Artificial Intelligence Finance News

AI Agents in Finance Can Be Hijacked, ClawSecure Finds

AI Agents in Finance Can Be Hijacked, ClawSecure Finds

ClawSecure found the cheap worker tier one major lab markets for real-time financial monitoring obeyed hidden attacker commands 91.7% of the time.

AI agents in finance can be hijacked through ordinary content, an email, a shared document or a support ticket, to steal credentials, drain financial accounts, and exfiltrate private data without the victim ever making a mistake, according to The AI Agent Threat Report from ClawSecure. ClawSecure released the report in two volumes on September 24, 2026, drawing on research conducted from May through July 2026. Its findings speak directly to anyone evaluating AI agents for finance.

AI agents are already running finances, businesses, and critical systems, and every one of them can be hijacked by the content it reads”

— J.D. Salbego, Founder and CEO of ClawSecure

For AI agents in finance, the report’s most specific findings concern a worker model and the manager model placed above it. ClawSecure found that the cheap worker tier one major lab markets for real-time financial monitoring obeyed hidden attacker commands 91.7% of the time (11 of 12). The problem did not end at the worker. ClawSecure found that the manager model on top of that worker passed the poisoned result straight through on all 4 of 4 scenarios (100%).

Read More on Fintech : Global FinTech Interview: AI and the future of fintech with Hugh Cumming, CTO, Vena

ClawSecure found that, in one payload, the worker model did the attacker’s extra work for free, encoding the victim’s data into the exfiltration link itself, unprompted. According to ClawSecure’s research, a hijacked agent can drain credentials and API keys and pull financial data along with customers’ private records, and it can leave the user looking at a clean screen that says everything is fine, the entire time. ClawSecure has examined credential theft by hijacked AI agents in a separate article on its blog.

“AI agents are already running finances, businesses, and critical systems, and every one of them can be hijacked by the content it reads,” said J.D. Salbego, Founder and CEO of ClawSecure.

For finance teams asking whether an AI agent can be tricked into moving money, ClawSecure’s research shows a hijacked agent can move money, open accounts, and act as its user across every connected tool. The same access that makes an agent useful to a finance team is what an attacker gets when the agent is hijacked. Nobody on staff has to click the wrong thing for that to happen. Companies weighing AI agents in finance can read ClawSecure’s analysis of the security risks when AI agents transact. ClawSecure tested all models at the versions current at the time of the research; several have since been superseded, and no lab has claimed to have solved prompt injection. The full report is free to download from ClawSecure’s official release page. Every company named received coordinated disclosure before publication.

Catch more Fintech Insights : Global FinTech Innovations Are Transforming Banking into Continuous Financial Guidance

[To share your insights with us, please write to psen@itechseries.com ]

Related posts

Riparian Capital Partners Secures $54.7 Million In Financing Two Single-Family Rental Portfolios in Baltimore

Fintech News Desk

Great Bay Insurance Selects Sapiens for Its Cloud-Based Transformation Project for Reinsurance and Financial Management

Fintech News Desk

Allianz Life Launches Fixed Index Annuity Content on Interactive Tool

Cision PRWeb
1