Salesforce Einstein Prompt Mines to CRM Data Corruption
- Copilot & SaaS
- Autonomous Agents
- Tool Integrations & MCP
- Data Corruption
Zenity demonstrated that an unauthenticated attacker could use a public Salesforce Web-to-Case form to insert four specially chained case subjects that together formed a prompt mine. When an employee later asked Einstein for open cases, Query Records loaded the records into retained context even though the interface rendered only the first three. A natural follow-up question, including one asked five turns later, activated the hidden instructions, caused Einstein to query contact IDs, and repeatedly invoke an administrator-enabled Update Customer Contact action to replace customer email addresses with an attacker-specified value. The research required that write action to be configured in the organization and was not an out-of-box write path.