Microsoft has revealed a new side-channel attack technique, dubbed Whisper Leak, that enables adversaries to infer the topics of conversations with remote large language models (LLMs) by analyzing encrypted network traffic. The attack leverages packet size and timing patterns in streaming-mode LLM communications, allowing a passive observer—such as a nation-state actor at the ISP level or someone on the same Wi-Fi network—to determine if a user's prompt relates to a sensitive subject, even though the traffic is protected by HTTPS encryption. This vulnerability poses significant privacy risks for both individual and enterprise users of AI chat services.
The Whisper Leak attack is notable because it bypasses traditional encryption safeguards by exploiting side-channel information inherent in the way LLMs stream responses. Microsoft researchers demonstrated that trained classifiers can match observed traffic patterns to specific conversation topics, raising concerns about the confidentiality of AI-assisted communications. The disclosure highlights the need for additional countermeasures to protect the privacy of users interacting with AI models over the internet, especially in environments where adversaries may have the capability to monitor encrypted traffic.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
On its Security Blog, Microsoft publicly disclosed Whisper Leak, outlined the surveillance risks for users such as those on public Wi-Fi or in oppressive regimes, and shared defensive guidance. The post also referenced public research code and proof-of-concept materials.
Microsoft reported the Whisper Leak findings through responsible disclosure to affected providers before public release. According to the disclosure, multiple providers implemented mitigations to reduce the practicality of the attack, including response obfuscation measures.
Microsoft described Whisper Leak as a novel remote side-channel attack against streaming language models that infers the topic of prompts by analyzing encrypted traffic metadata such as packet sizes and timings. In controlled testing, the technique achieved very high topic-classification accuracy, including results above 98% in some scenarios.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourcescworld.com
Open sourcesecurityonline.info
Open sourcecsoonline.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.