• News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
No Result
View All Result
Home AI

Tenable Research Reveals No-Code Agentic AI Risks Enabling Financial Fraud and Workflow Hijacking

SmartSolutionUser1 by SmartSolutionUser1
December 19, 2025
in AI
0
Tenable Research Reveals No-Code Agentic AI Risks Enabling Financial Fraud and Workflow Hijacking
75
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Tenable, the exposure management company, released research detailing the successful jailbreak of Microsoft Copilot Studio. The findings underscore how the democratisation of AI creates severe, yet overlooked, enterprise risks.

You might also like

Immersion India Drives Outcome-Led Programmes as AI Accelerates the Global Skills Reset

AI-enabled email accounts could become the ultimate insider threat, Barracuda Unfolds

Gartner Predicts Strong 96% Growth in AI-Optimized IaaS Spending

Organisations are rapidly adopting “no-code” platforms to enable employees to build their own AI agents. The premise is harmless, efficiency without needing developers. While well-intentioned, automation without strict governance opens the door to catastrophic failure.

Summary of Research

To demonstrate how easily AI agents can be manipulated, Tenable Research created an AI travel agent in Microsoft Copilot Studio to manage customer travel reservations, including creating new reservations and modifying existing ones, all without human intervention. The AI travel agent was provided with demo data that included the names, contact information, and credit card details of demo customers and was given strict instructions to verify the customer’s identity before sharing information or modifying bookings.

Using a technique called prompt injection, Tenable Research successfully hijacked the AI agent’s workflow to book a free vacation and extracted sensitive credit card information.

The findings of this research could have significant business implications, including:

  • Data Breaches and Regulatory Exposure: Tenable Research coerced the agent into bypassing identity verification and leaking payment card information (PCI) of other customers. The agent, designed to handle sensitive data, was easily manipulated into exposing full customer records.

  • Revenue Loss and Fraud: Because the agent had broad “edit” permissions intended for updating travel dates, it could also be manipulated into changing critical financial fields. Tenable Research successfully instructed the agent to change a trip’s price to $0, effectively granting free services without authorisation.
Ms. Keren Katz, Senior Group Manager of AI Security Product and Research at Tenable
Ms. Keren Katz, Senior Group Manager of AI Security Product and Research at Tenable

“AI agent builders, like Copilot Studio, democratise the ability to build powerful tools, but they also democratise the ability to execute financial fraud, thereby creating significant security risks without even knowing it,” said Ms. Keren Katz, Senior Group Manager of AI Security Product and Research at Tenable. “That power can easily turn into a real, tangible security risk.”

AI Governance and Enforcement are Mission Critical for Safe and Secure AI Usage

A key takeaway is that AI agents often possess excessive permissions that are not immediately visible to the non-developers building them. To mitigate this, business leaders must implement robust governance and enforce strict security protocols before deploying these tools.

To avoid data leakage, Tenable recommends:

  • Preemptive Visibility: Map exactly which systems and data stores an agent can interact with before deployment.
  • Least Privilege Access: Minimise write and update capabilities to only what is absolutely necessary for the agent’s core use case.
  • Active Monitoring: Track agent actions for signs of data leakage or deviations from intended business logic.

If you have an interesting Article / Report/case study to share, please get in touch with us at editors@roymediative.com  roy@roymediative.com, 9811346846/9625243429.

Tags: AI Risks Enabling Financial Fraud and Workflow HijackingResearch Reveals No-Code Agenticsmart solutions worldTenable
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

Immersion India Drives Outcome-Led Programmes as AI Accelerates the Global Skills Reset

by SmartSolutionUser1
August 12, 2026
0
Immersion India Drives Outcome-Led Programmes as AI Accelerates the Global Skills Reset

Immersion India, a Bengaluru-based experiential learning company founded in 2017, announced a stronger focus on its outcome-led India immersion programmes for international business schools, universities and corporate leadership...

Read moreDetails

AI-enabled email accounts could become the ultimate insider threat, Barracuda Unfolds

by SmartSolutionUser1
August 11, 2026
0
AI-enabled email accounts could become the ultimate insider threat, Barracuda Unfolds

The greatest risk from a compromised AI-enabled account is how quickly an AI assistant can help attackers uncover sensitive information, identify targets, craft convincing communications, and advance an...

Read moreDetails

Gartner Predicts Strong 96% Growth in AI-Optimized IaaS Spending

by SmartSolutionUser1
August 11, 2026
0
Gartner Predicts Strong 96% Growth in AI-Optimized IaaS Spending

Worldwide AI-optimized infrastructure as a service (IaaS) spending is projected to grow 96% through 2026, reaching $42 billion, according to Gartner, Inc., a business and technology insights company....

Read moreDetails

Bridge Data Centres and Morong Electric Jointly Launch the World’s First Fully Prefabricated Power Module for AI Data Centres 

by SmartSolutionUser1
August 10, 2026
0
Bridge Data Centres and Morong Electric Jointly Launch the World’s First Fully Prefabricated Power Module for AI Data Centres 

Bridge Data Centres (BDC), a Singapore-headquartered hyperscale data centre provider, and Morong Electric, an electrical manufacturing specialist, have launched PowerCore 5.0, the world's first fully prefabricated power module...

Read moreDetails

KLH Hosts AICTE-ATAL FDP on AI and Advanced Analytics in Digital Marketing

by SmartSolutionUser1
August 11, 2026
0
KLH Hosts AICTE-ATAL FDP on AI and Advanced Analytics in Digital Marketing

The Department of BBA of KLH Bachupally inaugurated an AICTE Training and Learning (ATAL) Academy-sponsored Six-Day Faculty Development Programme (FDP) titled "AI and Advanced Analytics in Digital Marketing:...

Read moreDetails
Next Post
Where IT Spending Is Headed Next – 4 SAP Concur’s Joule AI Agents Transforming Travel and Expense Management

Where IT Spending Is Headed Next - 4 SAP Concur’s Joule AI Agents Transforming Travel and Expense Management

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

Browse by Category

Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

  • News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

BROWSE BY TAG

Agentic AI AI Akamai AMD Cloudflare CloudKeeper Coforge CrowdStrike Cybersecurity Databricks Fortinet Gartner GenAI Google Cloud HCLTech Honeywell IBM India Infosys Kaspersky Keysight Kramer LTIMindtree Microsoft New Relic Nvidia OpenAI Palo Alto Networks PPDS Qlik Qualcomm Red Hat Seqrite ServiceNow SiMa.ai smart solutions world smartsolutionsworld smart solutions world latest news Snowflake Software Tata Communications Tech Mahindra Technology Tenable Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

© 2024 NCN - Premium news & magazine by NCN.

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?