Return to Threats

ESET調査:中小企業のAI活用で設定不備やプロンプト注入による情報流出リスクが増加

ITmedia エンタープライズ 2026-06-12 data leakage High

What Happened

ESETは、中小企業で生成AIやAIエージェントの導入が進む一方、設定不備やプロンプト注入攻撃、不正スキルにより機密情報がAI経由で流出する危険が増していると報告した。[4] 調査では、AI利用規定が未整備の企業が多く、顧客情報や財務データを安易に入力することによるデータ漏洩や権限管理の不備が問題として挙げられている。[4]

Why It Matters

The article reports that ESET found many small and medium-sized businesses are adopting generative AI and AI agents without sufficient rules or configuration controls, creating risks of data leakage through careless input of customer or financial data. It also highlights prompt injection and misconfigured agents as ways attackers could manipulate AI systems to expose internal information. RealGround analysis: this maps to a strong data-leakage and governance exposure, so priority defenses include policy enforcement, least-privilege access, and adversarial testing of AI workflows.

Healthcare Fintech SaaS SMB AI startups

RealGround Analysis

This signal maps to data leakage. Organizations using AI agents, LLM APIs, SaaS integrations, or sensitive data workflows should review whether this class of issue could create unauthorized tool execution, data leakage, weak approval gates, or unmanaged supply-chain exposure.

Recommended Actions

  • Restrict AI agent tool permissions and production write paths.
  • Review sensitive data access across prompts, logs, embeddings, memory, and SaaS integrations.
  • Add human approval workflows for high-impact or state-changing actions.
  • Run prompt injection and indirect prompt injection tests against affected workflows.
  • Document the owner, control gap, and remediation deadline for this risk class.

Source

https://www.itmedia.co.jp/enterprise/articles/2606/12/news038.html

Talk to AI CISO