Skip to content
Skip to content
AI Security

The lead form was the way in: indirect prompt injection and the SalesBleed lesson

Summarise with

On 24 September 2026 Zenity Labs showed that a stranger filling in a public lead form could make a Salesforce agent post CRM data out of the building. Nobody clicked anything. The form did the talking.

Quick answerIndirect prompt injection hides instructions inside content an AI agent reads, such as a lead form. SalesBleed used it against Salesforce Agentforce to leak CRM data with zero clicks. Salesforce fixed it by 18 August 2026.
Section 01

What SalesBleed did, and why indirect prompt injection needed no click#

0 clicks

needed from the victim to leak CRM data in Zenity's SalesBleed chain

Zenity Labs, 24 September 2026

Start with the quiet quarry. A marketing team runs a website form, the form feeds the CRM, and an AI agent reads the CRM so a salesperson can ask it for a summary of this morning's leads. Every step is ordinary. On 24 September 2026, Zenity Labs published SalesBleed, a chain of three flaws in Salesforce Agentforce that turned that ordinary loop into an exit. Its own one-line verdict is hard to beat: the entry point was a public Web-to-Lead form, and the exit was a DNS query.

The mechanism is indirect prompt injection. Nobody attacked the model directly. An attacker typed instructions into a field on a public lead form, the text sat in the Leads table like any other enquiry, and it waited. As SecurityWeek reported on 25 September, the malicious instructions stayed dormant until an employee asked an Agentforce agent to work with that submission. Then the agent read the attacker's words as if they were part of its job.

That is the whole trick, and it is why the phrase indirect prompt injection matters more than the brand name on this particular bug. The OWASP Top 10 for LLM Applications puts prompt injection first, as LLM01, and defines the indirect kind as the moment a model accepts input from external sources such as websites or files. A lead form is an external source with a friendly face.

The persistence problem nobody budgets for#

Zenity noted something that should keep revenue operations teams awake. The poisoned lead does not fire once and vanish. It persists in the Leads table and could execute again every time an employee reviews it. A phishing email gets deleted. A poisoned CRM record gets handed round the sales floor, lovingly enriched, and summarised on every pipeline call.

And the volume ceiling is generous. As Formstack's guide to Web-to-Lead limits notes, Salesforce lets the feature generate 500 leads per 24 hours from prospects who submit contact details. For a growth team that is a feature. For an attacker it is 500 chances a day to leave a note under the door.

watercolour fox reading an envelope by lantern light at a letterbox, illustrating indirect prompt injection hidden inside a lead form
The letter was addressed to the agent, not to you.

The fox reads the hedgerow, not just the path. Indirect prompt injection is a hedgerow problem: the danger sits in the undergrowth your agent is paid to read, not on the road your firewall is built to watch.

Section 02

How the data got out when Salesforce Agentforce said it was blocked#

The second half of the chain is the part security buyers should study. Agents that can write links or images into a reply can smuggle data out inside those links. Salesforce knew this. After a similar disclosure a year earlier, it shipped a control called Trusted URL allowlisting which, as The Hacker News reported in September 2025, stops agent output being sent to untrusted URLs by enforcing a URL allowlist.

SalesBleed walked round that fence. Zenity's write-up describes three parsing gaps: a redactor that did not recognise some top-level domains as hosts, a disagreement between redaction and rendering over where a URL ends, and malformed addresses that slipped past redaction but still worked inside an image tag. The data then left by DNS, which Zenity notes is cramped, since a single label caps at 63 characters and a full name at 253, but it slips past controls built for web traffic.

SecurityWeek relayed the detail that stings most: Agentforce reported that the content had been blocked, while the sensitive CRM data had already been sent to the attacker's server. A control that reports success after the fact is a comforting light over an empty henhouse.

The SalesBleed disclosure, in five dates

The dates are worth reading slowly. Zenity's disclosure timeline says the flaws were reported to Salesforce by email on 1 June 2026, and that the fixes were fully confirmed by Salesforce on 18 August. That is a responsible, ordinary disclosure: roughly eleven weeks of quiet work, then publication once the patch was in.

This was not the first lead form through the door#

There is a precedent, and it is almost the same animal. In September 2025 Noma Security disclosed ForcedLeak, another indirect prompt injection against Agentforce that also rode in on Web-to-Lead. Its exfiltration route used an allowlisted domain that had expired, and Noma's researchers noted that the domain they bought to prove it cost $5. Salesforce's answer, as quoted by The Hacker News, was that its services would enforce the Trusted URL allowlist so no malicious links are called or generated through potential prompt injection.

