Internal AI support assistant returned another customer's data after a crafted ticket
A medium Cybersecurity scenario on AI Assistant Prompt-Injection Leak.
Start a graded attempt against this scenario. Your response is scored by the same deterministic rubric used across the catalog. Email and evidence content stay hidden until you start.
Launches this exact scenario. One of 6 templates in this Track + Difficulty pool.
catalog id · ai-assistant-prompt-injection-leak
What this scenario practices, mapped to recognized frameworks.
Educational mapping only. Not a compliance attestation.
- Indirect prompt-injection incident response
- Least-privilege retrieval scoping for AI assistants
- Data from Information Repositories · CollectionT1213 · TA0009PartialMedium confidence
Trains response when an AI assistant surfaces repository data it should not.
- User Account PermissionsD3-UAPMappedHigh confidence
Trains least-privilege scoping of the assistant's retrieval connectors.
- Network Traffic AnalysisD3-NTAMappedMedium confidence
Trains review of assistant request/response traces to scope the leak.
- Identity Management, Authentication and Access Control · ProtectPR.AA · PRMappedHigh confidence
Trains access-scoping of the assistant's data connectors.
- Continuous Monitoring · DetectDE.CM · DEMappedMedium confidence
Trains detection of anomalous disclosure from assistant traces.
- IR lifecycle phaseDetection & AnalysisMappedHigh confidence
Trains tracing which records the assistant disclosed and how far.
- IR lifecycle phaseContainment, Eradication & RecoveryMappedHigh confidence
Trains pausing/safe-moding the assistant and narrowing its scope.
- Vendor/Supplier Cybersecurity Requirements2.RMappedMedium confidence
Trains governance of the assistant's third-party connectors.
- Detecting Relevant Threats and TTPs3.AMappedMedium confidence
Trains detection of injected-instruction abuse via output review.
- Application Software SecurityControl 16MappedHigh confidence
Trains treating untrusted input as data and securing the AI app.
- Data ProtectionControl 3MappedMedium confidence
Trains protecting the customer and internal data the assistant can reach.