# ChatGPT could secretly steal Gmail data via shared links

> Source: <https://itdaily.com/news/security/chatgpt-could-steal-gmail-data/>
> Published: 2026-09-09 07:49:52+00:00

**Check Point has discovered a security flaw between ChatGPT and Gmail. An attacker could secretly exfiltrate emails via a hidden communication channel.**

Security firm Check Point warns of a vulnerability involving ChatGPT. The popular chatbot could potentially grant attackers access to your confidential emails in Gmail. OpenAI has since resolved the vulnerability, but experts warn of similar risks in other AI applications.

The security flaw demonstrates how vulnerable integrated AI systems are when users grant them extensive access to external services. In the proven attack scenario, a manipulated prompt, a shared web link, or a custom GPT was sufficient to take control of a victim’s account. ChatGPT then retrieved data from Gmail using the owner’s legitimate permissions and forwarded it to the attacker, while the chat window remained perfectly normal for the victim.

## Abuse of trust

Check Point Research refers to this phenomenon as a ‘manipulated insider.’ It involves an AI assistant that is manipulated via legitimate access rights to act on behalf of an attacker within an organization’s trust framework. No stolen passwords or malware are involved; only the permissions entrusted to the assistant by the user themselves are abused. OpenAI has since patched the specific leak, but the underlying technique remains a point of concern.

According to Fred Streefland, [CISO at Check Point](https://itdaily.com/cio/deryck-mitchelson-check-point-interview/), this is not an isolated ChatGPT problem. Attackers can apply similar techniques to existing capabilities and vulnerabilities in other AI applications, such as Microsoft Copilot. He believes the infrastructure behind modern AI is so complex that security flaws remain inevitable. The warning states that when a system is smart, it is simultaneously vulnerable.

## Lack of oversight

According to Streefland, the lack of oversight is the biggest pitfall for companies. As a result, the identification and protection domains within cybersecurity policies must scale up rapidly. After all, those who lack visibility into their systems cannot adequately secure them.

Check Point advises security managers to create an inventory of all AI applications and active AI agents within the organization. Additionally, the security firm advocates for proactive testing of integrations through specialized red teaming and vulnerability assessments before they go operational. Only through strict governance, continuous monitoring, and a preventive approach will AI remain a valuable tool rather than a digital security risk.
