About

The consultancy born at the intersection of behavioral economics and human experience.

NOW HIRING

Join a team reshaping how the world experiences brands.

View open roles →

COMPANY

GROW WITH US

CONNECT

Services

Comprehensive CX and management consulting for enterprise brands.

ALL SERVICES

Explore the full range of CX & management consulting services.

Browse all services →

CORE

SPECIALIST

Solutions

Structured solutions that turn CX ambition into measurable outcomes.

ALL SOLUTIONS

Explore every CX solution we offer.

Browse solutions →

STRATEGY & GOVERNANCE

DESIGN & DELIVERY

CULTURE & EXPERIENCE

Industries

A decade of CX transformation across the region's defining sectors.

ALL INDUSTRIES

See how we work across every sector.

Browse industries →

BUILT ENVIRONMENT

FINANCE & TECH

PEOPLE & MOBILITY

Products

Proprietary tools, platforms, and AI that power CX transformation.

ALL PRODUCTS

Explore the full Renascence product ecosystem.

Browse products →

AI & TECHNOLOGY

LEARNING & GAMES

PLATFORMS & TOOLS

AI PRODUCTS

Opinion

Insights, research, and conversations at the frontier of CX.

ReadExperience JournalArticles & research on CX, behavior, and transformation.Watch & listenExperience LoomOur video podcast on CX & behavior.CuratedCX NewsIndustry news that matters in CX, minus the noise.

Latest articles

Latest episodes

Latest news

Hub

Free tools, templates, and resources to advance your CX practice.

NEW · MANIFESTO

Burn the Deck. Ten Virtues. Zero Excuses. — read our manifesto for the brave consultant.

Start reading →

AI TOOLS

FREE TOOLS

LEARNING

CULTURE

Customer Service · 10 September 2026

AI Customer Service Agents Vulnerable to MFA Bypass, OTP Theft

Security researchers found AI-powered customer service agents can be manipulated to bypass MFA and extract OTPs, exposing sensitive account data across support channels.

Newsdesk
Curated briefing · 2 min read · 2 sources

What happened

Security researchers have found that AI-powered customer service agents can be manipulated to bypass multi-factor authentication (MFA), extract one-time passcodes (OTPs) and leak sensitive user data, according to reporting from cyberpress.org and gbhackers.com. The findings point to a class of vulnerability in conversational AI systems deployed for support and account-servicing functions, where the same natural-language flexibility that makes these agents useful can be exploited to trick them into circumventing identity checks.

The reports describe this as a security weakness inherent to how AI agents are designed to be helpful and responsive to customer requests, rather than a flaw isolated to one vendor or platform. By crafting inputs that exploit this helpfulness, attackers may be able to coax an AI agent into revealing verification codes or account details it should otherwise withhold.

Why it matters

As organisations across banking, telecom, retail and government race to deploy AI agents for customer service, this finding is a reminder that conversational AI introduces a new attack surface distinct from traditional web or app security. MFA and OTPs exist specifically to prevent account takeover; if an AI intermediary can be socially engineered into defeating them, the control itself is undermined regardless of how robust the underlying authentication infrastructure is.

For leaders overseeing AI adoption, the issue reframes security testing as a design requirement, not an afterthought. AI agents need to be evaluated not just for accuracy and tone, but for how they behave under adversarial prompting — a discipline closer to penetration testing than conventional QA.

The Renascence take

The instinct in most AI rollouts is to optimise for helpfulness and resolution speed, and to treat security as a backend concern handled elsewhere in the stack. This story shows why that separation no longer holds when the AI agent itself sits directly in the authentication path.

An AI agent that has been trained to be maximally accommodating is, by definition, easier to manipulate — helpfulness and resistance to social engineering pull in opposite directions, and most deployments have never been tested for that tension. Customer-obsessed operators should treat every AI-facing authentication flow as a potential social-engineering target, red-team their agents the way they would a call-centre script, and keep a hard technical boundary between what the AI can discuss and what only a verified backend system can release. The lesson isn't to make agents less friendly; it's to make sure friendliness is never the thing standing between an attacker and a customer's account.

Sources

This briefing was written by our Newsdesk, synthesising reporting from the outlets below. Follow the links for the original coverage.

FAQ

Questions we get on this topic

According to reporting from cyberpress.org and gbhackers.com, AI-powered customer service agents can be manipulated through crafted natural-language prompts to bypass multi-factor authentication, reveal one-time passcodes and leak sensitive user data.

No. The reports describe it as a structural weakness tied to how conversational AI agents are designed to be helpful and responsive, rather than a bug isolated to a single company's product.

Banking, telecom, retail and government organisations that have deployed AI agents for support and account-servicing functions are highlighted as most at risk, since these sectors rely heavily on MFA and OTPs to protect customer accounts.

The reporting and analysis suggest treating AI-facing authentication flows as adversarial testing targets, red-teaming agents like a call-centre script, and enforcing a strict technical separation between what the AI can discuss and what only a verified backend system can release.

Stay ahead of CX

Get the signal, not the noise.

The stories shaping customer experience — plus the Journal and Experience Loom — in your inbox.