When AI Becomes the Insider: Understanding the AgentForger Attack
- Javier Conejo del Cerro
- hace 1 dÃa
- 2 min de lectura

For decades, phishing attacks have relied on convincing users to perform malicious actions.
AgentForger introduced a different model.
Instead of stealing credentials or installing malware, a single phishing link could create an autonomous AI agent inside the victim’s organization—one capable of acting continuously with the employee’s own permissions.
The attack wasn’t about compromising the user.
It was about creating a new digital employee that answered to someone else.
Phase 1 – One Click Creates a New Insider
The attack starts with what appears to be an ordinary ChatGPT link.
Without additional interaction, the platform begins creating a new AI agent inside the organization’s trusted environment.
The phishing link doesn’t deliver malware.
It delivers an employee with a different boss.
Phase 2 – Turning Trust into Persistence
The malicious instructions configure the agent using the victim’s existing enterprise connectors.
Approval prompts are disabled, available integrations are attached automatically, and the agent is published and scheduled to execute every hour.
Rather than requiring repeated phishing attempts, the attacker creates a persistent autonomous workflow capable of operating indefinitely.
The first click is also the last one required.
Phase 3 – An Autonomous Insider
Once active, the rogue agent continuously checks for specially crafted emails containing new instructions.
Using the victim’s connected applications—including Outlook, Gmail, Google Drive, Slack, Teams, and Microsoft 365—it can collect documents, execute tasks, retrieve sensitive information, search internal communications, and send the results back to the attacker.
It can even impersonate the victim to distribute new phishing messages inside the organization, enabling broader compromise and business email compromise (BEC) scenarios.
The attacker no longer operates inside the network.
The AI does.
Phase 4 – Securing the Next Generation of Identities
OpenAI patched the vulnerability, but AgentForger exposes a larger security challenge.
Autonomous AI agents are rapidly becoming privileged identities capable of making decisions, accessing enterprise systems, and executing workflows without constant human approval.
Protecting AI now requires more than securing users.
Organizations must continuously audit how agents are created, what permissions they receive, what actions they perform, and whether those actions truly reflect human intent.
The next insider threat may not be an employee.
It may be an employee’s AI.
Defense Measures
Organizations should strengthen AI governance by:
Auditing AI agent creation, publication, and scheduling.
Reviewing enterprise connector permissions regularly.
Monitoring autonomous workflows for unusual behavior.
Restricting unnecessary agent privileges and approval bypasses.
Continuously reviewing AI-generated actions across enterprise applications.
Treating AI agents as privileged identities within Zero Trust architectures.
Providing security awareness training focused on AI-enabled phishing.
AI governance is rapidly becoming identity governance.
Conclusions
AgentForger demonstrates that the future of phishing is no longer limited to stealing access.
It is about creating autonomous identities that already have it.
When a single click can deploy an AI capable of thinking, acting, communicating, and persisting inside an organization, the question is no longer whether users can recognize phishing links.
It is whether organizations can recognize when their newest employee was hired by the attacker.
The Hacker News
