SalesBleed Flaws Let Salesforce AI Agents Leak CRM Data and Send Phishing Messages

Security researchers have disclosed three vulnerabilities in Salesforce Agentforce that could have allowed attackers to steal sensitive CRM data and distribute phishing messages through trusted enterprise AI agents.

Collectively named SalesBleed, the flaws were discovered by Zenity Labs. Researchers found that an attacker could place malicious instructions inside a Salesforce Web-to-Lead submission. When an employee later asked Agentforce to process the poisoned lead, the hidden instructions could manipulate the AI agent without requiring the employee to click a malicious link.

Zero-Click CRM Data Theft

Two of the vulnerabilities reportedly bypassed Salesforce Trusted URL protections, which are designed to stop AI agents from communicating with unauthorized destinations. A successful attack could expose information such as customer records, contact details, contracts, pricing and sales opportunities.

The third weakness affected the Agentforce integration with Slack. It could allow malicious messages to appear as though they came from a trusted internal AI agent, potentially making phishing attempts more convincing to employees.

Salesforce Fixes the Vulnerabilities

Zenity Labs responsibly reported the vulnerabilities to Salesforce, which investigated and remediated the identified weaknesses. The disclosed attack techniques are no longer expected to work against patched systems.

There is currently no public evidence that SalesBleed was exploited in real-world attacks or caused customer information to be stolen. Organizations should therefore treat the disclosure as important security research rather than a confirmed Salesforce data breach.

Why SalesBleed Matters

SalesBleed demonstrates how AI agents can introduce new security risks when they process untrusted information and have access to sensitive business systems. Organizations deploying enterprise AI should restrict agent permissions, monitor automated actions, inspect external input and prevent agents from sending data to unapproved destinations.

Businesses using Salesforce Agentforce should also review their configurations, monitor Web-to-Lead submissions for suspicious instructions and ensure that Salesforce security updates and recommended controls have been applied.

Leave a Comment

Your email address will not be published. Required fields are marked *