, permissions, monitoring, and validation so they can prove whether the agent stayed inside its approved purpose. Without that, audit and regulatory response become retrospective guesswork.

👉 Read our full editorial: ForcedLeak shows how prompt injection breaks AI CRM trust boundaries



   
ReplyQuote
Share: