GhostJacking: How Attackers Hijack AI Agents via Security Alerts
A newly published attack technique dubbed "GhostJacking" is exposing critical identity governance weaknesses in AI agent deployments, according to research cited by Dark Reading. The technique demonstrates how adversaries can weaponize routine security alerts and blocked events—typically considered noise in enterprise SOC environments—to manipulate and ultimately hijack autonomous AI agents acting on behalf of users and organizations.
The research highlights a fundamental blind spot in how identity and access management (IAM) frameworks handle AI agent personas. Because AI agents frequently process security telemetry to make decisions about user actions, attackers can craft poisoned alert streams that alter the agent's behavior. When an AI agent encounters a blocked event, for example, it may interpret the block as a policy signal and proceed through alternative paths—essentially following attacker-supplied logic while appearing legitimate to monitoring tools. Security teams can run a email breach checker to verify whether compromised credentials might be fueling unauthorized agent activity, and a browser fingerprint test to detect anomalous session characteristics associated with hijacked agent sessions.
Researchers warn that GhostJacking is particularly dangerous in environments where AI agents operate with broad delegated permissions across SaaS platforms, ticketing systems, and cloud infrastructure. Once an agent is compromised, attackers can exfiltrate data, escalate privileges, or pivot laterally—often without triggering traditional identity-based detection rules. The attack underscores the urgency of implementing granular least-privilege controls, behavioral baselining for AI agent activity, and strict verification of the alert sources that agents consume. Organizations should also assess their network exposure using a port scanner to identify any AI agent endpoints that may be inadvertently reachable from the public internet.
Identity governance vendors and AI security teams are now being urged to treat AI agent personas as first-class identities requiring the same lifecycle management, monitoring, and threat modeling applied to human users. As autonomous agents become more prevalent in enterprise workflows, GhostJacking represents a new class of identity-centric AI threat that demands immediate attention from CISOs and security architects.