Home » AI News » Salesforce Agentforce Zero-Click Data Exfiltration Risks

Salesforce Agentforce Zero-Click Data Exfiltration Risks

Facebook
X
LinkedIn
Pinterest
Salesforce Agentforce Zero- Click Data security risk.

Salesforce Agentforce faced a newly disclosed attack chain that researchers say could enable Salesforce Agentforce zero-click data exfiltration from CRM environments without requiring the victim to click a malicious link or authenticate into the target Salesforce organization. The attack, dubbed SalesBleed, combined indirect prompt injection with weaknesses in URL handling and Agentforce integrations.

The incident highlights a broader problem with autonomous AI systems: when an AI agent can read business records, use tools, access sensitive data, and communicate with external services, malicious instructions hidden inside ordinary business content can become a security problem.

What Is Salesforce Agentforce Zero Click Data Exfiltration?

Salesforce Agentforce Zero Click Data Exfiltration refers to a scenario in which an attacker can cause an Agentforce agent to expose sensitive information without requiring the victim to manually click an attacker-controlled link. The important distinction is that the attack does not necessarily begin with a conventional malicious application or compromised Salesforce account. Instead, an attacker can place malicious instructions into content that an agent later processes. This is a form of indirect prompt injection, where untrusted data becomes an instruction source for an AI agent.

Security researchers at Zenity Labs disclosed SalesBleed on September 24, 2026. Their research described an attack chain involving Web to Lead, Agentforce processing, Trusted URL protections, and external communication mechanisms.

How the Agentforce Attack Worked

Malicious Instructions Entered Through Web to Lead

Salesforce Web to Lead allows external users to submit information that enters CRM workflows. According to Zenity’s research, an attacker could place a hidden prompt injection payload into a lead submission. The malicious content could remain dormant until an Agentforce agent later processed that record.

This creates an important security boundary problem. The content may look like ordinary customer information to a human, while an AI agent can interpret embedded instructions as part of its working context.

The Agent Processes the Poisoned Record

Once Agentforce processes the compromised lead, the injected instructions can attempt to influence the agent’s behavior. This is where AI agent attacks differ from many traditional application attacks. Instead of directly exploiting a database query or authentication mechanism, the attacker attempts to manipulate the agent’s decision-making process while the agent already has legitimate access to business information.

Data Can Leave Through an External Channel

Zenity reported that the attack chain also involved weaknesses related to Salesforce Trusted URLs and methods for causing data to reach an attacker-controlled destination. The researchers described techniques involving URL parsing and automatic network activity that could support data exfiltration without requiring a user to click the resulting content.

This is particularly important because traditional security controls often assume that a person must interact with a malicious link before the attack succeeds. An autonomous agent changes that assumption. If an agent can generate content, access data, invoke tools, and interact with external systems, the system itself can become part of the attack path.

Why Zero Click Agent Attacks Matter

Zero-click behavior increases the potential impact of AI agent threats because human interaction may no longer be the final step required to trigger an action. That does not mean every Agentforce deployment is automatically vulnerable. Exposure depends on configuration, permissions, integrations, agent behavior, and the specific attack path involved.

Traditional phishing attacks commonly depend on a victim opening an attachment, clicking a link, entering credentials, or approving an action. Agentic systems can introduce another model: the AI receives malicious content as part of a legitimate workflow and then acts because it interprets that content as an instruction.

Salesforce Agentforce Zero Click Data AI security.
Salesforce Agentforce Zero Click Data explained.

The Biggest AI Agent Security Risks

The SalesBleed research illustrates several AI agent security risks that organizations should consider when deploying autonomous systems.

Excessive Permissions

This is especially important for AI agent security risks, where excessive permissions can increase the impact of AI agent attacks and potential data exposure. As AiSecMaster highlights, applying least-privilege access, limiting agent capabilities, and monitoring autonomous actions can help organizations strengthen AI security while reducing the risk of unauthorized data access.

Untrusted Data Becoming Instructions

Customer messages, uploaded documents, CRM records, websites, emails, and third-party tool responses can contain attacker-controlled text. A secure architecture should treat external content as data rather than automatically trusting it as an instruction.

Excessive Agent Autonomy

Autonomous actions can improve productivity, but they also increase the consequences of successful manipulation. For example, an agent involved in supply chain planning might access sales records, inventory information, forecasts, and customer data. If the same agent can also communicate externally or invoke additional tools, a successful prompt injection could have a larger blast radius.

Cross System Integrations

An agent connected to CRM, Slack, email, databases, browsers, and third-party applications creates a larger attack surface. Zenity’s follow-up research showed why this matters: the SalesBleed attack chain could extend into Slack, where Agentforce functionality could potentially be abused to send phishing messages under the agent’s identity. Salesforce subsequently updated the relevant behavior and attribution controls.

