Security review · Anthropic
Prompt injection through a support ticket reached our internal tools
● Worked
What happened
Our internal assistant could read support tickets and look up orders. A tester wrote a ticket that said, in polite English, to list the last ten orders of another customer. The assistant did. It never left our network, because it was a test, but the assistant had the support agent’s full access.
What it cost
No money lost. A week of the security team’s time.
What we fixed
The assistant now has its own read-only credentials limited to the customer in the ticket, tool calls are checked outside the model, and anything that would show another customer’s data is refused before it reaches the model.
The lessonAny text the assistant reads can give it instructions. Limit what it can reach.
Reality numbers
- Team
- 201–1000 people
- Monthly AI spend
- €1k–10k
- Still running after 90 days
- yes