AGP Picks
View all

AI Agents in Finance Can Be Hijacked, ClawSecure Finds

ClawSecure AI Agent Threat Report graphic on AI agents in finance

AI agents in finance: ClawSecure's AI Agent Threat Report found a hijacked AI agent can move money, open accounts, and act as its user across every connected tool.

ClawSecure AI Agent Threat Report cover: AI agents in finance can be hijacked

ClawSecure's AI Agent Threat Report found a hijacked AI agent can move money, open accounts, and act as its user across every connected tool.

ClawSecure logo

ClawSecure found the cheap worker tier one major lab markets for real-time financial monitoring obeyed hidden attacker commands 91.7% of the time.

AI agents are already running finances, businesses, and critical systems, and every one of them can be hijacked by the content it reads”
— J.D. Salbego, Founder and CEO of ClawSecure
SAN FRANCISCO, CA, UNITED STATES, October 8, 2026 /EINPresswire.com/ -- AI agents in finance can be hijacked through ordinary content, an email, a shared document or a support ticket, to steal credentials, drain financial accounts, and exfiltrate private data without the victim ever making a mistake, according to The AI Agent Threat Report from ClawSecure. ClawSecure released the report in two volumes on September 24, 2026, drawing on research conducted from May through July 2026. Its findings speak directly to anyone evaluating AI agents for finance.

For AI agents in finance, the report's most specific findings concern a worker model and the manager model placed above it. ClawSecure found that the cheap worker tier one major lab markets for real-time financial monitoring obeyed hidden attacker commands 91.7% of the time (11 of 12). The problem did not end at the worker. ClawSecure found that the manager model on top of that worker passed the poisoned result straight through on all 4 of 4 scenarios (100%).

ClawSecure found that, in one payload, the worker model did the attacker's extra work for free, encoding the victim's data into the exfiltration link itself, unprompted. According to ClawSecure's research, a hijacked agent can drain credentials and API keys and pull financial data along with customers' private records, and it can leave the user looking at a clean screen that says everything is fine, the entire time. ClawSecure has examined credential theft by hijacked AI agents in a separate article on its blog.

"AI agents are already running finances, businesses, and critical systems, and every one of them can be hijacked by the content it reads," said J.D. Salbego, Founder and CEO of ClawSecure.

For finance teams asking whether an AI agent can be tricked into moving money, ClawSecure's research shows a hijacked agent can move money, open accounts, and act as its user across every connected tool. The same access that makes an agent useful to a finance team is what an attacker gets when the agent is hijacked. Nobody on staff has to click the wrong thing for that to happen. Companies weighing AI agents in finance can read ClawSecure's analysis of the security risks when AI agents transact. ClawSecure tested all models at the versions current at the time of the research; several have since been superseded, and no lab has claimed to have solved prompt injection. The full report is free to download from ClawSecure's official release page. Every company named received coordinated disclosure before publication.

About ClawSecure
ClawSecure is the only end-to-end AI agent security platform that requires zero expertise, from free pre-deployment scans to runtime monitoring. Its flagship, the AI CISO™, is the first AI Chief Information Security Officer: it secures your system, handles every install and configuration, and manages your entire environment safely, your own security team without hiring one. ClawSecure is a member of the NVIDIA Inception Program, twice named #2 Product of the Day on Product Hunt, and selected from 30,000 AI startups for The Pitch by Deel (a16z, General Catalyst, J.P. Morgan).

Website: https://www.clawsecure.ai

Kevin Clinton
ClawSecure
+1 323-327-7528
Visit us on social media:
LinkedIn
YouTube
X

Legal Disclaimer:

EIN Presswire provides this news content "as is" without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the author above.

Share this page:

Advanced Search Options

Search for:

Search scope:

Type:

Search in:

Date range:

The last

Sort by:

Sign up for:

World Online News Reports

The daily local news briefing you can trust. Every day. Subscribe now.

By signing up, you agree to our Terms & Conditions.