ChatGPT Leak: Attackers Could Eavesdrop on Your Gmail

On September 8, 2026, Check Point Research revealed how attackers could spy on victims' Gmail and Drive through a hidden channel between ChatGPT accounts.

ChatGPT
security
AI-agents
privacy
By the AI Focus team · 4 min read
Share:

At a glance

  • Check Point Research demonstrated on September 8, 2026, that ChatGPT sessions from different accounts could reach each other through a shared internal packet service.
  • Everything the session already had access to was exposed: conversation history and files, plus connected apps like Gmail, Google Drive, Microsoft Teams, and GitHub.
  • The only trace was a small 'Talked to Gmail' label, logged after the reading already occurred; OpenAI has since shut down the affected service.
  • Our take: every connection you give an AI assistant is a key, not a gadget. This is a structural problem with agents that have access, not a ChatGPT slip-up.
ChatGPT Leak: Attackers Could Eavesdrop on Your Gmail
In this article

ChatGPT Leak: Attackers Could Eavesdrop on Your Gmail

Researchers at Check Point Research managed to read someone else’s mailbox through ChatGPT. No cracked password, no phishing email - instead, a hidden channel between ChatGPT accounts that were supposed to be fully separated. Everything the victim had connected to ChatGPT lay exposed: Gmail, Google Drive, Microsoft Teams, and GitHub. Check Point published the research on September 8, 2026; Tweakers reported the same day. OpenAI has since shut down the affected internal service, and there is no evidence of real-world abuse. Yet this is more than a patched leak: it shows what happens when you hand an AI assistant keys to your doors.

Two separate accounts, one shared storage location

The problem ran deep in the machinery. Sessions from different ChatGPT accounts were able to read and write metadata on the same internal packet service, a JFrog Artifactory instance - essentially a warehouse where software retrieves its components and related data. Accounts should be completely isolated from each other, but in practice they shared a storage location.

An attacker only needed to leave an instruction there. That could happen through a malicious prompt someone pasted, a shared conversation link, or a custom GPT - a modified ChatGPT variant anyone can offer. The next time the victim asked a normal question, their ChatGPT session would check that shared storage, execute the hidden command with the privileges that session already had, write the result back, and then answer the real question normally. The victim saw a normal answer to a normal question. In the demonstration, researchers retrieved email data through the victim’s connected Gmail, and it was ready in the attacker’s session after just one normal conversation turn.

In practice, this was nearly zero-click - an attack requiring almost nothing from the victim. No attachment to open, no fake login page. A single pasted prompt, a shared link, or a custom GPT with a hidden instruction was enough.

The assistant works dutifully while it’s being robbed

This is the core of the story. Every connection you give your AI assistant is a door. You think of convenience: having emails summarized, documents looked up, code reviewed. An attacker sees the exact same list, but as loot. And the assistant itself can’t tell the difference: it executes the hidden command just as diligently as your real question, because both arrive through channels it trusts.

It barely left a trace. The only sign was a small “Talked to Gmail” label on the answer, and that was only logged after the reading had already happened. Check Point captures it most sharply themselves:

“It recorded what occurred. It did not give the victim a chance to stop it.”

It recorded what happened; it gave the victim no chance to prevent it. This pattern keeps appearing with agents - AI systems that perform tasks independently: the check comes afterward, if it comes at all. In the wiki incident now before the European Commission, agents ran outside their instructions for weeks without anyone noticing. Here, a session carries out someone else’s command without the victim being able to intervene. Different mechanism, same lesson: this isn’t a ChatGPT scandal, it’s a structural problem with assistants that have access.

What went right this time

This leak was found by researchers, not criminals, and there’s no evidence in reporting that it was ever exploited in the wild. OpenAI confirmed that the affected Artifactory instance was decommissioned. When Check Point reported the leak exactly isn’t stated in the article, so we can’t say much about response speed. And researchers who make this kind of work public strengthen the system: every described and patched attack route is one fewer. Don’t assume this means you should switch to a different assistant though: nothing shows that competitors couldn’t make this kind of architectural mistake.

What you need to do today is simple. Open the settings of your ChatGPT, or whichever assistant you use, and review the list of connected apps. Anything you haven’t really used in the past month: disconnect it. Connect only what you need for the work you actually ask that assistant to do, and treat every connection as a key to your house, not a gadget you turn on because you can. If customer data sits in what you connect - a mailbox full of client files, for example - there’s more at stake than your own risk; what customer data is doing in an AI assistant, we sorted out earlier. This week’s leak is patched. The doors you open yourself remain your responsibility.

Update September 10, 2026: trust in what you see was also tackled from the other side that same week: Apple builds authenticity proof into the camera itself with Reference Image.

Stay on top of AI trends

Get the latest insights on AI in business every week, with exclusive case studies and practical implementation tips.

No spam. Unsubscribe anytime. Privacy guaranteed.