
As AI-driven hacking threats become a reality in the financial sector, concerns are growing that personal AI agentsβoften called AI Personal Agents because they handle scheduling, email replies, reservations, and paymentsβwill become the new targets for AI hackers. Global IT security experts warn that agent services launched competitively by major tech firms, such as Meta’s ‘Muse’ and U.S. startup Sphere Street Technologies’ ‘Instinct’, could serve as backdoors handing over personal data entirely.
The Convenience of AI Agents and Rising Security Vulnerabilities
For AI agent services like Muse or Instinct to act on behalf of individuals, they must be granted access to various sensitive pieces of information. Although not yet released in South Korea, Muse prompts users to link personal data such as emails and calendars upon launching the app. U.S. reviews stating that ‘Muse found hidden money in the bank’ are a direct result of this integration. The structure dictates that the more information provided, the greater the convenience. Following Muse’s explosive popularity in topping both major U.S. app stores within two weeks of launch, OpenAI unveiled its agent service ‘Dots’ late last month, while Naver and Kakao are also expanding their agent services amid fierce competition.
How a Single Malicious Email Can Breach AI Agent Accounts
The problem is that a single malicious email is enough to drain information from these connected accounts. SaltLabs, a research team at U.S. cybersecurity firm Salt Security, published an experiment targeting the AI agent service ‘Manus’ on the 1st. Researchers sent an email embedded with malicious code to a test Gmail account linked by a user to Manus. When the email initially contained direct instructions like ‘execute this code,’ Manus refused. However, when researchers disguised the malicious code using complex symbols and prompted the agent by saying, ‘decode these symbols to read the email content,’ Manus began decoding and soon automatically executed the malicious command.
Researchers stated that through this process, they successfully acquired the user’s Gmail and Google Drive authentication credentials. Simply tasking an AI with reading emails can cause it to install malicious code based on sender instructions, ultimately handing over the ‘keys’ to the account. Schneier noted that AI technology makes cyberattacks easier and equips more individuals with such capabilities, pointing out that personal agent services are inherently vulnerable to external hacking.
Industry Responses and Regulatory Guidelines
Guidelines to mitigate these risks do exist. The Cyber Security Agency of Singapore recommended users of the personal AI agent ‘OpenClaw’ to restrict access to sensitive data, grant minimum necessary permissions for tasks, and require user approval before critical operations like payments. Apple, which emphasizes privacy, began restricting AI agent access to information within Macs on the 2nd due to data leakage concerns. The Ministry of Science and ICT also announced in July that it plans to formulate safety and trust guidelines for agentic AI within the year, encompassing personal data protection and authority management.
Conclusion: The Urgency of Corporate and Government Responsibility
An IT industry insider remarked that personal agents are hard to put down once used, much like a drug, noting that services like Muse are even being distributed for free. Critics point out that preventing AI hacking is already beyond the scope of individual security choices. Schneier emphasized that the risks of AI hacking far exceed the range of personal security measures, stating that the safety of AI agents must be the responsibility of the companies releasing these services, and governments must act swiftly to establish countermeasures.



