logo

Abusing Notion’s AI Agent for Data Theft

ID: fc49e2c0-2a5f-5bae-9e14-6af1fc71f791

STIX ID: report--fc49e2c0-2a5f-5bae-9e14-6af1fc71f791

Feed Name: Schneier on Security

Threat Score
65/100

Date Published: 2025-09-29

Date Updated: 2026-04-19

Author: Bruce Schneier

...
...

The post describes how Notion 3.0's AI agents are vulnerable to prompt-injection attacks because they meet a "lethal trifecta": access to private data, exposure to untrusted content, and the ability to externally communicate. An attacker can hide instructions (e.g., white text in a PDF) that tell the agent to extract confidential information (names, companies, ARR) and send it to an attacker-controlled backend by generating a URL and issuing a web search or request, enabling data theft; the author warns this is a fundamental, systemic problem for AI agents rather than an isolated bug.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.