SalesBleed: Poisoned Leads Trigger Slack Phish

Security Week Feed · High sophistication
Last updated September 25, 2026

Researchers say three “SalesBleed” flaws in Salesforce Agentforce could let attackers plant malicious instructions inside a Web-to-Lead form submission that later causes an Agentforce agent to leak CRM data or post phishing in Slack. The attack can stay hidden until an employee asks Agentforce to interact with the poisoned lead, at which point data can be exfiltrated “zero-click” using crafted URLs or image tags, or used to send trusted-looking Slack messages.

Key findings

  • The flaws could be triggered through Salesforce Web-to-Lead forms by injecting malicious instructions into a lead submission.
  • The malicious content can remain dormant until an employee prompts an Agentforce agent to interact with the poisoned lead.
  • Two issues could enable “zero-click” CRM data exfiltration (including via HTML image tags and URL parsing weaknesses).
  • A separate issue in the Agentforce-Slack integration could allow attackers to use the agent to distribute phishing messages into internal Slack channels.
  • Slack link previews could be abused so that “as soon as the links appear,” Slack initiates requests that carry CRM data to attacker infrastructure.
  • Salesforce fixed the reported issues after Zenity disclosed them (reported June 1; addressed by August 19).

Who’s being targeted

  • Commonly targeted roles: Sales, Sales Operations / RevOps, Customer Success, CRM/Application Administrators, All Slack users, IT/Security teams managing SaaS integrations.
  • Affected industries: Any organization using Salesforce Agentforce, Any organization using Salesforce + Slack integrations, Sales/CRM teams, Customer service/operations teams.
  • Attack channels: email, slack.
  • Impersonated: Prospective customer lead (via official Web-to-Lead submission), Salesforce Agentforce agent (trusted internal automation).

Awareness takeaways

  • Treat internal-system messages (including AI agents) as untrusted until verified, especially when they contain links or ask for logins.
  • Train sales/ops teams that inbound “lead” submissions can be weaponized; avoid copy/pasting or asking AI tools to process suspicious lead text/links.
  • Warn Slack users that link previews can leak data; be cautious with unexpected links posted by bots/agents.
  • Encourage rapid reporting of “weird but blocked” security messages, data may already have left even if the UI says content was blocked.

Red flags to watch for

  • Unexpected or oddly formatted content in a lead submission (e.g., suspicious links/HTML-like text)
  • AI agent behavior that doesn’t match the request (e.g., pulling unrelated records)
  • Outbound connections/requests occurring immediately after the agent opens the lead
  • A “trusted system” posts unexpected login/verification links
  • The message does not clearly identify the real requesting user/owner
  • Links that prompt for credentials or unusual access approvals
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine a normal Salesforce lead turning into a Slack phish… without anyone clicking anything. SalesBleed hides malicious instructions inside a Web-to-Lead form. It just sits there until someone asks Agentforce to summarize the lead, then the poisoned text makes Agentforce leak CRM data or post phishing links into Slack. That poisoned lead can make Agentforce post in an internal Slack channel: a trusted-looking bot message with a login link. As soon as the link appears, Slack link previews quietly send CRM data out, before anyone even clicks. If a bot or Agentforce posts an unexpected login or verification link, stop and report it to security, don’t click it, even if it looks like it came from Salesforce.

Categories

Similar attacks

SalesBleed: Hijacked AI Agents for 0‑Click Theft

SalesBleed: Hijacked AI Agents for 0‑Click Theft

Researchers found flaws in Salesforce Agentforce that let attackers plant “poisoned” lead data which the AI agent later processed and used to silently leak CRM data, without any employee click. A related Slack integration flaw could also let attackers send phishing messages that appear to come from…

September 24, 2026
Iranian “Chosen Brick” Lures Sent via Telegram

Iranian “Chosen Brick” Lures Sent via Telegram

UK, US, and Dutch agencies warned that Iranian state-linked actors used social messaging apps to build trust with dissidents, journalists, and activists before sending disguised files that install Windows malware. The attackers often impersonated someone the target already knows or “technical…

September 17, 2026
Phishing Link Could Plant a Rogue ChatGPT Agent

Phishing Link Could Plant a Rogue ChatGPT Agent

Researchers described a now-patched flaw ("AgentForger") where a single benign-looking ChatGPT link could silently create and publish an attacker-controlled Workspace Agent inside a company. If an employee was already logged in and had connected apps (like email, Drive, Slack, or Teams), the agent…

July 24, 2026
Fake Job Lures Push Malware via Terraform Registry

Fake Job Lures Push Malware via Terraform Registry

Researchers reported a real developer-targeting campaign linked to DPRK actors where attackers pose as legitimate recruiters or Web3 companies and trick targets into running code or pulling poisoned dependencies. The operation has now expanded to include malicious Terraform providers hosted in the…

September 23, 2026
Resume Phish Hit Brazil Banks; AI Aided Ops

Resume Phish Hit Brazil Banks; AI Aided Ops

Two real, ongoing intrusion campaigns targeted organizations in Latin America, including a Mexican transportation organization and Brazil’s financial sector. In the Brazil campaign, attackers reportedly got in via a resume-themed phishing attachment, then attempted to download and run tunneling…

September 3, 2026
Attackers Phish via Teams & Slack, Not Email

Attackers Phish via Teams & Slack, Not Email

Research and incident examples show attackers increasingly using trusted collaboration tools (like Microsoft Teams and Slack) to impersonate IT/support or known community members, then push victims to phishing sites, approve MFA prompts, or run malicious files. Because messages come through…

August 20, 2026