Threat Intelligence

New AI Attack Technique Hijacks Enterprise Workflows Without Credentials

Dark Reading · 10 Sept 2026
Key Takeaway Review any AI-powered or automated workflow tools your business uses to ensure every entry point requires proper authentication, not just the ones handling obvious logins.

Security researchers have identified a new attack technique dubbed 'workflow identity hijacking' that targets AI-driven business systems. Rather than stealing passwords or breaking encryption, the method exploits how automated workflows handle identity and trust, allowing an attacker to send a basic request through an unauthenticated entry point and gain access to sensitive organisational data.

This approach is concerning because it can bypass standard security controls that businesses rely on, such as authentication checks, since the attack does not require valid credentials to succeed. As more small and medium businesses adopt AI tools and automated workflows to handle customer data, invoicing, and internal processes, this type of identity-based weakness becomes a growing risk.

While full technical details are still emerging, the core issue highlights a broader trend: attackers are increasingly targeting the trust relationships between systems and AI tools rather than traditional user accounts.

AI security identity security enterprise data workflow automation
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.