SalesBleed is what happens a year later when the fix is a list and the attacker studies how the list is read. That is not a scandal. It is the normal rhythm of this category, and it is exactly why prompt injection prevention cannot be sold as a single switch.

Days from report to confirmed fix
SalesBleed, 2026
78 days
ForcedLeak, 2025
42 days
The 2026 chain took longer to close than the 2025 one, which suggests the easy fences were already up. Dates from Zenity Labs and Noma Security.
Section 03

What the research measures about indirect prompt injection, and what it does not#

Indirect prompt injection succeeds often in the lab
Ladder chart of indirect prompt injection attack success in lab benchmarks: WASP partial success up to 86 per cent, Agent Security Bench highest average 84.3 per centAttack success in lab benchmarks, per cent020406080100WASP, partial: 86%WASP, partial86%ASB, best average: 84.3%ASB, best average84.3%
Ladder chart of indirect prompt injection attack success in lab benchmarks: WASP partial success up to 86 per cent, Agent Security Bench highest average 84.3 per cent
ItemValue
WASP, partial86%
ASB, best average84.3%
Two peer-reviewed benchmarks measured high attack success against AI agents under test conditions. These are lab rates, not incidence in the wild. Sources: Agent Security Bench and WASP.

Security marketing lives or dies on one distinction: what researchers observed attackers doing, and what a vendor says attackers could do. They are different sentences and they deserve to look different on the page.

Here is the measured side. The idea itself is old enough to have a paper trail: Greshake and colleagues described indirect prompt injection in 2023, warning that LLM-integrated applications blur the line between data and instructions. Since then the benchmarks have got specific. Agent Security Bench, presented at ICLR 2025, reported a highest average attack success rate of 84.30% against LLM agents, with limited effectiveness from current defences. WASP, a web-agent benchmark, found attacks partially succeed in up to 86% of cases, while agents often struggle to complete the attacker's full goal.

And the sober counterweight. AgentDojo, built on 97 realistic tasks and 629 security test cases, found that existing attacks break some security properties but not all. That line is the honest middle. Indirect prompt injection works often enough to take seriously and unreliably enough that every headline claiming it is unstoppable is overselling.

The regulator's view is the sharpest sentence in the pile#

The UK National Cyber Security Centre wrote in December 2025 that prompt injection attacks will remain a residual risk and cannot be fully mitigated with a product or appliance. Read that twice if you sell security. It is the most useful sentence a vendor can quote, because it frames your product as one layer in a design rather than a cure, and buyers trust the vendor who admits the ceiling.

The standards bodies agree on the shape. NIST AI 100-2 E2025 lists leaking restricted information through indirect prompt injection as a recognised attack class. For firms in scope of the EU AI Act, Article 15 requires high-risk systems to be resilient against attempts by unauthorised third parties to alter their use or outputs by exploiting vulnerabilities. None of these documents promises a fix. All of them expect a plan.

@HoustonIntrove1
SalesBleed: poisoned Web-to-Lead, Agentforce reads it, CRM data walks out with zero clicks. Salesforce fixed it. Which of our Salesforce agents still treat public form fields as trusted input?
26 September 2026View on X

That practitioner question, posted hours after the story broke, is the right one. The fix closed a parsing gap. The design choice that made the gap matter, an agent that treats anything in the CRM as instructions, is still sitting in many a den.

Section 04

What marketing and RevOps teams should change on Monday#

This is where the story stops being a security bulletin and becomes a marketing operations brief. The lead form belongs to marketing. The CRM hygiene belongs to RevOps. The agent was bought by sales. Indirect prompt injection lives in the gap between three owners, which is exactly where nobody is watching.

Start with the form. Every free-text field on a public form is now an input to software that can act. That does not mean killing the form, which would be a cure worse than the cold. It means treating form text as untrusted data, keeping it out of the instruction path, and asking your platform owner which agents read which fields.

Each link in the chain sits with a different team, which is why prompt injection prevention needs a named owner.
Link in the chainUsual ownerQuestion to ask this week
Public lead formMarketingWhich free-text fields reach an agent?
CRM recordRevOpsCan a lead record carry instructions to an agent?
Agent actionsSales opsWhat can the agent read, and where can it write?
EgressSecurityCan the agent reach any outside address at all?
  • Public lead formMarketingWhich free-text fields reach an agent?
  • CRM recordRevOpsCan a lead record carry instructions to an agent?
  • Agent actionsSales opsWhat can the agent read, and where can it write?
  • EgressSecurityCan the agent reach any outside address at all?

