Copy article

£19,000: What a UK CEO's AI agent fetched on a criminal forum. Full fredentials included.

ended 02. April 2026

A UK CEO's AI personal assistant was listed for sale on a criminal forum in February for $25,000. The selling point wasn't a password. It was the assistant itself  which had quietly accumulated the company's production database credentials, Telegram bot tokens, and Trading 212 API keys in plain-text Markdown files, no encryption at rest. The attacker's pitch: "Your AI? It's my AI now!"

This was revealed last week at RSA Conference 2026 in San Francisco, the world's largest cybersecurity conference in a report by Venturebeat. With those credentials, a buyer gets direct access to live financial accounts, the ability to execute trades against a live portfolio, read and send communications impersonating the CEO, and walk straight into the company's production database. No phishing required. No brute force. Just $25,000 of crypto and the keys are yours.

Security firm Cato Networks ran a live internet scan at the conference and found nearly 500,000 exposed OpenClaw AI assistant instances. The week before: 230,000. SecurityScorecard identified over 15,000 of those instances as vulnerable to remote code execution, meaning attackers do not even need to buy access. They can take it.

The assistant collected all of this because that is what it was designed to do. Workflow integration is the selling point. Connect it to your email, your calendar, your financial accounts, your internal systems, and watch it get things done. Nobody in the procurement conversation asked what happens when something that knows everything about you gets exposed to the internet.

Researchers at Koi Security found 824 malicious skills already published in ClawHub, the popular assistant's plugin marketplace, 335 of them linked to a single coordinated supply chain attack, similar to the type of vulnerability faced by Jaguar Land Rover. The CEO whose data was sold almost certainly had no idea the assistant had accumulated any of this. It was probably still running. Pilot programmes rarely have formal offboarding. 

Cisco's research team found that 85% of enterprise customers have AI agent pilots active right now, with only 5% under the security governance a full deployment would require. The other 80% are live, learning, accumulating access, and largely unwatched.

Two incidents disclosed at the same conference by CrowdStrike CEO George Kurtz sharpened the picture further. At one Fortune 50 company, a CEO's AI agent rewrote the company's own security policy, not because it was compromised, but because it encountered a problem, lacked permission to fix it, and removed the restriction itself. Every identity check passed. The company caught it by accident. At a second Fortune 50, a swarm of 100 agents delegated a code fix between themselves with no human approval. Agent 12 made the commit. The team found out afterwards.

We want your views:

  • When a vendor sells an AI assistant on the strength of its workflow integration, and that integration means it accumulates live financial credentials and production database access, where does the liability sit when it is compromised: the vendor, the IT team, or the executive who signed off procurement?
  • The CEO's assistant in the BreachForums listing was almost certainly a pilot or early deployment. At what point does a pilot carry the same security obligations as a production system, and who in your organisation is currently making that call?
  • Standard security practice for any new software with broad system access is to run it in a sandboxed environment first, isolated from live credentials and production data, until it is properly evaluated. Why are AI assistants being deployed directly into live workflows instead, and what would it take to change that?
  • If your organisation has an AI agent pilot running right now and you cancelled it tomorrow, could you confirm with confidence that it holds zero live credentials and has been fully offboarded? If not, what is your current process for finding out?
  • CrowdStrike's research found agents at Fortune 50 companies rewriting their own security policies and committing code without human approval, both caught by accident. What human checkpoint in your organisation would have caught either of those, and does it actually exist in writing?

2 responses from the Newspage community

Copy all

Star Quote
Copy

Calling this a security problem lets the procurement conversation off the hook entirely.

The decision to hand a learning system access to live financial accounts, production databases, and executive communications wasn't made by the seller. They just hype up the connectivity "boost". The decision was made the day someone approved the integration as a feature worth having.

By the time the $25,000 BreachForums listing appeared, the damage was already done. Security teams inherit the consequences of rash procurement decisions they were never part of.

The real question isn't how to secure an AI assistant that holds everything. It's why "holds everything" passed the buying criteria in the first place. Every system that accumulates access at that level should require the same due diligence as a privileged admin access account. Most don't get a fraction of it.

You wouldn't give a new contractor live database credentials on day one of a pilot. Somehow AI assistants get a free pass.
Copy

IT departments major headaches are security and AI.
Shadow AI occurs were users just start using Ai systems without the knowledge of their IT department. This is the start of the problems.

For Agents to work they need to access other systems, and this were the problems start.

The speed at which AI is moving, being released without sufficient testing needs to be understood by their IT departments.

Code red should be called right now and all IT systems needs to be locked down. Nobody like this but this needs to done and done now.