One Bad Prompt Took Down a Company's Salesforce: RSA's Jim

Overview


AI agents are moving into production faster than security teams can track them. They hold credentials, carry entitlements, and act on systems of record, yet most enterprises cannot say which agents are running, who owns them, or whether anyone can stop them. Gartner expects a typical Global Fortune 500 enterprise to run roughly 150,000 AI agents by 2028, up from fewer than 15 in 2025, while only 13% of organizations believe they have the right agent governance in place.


At The AI Conference in San Francisco, RSA announced RSA Agent ID, an agentic identity security platform for regulated industries such as finance, government, healthcare, and critical infrastructure. We sat down with Jim Taylor, President and Chief Product and Strategy Officer at RSA, to dig into how it works.


Why Agents Break the Identity Model


"What changes with agents? Everything. They're not a service account. They're not static. They're dynamic. You give an agent a task, and if you badly word that task, it will do whatever it deems necessary to perform it. Agents don't get tired at two o'clock in the morning. They just go."

Agents also accumulate permissions, data, and access over time, and nobody follows up. "Employees create an agent to hit a deadline, but once it's off in the wild, that's it. We don't check when its permissions change. We don't delete or disable agents."


The scale surprises even regulated firms. A medium-sized global bank told RSA it had no agents, since policy prohibited them. "Agents don't tend to respect policy," Taylor said. "We did an audit and found more than 4,000 agents running around in their enterprise." According to IBM, incidents involving shadow AI cost $670,000 more on average than standard incidents.


When a Prompt Becomes a Denial-of-Service Attack


Taylor's failure scenario involved no attacker at all. A customer success employee at an unnamed company asked an agent to "go to Salesforce and get all the data" to build customer health charts. The agent began downloading the entire Salesforce database. Salesforce's defenses read the traffic as an attack, shut down the instance, and warned the company that it appeared to be under a denial-of-service attack.


"One operator on the customer service desk took the whole company's Salesforce instance down by essentially having an agent perform a denial-of-service attack. He didn't do anything wrong."

The Governance Gap: Agents Need Identity, Ownership, and Kill Switches


The Salesforce incident illustrates a structural problem: agents inherit human entitlements without inheriting human accountability. In most organizations, no one owns an agent after it is deployed. It has no lifecycle, no deprovisioning path, and often no audit trail that maps its actions back to a responsible principal.


RSA Agent ID is designed to close that gap by treating agents as first-class identities. The platform issues each agent a verifiable identity, binds it to an owner, scopes its permissions to the task at hand, and provides the visibility and kill-switch controls needed to shut an agent down when it misbehaves.


For regulated industries, the stakes are higher. Financial services firms face supervisory expectations around model risk and operational resilience. Healthcare organizations must protect PHI under HIPAA. Government and critical infrastructure operators answer to strict access-control and incident-reporting regimes. An ungoverned agent that touches a system of record is, in each of these contexts, a compliance event waiting to happen.


What Security Teams Should Do Now


Taylor's advice for enterprises is straightforward: assume you have more agents than you think, and build governance before scale forces your hand.


  • Inventory every agent. Run an audit across cloud, SaaS, and on-prem environments. Shadow agents rarely announce themselves.
  • Assign an owner to each agent. No agent should exist without a named human or team accountable for its behavior.
  • Scope permissions tightly. Grant the minimum access needed for the task, and review entitlements as tasks change.
  • Enforce lifecycle controls. Deprovision agents the same way you deprovision employees and service accounts.
  • Prepare for the prompt-as-attack scenario. A badly worded instruction can look identical to malicious traffic from the outside. Plan for it.

As agents proliferate, the question is no longer whether they will touch your systems of record, but whether you will know when they do. The 4,000-agent bank audit is a preview of what most enterprises will find when they finally look.

via MarkTechPost

Related