A newly discovered zero-click attack, dubbed Shadow Escape, is enabling threat actors to exfiltrate vast amounts of sensitive data—including Social Security numbers, financial information, and medical records—from organizations using popular AI assistants. The attack exploits the Model Context Protocol (MCP), a standard used to connect large language models such as ChatGPT, Claude, and Gemini to internal databases and tools. By embedding concealed instructions within seemingly benign documents, attackers can trigger AI assistants to extract and transmit private data without any user interaction or awareness.
Researchers from Operant AI warn that the attack leverages default MCP permissioning, making it easy to perpetrate and difficult to detect, with the potential for trillions of records to be compromised and sold on the dark web. The attack does not require traditional phishing or user error; instead, it relies on the AI assistant's legitimate access to sensitive information, which is then abused for stealthy data exfiltration. Organizations are urged to audit their AI agent deployments and review MCP configurations to mitigate this emerging threat.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting emphasized that the newly disclosed Shadow Escape attack could lead to data exposure in AI assistant environments. This appears to be additional coverage of the same disclosure rather than a separate real-world incident.
Shadow Escape was publicly reported as a new zero-click attack technique affecting AI assistants, with claims that it could expose sensitive data at large scale. Coverage described the issue as putting vast numbers of records at risk through AI assistant interactions.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.