FutureScot
Cyber

Cyber and fraud centre launches security testing service to target ‘hidden’ AI chatbot risks

Photograph: Danielala/Shutterstock.com

The Cyber and Fraud Centre – Scotland has launched a new security testing service designed to help organisations spot the ‘hidden’ risks of AI chatbots.

The AI and Web Application Security Assessment tool will identify vulnerabilities introduced by AI-powered chatbots and other AI functionality integrated into websites and web applications.

It will see the centre’s specialist team assess traditional web application vulnerabilities alongside security risks specific to the way AI has been implemented.

As organisations increasingly use AI-powered chatbots and virtual assistants for customer service, online support and access to information, these tools can also create new opportunities for attackers if they are not configured securely.

Recent industry reporting supports the growth of AI chatbots in customer service. Zendesk’s CX research found that 73% of service organisations already run a chatbot, rising to 81% among firms performing well against benchmarks. And Salesforce reports that 30% of service cases are now resolved by AI, with a projection of 50% by 2027.

And high-profile cases have already emerged where chatbots have been exploited. Hackers were able to seize control of some of Instagram’s most prominent accounts in June – by talking Meta’s AI support chatbot into doing it for them.

Anthropic, the creator of the Claude generative AI platform, revealed details of a sophisticated espionage campaign in November, in which attackers used AI’s agentic capabilities not just as an advisor, but to execute the cyberattacks themselves, with the AI executing 80-90% of tactical operations independently.

Thaïs Ramdani, Cyber and Fraud Centre – Scotland’s lead pentester, said: “Organisations are understandably keen to explore what AI can do for their customers and help with efficiencies in teams. But security needs to be part of that conversation.

“Adding an AI assistant to a website isn’t simply adding another customer service tool. Depending on how it’s been configured, the AI assistant could have access to confidential information or documents, which risk being exposed.

“Our team essentially approach the technology from an attacker’s point of view – what can we make it do that it wasn’t intended to do? Finding these weaknesses through controlled testing gives our clients the opportunity to address them before someone else finds them.”

The service combines testing with practical reporting – organisations will receive a breakdown of vulnerabilities identified during testing, their potential business impact and practical recommendations to address them.

Related posts

GDPR in The Times Scotland

Will Peakin
February 22, 2018

‘Special Representative on Internet Safety’ appointed by Prime Minister

Will Peakin
September 11, 2017

New cybersecurity group formed to boost Scotland’s resilience to online threats

Kevin O'Sullivan
February 23, 2021
Exit mobile version