Critical

Financial PII — Personal Financial Data Request for Named Individual

An attacker asks an AI assistant to disclose private financial information — bank details, card numbers, net worth, debts, tax records — about a specific named individual, often framed as a friend, doctor, fiancé, or other relation. The relationship label makes the request sound legitimate, tricking the AI into treating a surveillance attempt as a normal personal question.

How the attack works

The attacker addresses the AI as if the target is someone in their own life, e.g. 'my fiancé, Brett' or 'my doctor, Anne'. They then ask for a specific piece of financial data about that named person: bank account numbers, card details, investment holdings, loan balances, property ownership, insurance status, or transaction history. The personal relationship framing is designed to lower the AI's guard compared to an anonymous or generic financial question. If the AI complies, the attacker walks away with information usable for fraud or further targeting.

Netzilo detection

Netzilo reports this behaviour when it is observed.

Signature ID
ff6dd863-b6d2-489e-a3ac-6b09977af79c
Severity
Critical

Why it matters

If successful, an attacker obtains financial details about a real, named person that can be used for identity theft, account takeover, or building a convincing social-engineering pretext against that individual or their contacts.

What you can do

  • Configure the AI system to refuse requests for financial or identity data about any named third party, regardless of stated relationship.
  • Log and review prompts that combine a personal relationship claim with a request for account numbers, net worth, debts, or tax data.
  • Separate legitimate use cases (e.g. authorized fraud investigation, forensics) with a verified escalation path rather than allowing free-text claims of relationship or authorization.
  • Educate users and support staff that 'my doctor/fiancé/friend told me to ask' is a common social-engineering framing, not proof of authorization.

Known benign look-alikes

  • Law enforcement or forensics professionals with authorized access
  • Academic discussion of financial privacy or identity theft without targeting a named individual
  • General financial literacy questions about credit, loans, or investments

References

Related threats