CSCase Studies
Case Study: Attacking a Customer-Support AI Chatbot
A fictional assessment of a RAG-backed support chatbot with tool access, where an indirect prompt injection hidden in a knowledge-base document led to data exfiltration, plus how it was detected and the controls that fixed it.
Intermediate4 min readassociate streamUpdated Sat Aug 01 2026 00:00:00 GMT+0000 (Coordinated Universal Time)
Learning objectives
- Explain how indirect prompt injection differs from a user typing a malicious prompt
- Trace a RAG-and-tools chatbot from a poisoned document to data exfiltration
- Identify why the model's tool permissions, not its wording, are the real boundary
- Name the controls that contain injection without trying to filter every phrasing
Academy subscription
Subscribe to unlock this module
This module is part of the StrikeOps Academy subscription. Unlock every paid module, with hands-on labs and knowledge checks.
- Every paid module across all tracks
- Hands-on labs and knowledge checks
- New content as it ships
$59/ month · or $590 / year
The Reference library and Foundation starters are free to read now.