{"id":10091,"date":"2025-12-25T00:55:25","date_gmt":"2025-12-25T00:55:25","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=10091"},"modified":"2025-12-25T00:55:25","modified_gmt":"2025-12-25T00:55:25","slug":"eurostar-accused-researchers-of-blackmail-for-reporting-ai-chatbot-flaws-hackread-cybersecurity-information-information-breaches-ai-and-extra","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=10091","title":{"rendered":"Eurostar Accused Researchers of Blackmail for Reporting AI Chatbot Flaws \u2013 Hackread \u2013 Cybersecurity Information, Information Breaches, AI, and Extra"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>The push so as to add AI to customer support, which we now have been witnessing these days in virtually each sector, can typically come at a excessive worth for safety. On December 22, 2025, the crew of moral hackers at <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/gumtree-exposed-gps-location-users-source-code\/\" target=\"_blank\" rel=\"noreferrer noopener\">Pen Take a look at Companions (PTP)<\/a> went public with a sequence of flaws they discovered within the new AI chatbot for Eurostar.<\/p>\n<p>In your info, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eurostar.com\/rw-en\" data-type=\"link\" data-id=\"https:\/\/www.eurostar.com\/rw-en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Eurostar<\/a> is the well-known high-speed rail operator that connects the UK to mainland Europe via the Channel Tunnel, carrying thousands and thousands of travellers between main hubs like London, Paris, and Amsterdam.<\/p>\n<h3 id=\"how-the-flaws-were-discovered\" class=\"wp-block-heading\"><strong>How The Flaws Have been Found<\/strong><\/h3>\n<p>What began as a researcher planning a easy practice journey from London was the invention of \u201cweak guardrails\u201d that left the system open to manipulation. In your info, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/openai-guardrails-bypass-prompt-injection-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">guardrails<\/a> are the digital \u201csecurity brakes\u201d that cease an AI from going off-topic or leaking secrets and techniques.<\/p>\n<p>In response to PTP researchers, Eurostar\u2019s bot had a significant design flaw; it solely checked the final message in a chat for security. By merely enhancing earlier messages within the dialog on their very own display screen, the researchers discovered they might trick the AI into ignoring its personal guidelines.<\/p>\n<p>The technical aspect of the \u201chack\u201d was surprisingly easy. As soon as the protection checks have been bypassed, the researchers used <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/promptpwnd-vulnerabilit-ai-systems-data-theft\/\" target=\"_blank\" rel=\"noreferrer noopener\">immediate injection<\/a> to make the bot reveal its inside directions and the kind of AI mannequin it was utilizing.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails.png\"><img loading=\"lazy\" decoding=\"async\" width=\"600\" height=\"901\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails.png\" alt=\"\" class=\"wp-image-138984\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails.png 600w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails-200x300.png 200w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails-380x571.png 380w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\"\/><\/a><figcaption class=\"wp-element-caption\">Eurostar AI Chatbot Revealing Mannequin (supply: Pen Take a look at Companions)<\/figcaption><\/figure>\n<\/div>\n<p>Additional probing revealed two different important points. First, the chatbot was weak to HTML injection and might be compelled to show malicious code or pretend hyperlinks immediately within the person\u2019s chat window. Secondly, dialog and message IDs weren&#8217;t verified.<\/p>\n<p>This implies the system didn\u2019t correctly examine if a chat session really belonged to the person, probably permitting an attacker to \u201creplay\u201d or inject malicious content material into another person\u2019s dialog.<\/p>\n<h3 id=\"fixing-the-flaws\" class=\"wp-block-heading\"><strong>Fixing the Flaws <\/strong><\/h3>\n<p>This <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.pentestpartners.com\/security-blog\/eurostar-ai-vulnerability-when-a-chatbot-goes-off-the-rails\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">analysis<\/a>, which was shared with Hackread.com, reveals that discovering the vulnerabilities was really simpler than getting them mounted. The crew first alerted Eurostar on June 11, 2025, however there was no response. Lastly, after a month of chasing, they tracked down Eurostar\u2019s Head of Safety on LinkedIn on July 7.<\/p>\n<p>Researchers later realized that Eurostar had apparently outsourced their safety reporting course of proper when the bugs have been reported, main them to assert they&#8217;d \u201cno report\u201d of the warnings. <\/p>\n<p>At one level, the rail operator even accused PTP\u2019s safety crew of \u201cblackmail\u201d only for attempting to flag the problems. The accusation got here regardless of the corporate having a publicly accessible vulnerability disclosure program out there <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.eurostar.com\/uk-en\/responsible-disclosure\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">right here<\/a>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full\"><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails-1.png\"><img loading=\"lazy\" decoding=\"async\" width=\"903\" height=\"303\" src=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails-1.png\" alt=\"\" class=\"wp-image-138985\" srcset=\"https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails-1.png 903w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails-1-300x101.png 300w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails-1-768x258.png 768w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails-1-380x128.png 380w, https:\/\/hackread.com\/wp-content\/uploads\/2025\/12\/Eurostar-AI-Chatbot-Found-With-Major-Security-Flaws-and-Weak-Guardrails-1-800x268.png 800w\" sizes=\"auto, (max-width: 903px) 100vw, 903px\"\/><\/a><figcaption class=\"wp-element-caption\">(Supply: Pen Take a look at Companions)<\/figcaption><\/figure>\n<\/div>\n<p>\u201cWe had disclosed a vulnerability in good religion,\u201d the researchers famous, expressing their shock on the hostile response.<\/p>\n<p>Whereas the issues have now been patched, the crew warned that this must be a wake-up name for giant manufacturers. Simply because a instrument is AI-powered doesn\u2019t imply the outdated guidelines of net safety don\u2019t apply, and if the backend isn\u2019t stable, the flamboyant AI options are little greater than \u201ctheatre.\u201d<\/p>\n<p>\n\t\t\t<\/div>\n<p><template id="fA9JoXAmg8JQpvFyQ8YY"></template><\/script><br \/>\n<br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The push so as to add AI to customer support, which we now have been witnessing these days in virtually each sector, can typically come at a excessive worth for safety. On December 22, 2025, the crew of moral hackers at Pen Take a look at Companions (PTP) went public with a sequence of flaws [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":10093,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[1815,4747,5449,3121,361,157,7100,1812,6013,121,6948,2470],"class_list":["post-10091","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-accused","tag-blackmail","tag-breaches","tag-chatbot","tag-cybersecurity","tag-data","tag-eurostar","tag-flaws","tag-hackread","tag-news","tag-reporting","tag-researchers"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10091","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=10091"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10091\/revisions"}],"predecessor-version":[{"id":10092,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/10091\/revisions\/10092"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/10093"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=10091"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=10091"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=10091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-13 15:22:24 UTC -->