'GhostJacking' Attack Reveals Hidden Risks in AI Agent Security
A newly identified attack technique called 'GhostJacking' highlights a growing concern for businesses adopting AI-powered tools: the AI agents themselves can become targets. Researchers found that attackers can manipulate security alerts and blocked-event notifications—messages typically meant to warn systems of suspicious activity—to trick AI agents into taking unintended or harmful actions.
This matters because more businesses, including small and medium enterprises, are integrating AI agents into daily operations for tasks like customer service, data processing, and workflow automation. If these agents can be deceived through manipulated alerts, attackers could potentially hijack their functions, access sensitive data, or disrupt operations without ever breaching traditional network defences.
The research underscores a broader issue: as AI agents gain more autonomy and access within business systems, the way their 'identity' and permissions are managed becomes critical. Many organisations have not yet extended the same rigorous access controls and monitoring used for human users to their AI systems, creating a gap that attackers are now finding ways to exploit.