Check Point Research said a planted instruction in ChatGPT could quietly read data from connected Gmail and pass it to another account through shared Artifactory metadata, while the user still saw an ordinary answer. The same proof of concept could also copy out chat history and files from that conversation.
The trick is split execution: one hidden stream handles the attacker’s task, while the visible stream answers the user, so the reply looks clean and only a small “Talked to Gmail” label hints that an app was used. Because the malicious instruction has to be present before the chat starts, a pasted prompt, shared conversation, or custom GPT can seed the leak without changing the visible result.
For teams that let ChatGPT reach email, docs, or tickets, the exposure sits in the connected-app permission and the hidden conversation state, not in the wording of the answer. If those tools can already see sensitive data, a planted instruction can turn that access into a covert exfiltration path even after the model’s reply appears harmless.