the voice of customer experience technology
Front page
NewsCX Trust1h · 12:01 BST · 6 min read

AI Agents Raise Fresh Risks for Customer Data

Customer data, AI agents and core CX platforms are all coming under pressure. This week saw OpenAI expand its investigation into agents accessing third-party systems and data, 40 million McDonald’s records exposed, and an AI agent breaching a customer support platform

Customer data folders spilling from an open filing cabinet.

I seem to be saying this a lot recently, but cybersecurity is clearly becoming harder to separate from the CX story. As I’ve been following this week’s developments, what stands out is how many of the incidents touch the systems that CX teams rely on every day, from customer data platforms (CDPs) to development tools, identity services, and increasingly, autonomous AI agents.

OpenAI’s continuing investigation into its agent behavior is highlighting how software can interact with systems and security boundaries in ways its developers did not intend, and serves as a warning to CX leaders bringing autonomous agents into their teams’ workflows.

The broader security challenge is that the perimeter is increasingly made up of interconnected platforms, integrations, identities and automated software. A customer database can become a fraud target, an AI coding tool can expose internal information, and an autonomous agent can potentially reach systems far beyond the environment where it started.

Here are some of the biggest cybersecurity developments that have crossed my desk this week.

OpenAI Notifies 100 Organizations That Its Agents Crossed Security Boundaries

OpenAI's investigation into the incident earlier this year involving its models breaching AI platform Hugging Face has provided a look at how highly capable models can behave when given access to tools and external systems.

OpenAI has disclosed additional cases involving its models interacting with external websites and, in some cases, taking actions that were outside their intended tasks.

The company said this week it has identified and notified 100 companies of cases where “[o]ur models may have bypassed a third party’s security controls or may have impaired the availability of an online service; or misalignment cases negatively impacted third-party websites or services.”

The issue is becoming increasingly relevant to CX as enterprises connect AI agents to CRM platforms, knowledge bases, customer records and business workflows.

Giving an agent access to a system creates a different security problem from giving a conventional software application access. As the agent can interpret instructions, select tools and determine its next action, permissions need to be combined with monitoring and controls around what the agent is allowed to do.

Enterprises deploying customer service agents will need to know what systems an agent can reach, what actions it can take and how quickly unusual activity can be detected.

McDonald’s Exposes 40 Million Records Through CDP

A customer data platform used by McDonald’s Indonesia has reportedly exposed more than 40 million records, including approximately 28 million customer records.

The exposed information included names, email addresses, phone numbers and device IDs, alongside loyalty transaction data. More than 71,000 corporate advertising records were also reportedly accessible.

The affected technology sits directly within the customer data architecture. CDPs are designed to consolidate information from multiple touchpoints into unified customer profiles, making them valuable for loyalty, personalization and marketing. That concentration also means a configuration or access-control failure can expose a broad collection of customer information at once.

As with similar incidents of data exposure, scammers could use the information in social engineering and loyalty fraud campaigns. The database has since been secured, although it’s unclear whether unauthorized parties accessed or copied the information while it was exposed.

AI Coding Agents Leak 13,000 Internal Screenshots

AI coding agents have created another unexpected data exposure, with researchers at cybersecurity startup Glow Security identifying more than 13,000 internal screenshots published to public GitHub repositories by agents working across 343 organizations, including “one of the world's largest tech companies, a frontier AI lab, a major enterprise software provider, and a Fortune 500 travel company.”

The incident, dubbed PixelLeak, involved AI coding agents creating public repositories to store screenshots generated during software-development tasks. The researchers identified screenshots containing sensitive corporate information, such as internal billing interfaces and other development environments.

The important detail here is that the agents were carrying out legitimate development tasks, but the exposure happened because the software used to complete those tasks created a route for internal information to leave the organization's controlled environment.

That creates a familiar problem for CX technology. Developers working on CRM integrations, customer portals, contact-center applications and other customer-facing systems routinely have access to sensitive environments. If an AI coding assistant can interact with those environments, its permissions and output destinations become part of the data-security equation.

“Shadow AI” is a term I’m hearing more and more in my conversations. Organizations need to understand which AI development tools have access to customer-facing systems and where the information they generate is stored or published, as unauthorized tools can create data pathways that traditional application security reviews may miss.

Apple Patches Zero-Day Used in Targeted Attacks

Apple released security updates on September 29 to address CVE-2026-86950, a zero-day vulnerability in its CoreGraphics framework.

Apple said the vulnerability may have been exploited in extremely sophisticated targeted attacks. The flaw could allow arbitrary code execution when a vulnerable device processes specially crafted content. Apple issued updates for iOS, iPadOS and macOS.

The vulnerability is relevant to CX operations because customer-service teams increasingly work across mobile and desktop devices while accessing CRM systems, communications platforms and customer information.

A compromised endpoint can provide an attacker with an alternative route into customer-facing systems even when those applications have their own security controls. Endpoint security remains part of the customer-data protection story and service organizations should treat employee devices as potential access points into customer records and operational systems.

AI Agent Used in Attack on Cybersecurity Non-Profit

The Dutch Institute for Vulnerability Disclosure (DIVD) disclosed that its network was breached using an AI agent that exploited two zero-day vulnerabilities in Zammad, an open-source customer support and ticketing platform.

The incident provides a real-world example of an AI-enabled attack involving software used to manage support operations.

The vulnerabilities enabled session hijacking, remote code execution and privilege escalation. DIVD said the AI-driven attack moved through its environment autonomously, with the organization later reconstructing the attack from information left behind by the agent.

DIVD said the first malicious access occurred on September 21 and that it blocked access to systems the following day while beginning its investigation. The vulnerabilities were publicly documented on September 29.

In Other News

Elsewhere this week, vulnerabilities and breaches affecting network infrastructure, AI agents and government systems added to the security concerns facing organizations handling sensitive data:

  • Cisco SD-WAN Manager zero-day actively exploited: Cisco disclosed a critical authentication-bypass vulnerability in Catalyst SD-WAN Manager on September 30. CVE-2026-76504 carries a CVSS score of 9.8 and can allow an unauthenticated remote attacker to access an affected system with administrator privileges. Cisco said it was aware of active exploitation and urged customers to upgrade.

  • OpenAI, again: Asymmetric Security reported this week that it found OpenAI agents had interacted with 55 public and private-sector websites over a six-month period, including attempts to access or scrape information.

  • Pentagon personnel breach affects around 3 million people: A months-long breach of a Defense Manpower Data Center system exposed personal information belonging to around 2.8 million living people and nearly 300,000 deceased people, according to reporting based on government notifications.

rate this story
helps rank stories across CX Today
The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
same beat · CX Trust

When AI Agents Ignore “No,” Security Gets Real

24 Sept 2026
same beat · CX TrustWhy AI Is Pushing UK Businesses to Take Back Control of Their Data23 Sept 2026same beat · CX TrustThe EU AI Act Is a CX Problem Now22 Sept 2026