Samsung Leaks Semiconductor Secrets to ChatGPT. Twice. Then Once More.

Three Samsung engineers used ChatGPT to assist with internal work across three separate incidents in three weeks, pasting proprietary source code, hardware test sequences, and confidential meeting notes into the model. The data was retained for training; Samsung banned the tool after the third incident. Two incidents, apparently, were considered acceptable.

Severity: Unrated · Category: Data Exfiltration

Impact: Trade secrets permanently transferred to OpenAI

Source: The Economist Korea · TechRadar, Apr 2023

How Fencio prevents this

Sensitive data and an outbound channel ended up in the same context. The agent did not need to be malicious. It only needed to be convinced that sending the data somewhere was part of the job.

Fencio tracks sensitive data as it moves through an agent session and checks every outbound path, from links and images to emails and API calls. When classified data is about to leave, or a series of answers adds up to something the requester is not entitled to see, the response is blocked or redacted.

All incidents