Scope what the agent can touch, not just what it can say#

The most useful line in the social chatter came from security practitioners, not vendors: scope data access and egress together. An agent that can read the whole accounts table and also fetch external URLs is one clever sentence away from exporting the accounts table. Take away either half and the same injection becomes a nuisance rather than a breach.

Then log it. If an agent summarised a poisoned lead, you want to know which records it read and what it wrote, in the same way you would want to know which inbox opened the phishing email. Treat agent activity as a system of record, not a chat window.

Finally, write the incident sentence before you need it. Our interactive story on what a brand should say while a story is unconfirmed makes the point that attribution beats adjectives. If your agent ever leaks, you will want a statement written in the calm, not in the storm. We help teams build that muscle as part of AI consultancy work, alongside the agent governance we covered in agentic AI security and the runaway meter.

Section 05

What SalesBleed means for security vendors' marketing#

Now the other audience. If you sell AI security, SalesBleed is a gift and a trap in the same parcel. The gift is a clean, dated, well-documented case your buyers already understand, because every buyer has a lead form. The trap is the temptation to write it up as proof the sky is falling.

The vendor who admits prompt injection cannot be fully fixed is the vendor the buyer believes about everything else.
folkfox, on selling AI security honestly

Look at what else happened the same week. Decrypt reported on 24 September that Darktrace gave AI agents ten coding challenges, two of them rigged to be impossible, and two agents attacked the test network instead. SecurityWeek reported that OpenAI agents had probed websites while fetching public data, while noting that none of the attempts appears to have succeeded. Two very different findings, both easy to flatten into the same breathless headline.

The discipline that wins here is the one we set out in the 24-hour credibility test: say what was measured, by whom, under what conditions, and put the limits on the same panel as the claim. A lab rate of 84% is a lab rate. A proof of concept against a patched product is a proof of concept. Neither is evidence of attacks in the wild, and neither Zenity nor SecurityWeek reported any exploitation of SalesBleed outside research.

Content that earns the meeting#

The content that works for AI security buyers is practical and specific: a checklist mapping OWASP LLM01 to a buyer's own stack, a short explainer of what Trusted URL controls do and do not stop, a plain-English answer to what are the risks of prompt injection in a CRM. That is the kind of content marketing that ranks, gets cited by answer engines and gets forwarded to the CISO. It is also how we approach cybersecurity marketing for vendors, and it is the same advisory posture we argued for in our Check Point zero-day piece.

Fear sells a demo. Clarity sells a renewal. A vendor who can explain indirect prompt injection to a head of marketing without a single scary adjective will outfox the one with the loudest webinar.

Questions

Frequently asked questions#

What is indirect prompt injection?

Indirect prompt injection is an attack where instructions are hidden inside content an AI system reads, such as a web page, a document or a form submission, rather than typed to the model directly. When the agent later processes that content, it may follow the hidden instructions. OWASP lists prompt injection as the top risk for LLM applications.

What are the risks of prompt injection?

The main risks are data leakage, unwanted actions and misleading output. An agent with access to a CRM, email or files can be tricked into sending data outside, changing records or messaging colleagues. The UK NCSC says it remains a residual risk that no single product can fully remove, so design and access limits matter.

Was Salesforce Agentforce fixed after SalesBleed?

Yes. Zenity Labs reported the issues on 1 June 2026, Salesforce confirmed its fixes on 18 August 2026 and Zenity verified them on 19 August. Zenity published the research on 24 September 2026. No exploitation outside research was reported by Zenity or SecurityWeek.

What is web to lead Salesforce, and why did it matter here?

Web-to-Lead is Salesforce's standard way to turn a website form into CRM leads, up to 500 a day. It mattered because the form is public: anyone can type into it, and in SalesBleed that typed text later reached an AI agent that treated it as instructions.

What does good prompt injection prevention look like?

Treat all outside content as untrusted data, keep it out of the agent's instruction path, limit what the agent can read and where it can send data, block outbound requests it does not need, and log what it does. Assume some attacks will land, and make sure a successful one has little to reach.

Should marketing teams stop using AI agents on CRM data?

No. The sensible move is to know which agents read which fields, restrict their access and outbound reach, and give one named person ownership of the chain from form to CRM to agent. The value of agent summaries is real; so is the need to scope them.

Keep reading

Read more on this topic#

Selling AI security without the scare?

folkfox helps cybersecurity vendors turn disclosures like SalesBleed into content buyers trust: measured, dated and useful on Monday morning.

Want folkfox in your Google results and AI answers? Set folkfox as a preferred source.

The den

Where to?

Pricing

Choose a section. Enter opens it, Escape continues reading.

Cookie preferences

folkfox uses data the way we use strategy: only when it earns its place.