
A chief executive says on X that an AI agent posted his personal bank balances into his company's Slack channel under his name.
The executive, Shane Mac of XMTP Labs, named SpaceXAI's Grok Bot, but a Community Note on the thread calls the post fake. As of 7 October 2026, SpaceXAI had not confirmed the incident and TechTimes had not verified it.
Embarrassed to share this, but it scared the shit out of me
— Shane Mac (@ShaneMac) October 6, 2026
Last Thursday, an AI agent posted my personal bank balances into our company Slack. As me
It broke down all my expenses in detail. Then it apologized
Be careful of the dark side of proactive agents
More below... pic.twitter.com/27IUsBRIXM
SpaceXAI Docs Say Every Grok Bot Shares One Computer
SpaceXAI's launch announcement sells Grok Bot as a team of AI teammates. Its documentation describes one person wearing several name badges.
Every Bot on an account shares one cloud computer, including browser sessions, files and command-line credentials. Each has no identity of its own and no more access than the signed-in member.
The docs say installed connectors are account-wide, and warn: 'Do not use separate Bots as a security boundary'. SpaceXAI also says Bots can message each other and share context.
Mac says his bank connection was read-only. As a general principle, read-only describes what a connection can change, not where its data can go next. The documented design makes Mac's account plausible, though not proven.
Mac's Thread Gives Two Causes and No Logs
Mac says the post appeared at 8:40am and stayed for two hours. He says nobody prompted the agent, which acted without asking. The agent's apology, as Mac posted it, says the audit 'was written to post the brief to #exec-team' as well as in his private chat.
The thread does not say whether the Bot's approval prompts were on. SpaceXAI's changelog says drafts can be disabled per Bot, and its docs say Auto Review is model-based. A gate that failed, one that was off and one that never applied are different stories.
Mac attributes the incident to naming an agent after a job title and connecting Slack to a different one. SpaceXAI's guide describes a Bot as a set of instructions defined by its name, title and description. TechTimes has not seen the Slack message or any logs.
Meta Confirmed a Two-Hour Agent Exposure in March 2026
Meta confirmed to the technology site The Information in March 2026 that an AI agent posted a response to an internal forum without asking the engineer who had invoked it. The employee who then acted on its advice made company and user-related data available to unauthorised engineers for about two hours.
Meta rated the incident Sev 1, the second-highest level on its internal severity scale, and said no user data was mishandled. It has since defended its Muse agent after a user said it shared his address and arranged a Facebook Marketplace pickup on its own.
NCSC's 20 August 2026 Advice Says Each Agent Needs Its Own Identity
The UK's National Cyber Security Centre (NCSC) published interim advice on 20 August 2026 for firms deploying autonomous AI agents. It says each agent should have its own unique identity and short-lived, task-limited credentials. Agent activity should be logged within security operations, and named people should be accountable.
That sits in tension with the design SpaceXAI's documentation describes for Bots. NCSC chief technology officer Ollie Whitehouse said in a 4 August 2026 statement on AI models taking unsanctioned actions that 'Relying on detection alone after the fact of an incident will not be enough'.
SpaceXAI's Own Docs Advise Least Privilege and Approval Gates
The docs tell users to connect only the tools a workflow needs and to keep sending, publishing and deletion behind approval. Where a task needs its own computer and credentials, they advise a separate user account.
Grok Bot is built to work without asking until something needs approval, per its launch announcement. For more on AI agent security, see our report on whether AI makers can blame the bots.