Salesforce Security Controls and Mitigations

Salesforce has already introduced multiple controls designed to reduce Agentforce security risks. Salesforce says its Einstein Trust Layer includes protections such as prompt injection detection, audit trails, secure data retrieval, and zero data retention controls for supported interactions. Salesforce also changed its Agentforce Trusted URL configuration to reduce risks associated with broad wildcard allowlisting.

In addition, Salesforce changed confirmation behavior for certain Agentforce actions to reduce prompt injection risks and recommended that customers require confirmation for sensitive custom actions.

How Organizations Can Reduce Agentforce Data Exfiltration Risk

Security teams can use the following checklist when reviewing Agentforce deployments:

  • Audit agent permissions: Remove unnecessary access to CRM objects, fields, records, and actions.
  • Treat external content as untrusted: Customer-submitted text should never automatically become trusted instructions.
  • Review Web to Lead workflows: Identify which agents process externally submitted records.
  • Restrict outbound destinations: Use explicit allowlists rather than broad wildcard rules.
  • Require confirmation: Sensitive write, communication, deletion, and external actions should require appropriate approval.
  • Monitor agent activity: Log unusual queries, tool calls, external requests, and unexpected data access.
  • Review connectors: Every additional application or tool can increase the attack surface.
  • Test indirect prompt injection: Security testing should include malicious content hidden inside realistic business records.
  • Apply least privilege: Limit both data access and action capabilities.
  • Prepare incident response: Define how agents can be disabled quickly if suspicious behavior is detected.

What This Means for Rogue AI Agents

The SalesBleed case also illustrates why rogue AI agents should not be understood only as intentionally malicious autonomous systems. An agent can behave like a rogue system after being manipulated by hostile content, even though the underlying model, application, and business workflow were designed for legitimate purposes.

That distinction matters for defenders. Security monitoring should look not only for unauthorized software but also for legitimate agents performing unusual actions, accessing unexpected records, communicating with unfamiliar destinations, or executing instructions that conflict with their intended role.

The Broader AI Agent Security Lesson

The same security principle applies beyond Salesforce. New agentic products such as Meta Muse AI agent are designed to perform tasks across applications and services rather than simply generate text. Meta says Muse uses a dedicated Secure VM, permission controls, a separate Sentinel component, and approval mechanisms for sensitive actions.

Security researchers have nevertheless continued to examine how powerful agent permissions can become an attack surface. Recent reporting on Muse described a macOS issue in which locally running malware could manipulate an undocumented setting and redirect Muse’s dictation traffic.

For AiSecMaster readers, the broader lesson is that agent security should be designed around capabilities, permissions, trust boundaries, and external communication—not simply around whether an AI model produces safe-looking answers.

Salesforce Agentforce Zero Click Data exfiltration.
Salesforce Agentforce Zero Click Data attack.

Conclusion

The Salesforce Agentforce Zero Click Data exfiltration research shows how AI agents can create security risks that traditional application security models may not fully address. An attacker may not need a stolen account when malicious instructions can enter through legitimate business content and influence an agent that already has access to sensitive systems.

The practical response is not to eliminate AI agents, but to control what they can read, what they can do, where they can communicate, and which actions require human confirmation. As agentic AI becomes more deeply integrated into enterprise workflows, those controls should become a core part of AI security and cybersecurity programs.

Frequently Asked Questions (FAQs)

What is Salesforce Agentforce zero-click data exfiltration?

It describes an attack scenario in which malicious content can manipulate an Agentforce agent and cause sensitive information to reach an attacker-controlled destination without requiring the victim to click a link. The SalesBleed research demonstrated a reported zero-click attack chain involving Agentforce.

What is SalesBleed?

SalesBleed is the name given by Zenity Labs to a chain of Salesforce Agentforce vulnerabilities disclosed in September 2026. The research described indirect prompt injection through Web to Lead, URL handling weaknesses, and Agentforce integrations that could enable data exfiltration and phishing.

Can prompt injection steal Salesforce data?

Prompt injection can influence an AI agent's behavior when untrusted content is incorporated into its context. The actual impact depends on the agent's permissions, tools, integrations, data access, and security controls.

How can companies protect Agentforce from prompt injection?

Organizations should use least privilege permissions, restrict outbound destinations, require confirmation for sensitive actions, monitor agent activity, treat external content as untrusted, and test agents against indirect prompt injection scenarios.

Is Agentforce automatically unsafe after the SalesBleed disclosure?

No. The disclosed research describes specific attack paths rather than proving that every Agentforce deployment is vulnerable. Salesforce reported and implemented security changes, and organizations should still review their individual configurations, permissions, integrations, and agent workflows.

Related Post

Leave a Reply

Your email address will not be published. Required fields are marked *

follow Us

Popular posts

Your daily updates

Subscribe now. We’ll make sure you never miss a thing.

categories