Opening SecureFlowAgentForger ChatGPT Workspace Agent Forgery and Autonomous Insider
Case summary & sources

AIDEFEND SecureFlow / SecureFlow Case Index

Zenity Labs aidefend-sf0025

AgentForger ChatGPT Workspace Agent Forgery and Autonomous Insider

  • Copilot & SaaS
  • Autonomous Agents
  • Tool Integrations & MCP
  • Data Exfiltration
  • Credential & Identity Theft
  • Financial Fraud & Abuse

Zenity validated AgentForger against ChatGPT Workspace Agents: a crafted builder link used the victim's authenticated session to auto-submit attacker instructions, create and publish an agent, attach previously authorized connectors, disable supported approval prompts, stack recurring hourly schedules at five-minute offsets, and trigger immediate execution through Preview. The staggered schedules produced an effective five-minute TASK-email command loop across connected enterprise apps. The researchers demonstrated four alternative impact paths: organization mapping, sensitive-data theft, credential harvesting, and victim impersonation for phishing or fraud.

Mapped threat techniques

Source