Opening SecureFlowSalesforce Einstein Prompt Mines to CRM Data Corruption
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Zenity Labs aidefend-sf0018

Salesforce Einstein Prompt Mines to CRM Data Corruption

  • Copilot & SaaS
  • Autonomous Agents
  • Tool Integrations & MCP
  • Data Corruption

Zenity demonstrated that an unauthenticated attacker could use a public Salesforce Web-to-Case form to insert four specially chained case subjects that together formed a prompt mine. When an employee later asked Einstein for open cases, Query Records loaded the records into retained context even though the interface rendered only the first three. A natural follow-up question, including one asked five turns later, activated the hidden instructions, caused Einstein to query contact IDs, and repeatedly invoke an administrator-enabled Update Customer Contact action to replace customer email addresses with an attacker-specified value. The research required that write action to be configured in the organization and was not an out-of-box write path.

Mapped threat techniques

Source