Microsoft Reveals 'Whisper Leak' Attack That Exposes AI Chat Topics
Microsoft has disclosed a new side-channel vulnerability in AI chat systems that can reveal what users are discussing, according to Forbes. The flaw, named Whisper Leak, allows attackers monitoring encrypted internet traffic to infer conversation topics with high accuracy, even though the content itself remains secure.
The attack targets the streaming feature used by AI chatbots such as ChatGPT, Copilot, and Claude, where responses are displayed incrementally. By analyzing the size and timing of encrypted data packets sent between a user and an AI service, a passive observer can identify if a conversation concerns specific subjects like politics or financial crimes.
Microsoft researchers trained classifiers on traffic patterns from models operated by companies including OpenAI, Mistral, DeepSeek, and xAI. Their proof-of-concept achieved over 98% accuracy in detecting targeted topics. The company noted that the effectiveness of the attack can increase over time as more conversation samples are collected.
After responsible disclosure, OpenAI, Microsoft, and Mistral implemented mitigations by adding random text sequences to chatbot responses, which obscure packet patterns and neutralize the leak. Microsoft also advises users to avoid sensitive discussions on public networks, use VPNs for added protection, and prefer non-streaming modes when privacy is critical.
The discovery highlights ongoing challenges in securing AI communication systems, where even encrypted exchanges can inadvertently expose metadata about user interactions.
We hope you enjoyed this article
Consider subscribing to one of our newsletters like Cybersecurity AI Weekly or Daily AI Brief.
Also, consider following us on social media:
More from Cybersecurity
Oct 2 Suspected Chinese spies impersonate AI policy figures in phishing campaign Oct 2 AI Agents Tried to Access Canadian Government Archive Site Oct 2 Nuix Showcases Neo Financial Crime Tools at Sibos 2026 Oct 1 OpenAI Links Model Reasoning Extraction Campaign to Moonshot AI Oct 1 Ocrolus Adds Resistant AI Document Fraud Detection to DetectCybersecurity AI Weekly
Weekly newsletter about AI in Cybersecurity.
Industry analysis
2025 Global Business Services Agenda: Gen AI Takes Center Stage
This industry analysis by The Hackett Group explores the transformative impact of generative artificial intelligence (Gen AI) on global business services (GBS) in 2025. The study highlights the shift from exploration to acceleration of Gen AI initiatives, with 89% of executives advancing these projects to improve customer satisfaction, innovate products, and reduce costs. The report also discusses the challenges and strategies for successful Gen AI adoption, emphasizing the need for a technology-enabled operating model and the importance of reskilling the workforce.
Read moreYou may also like
Anthropic Attributes Its Largest Measured Distillation Campaign to Alibaba
Chinese AI Agents Deceived Evaluators in Controlled Tests
Suspected Chinese spies impersonate AI policy figures in phishing campaign
Researchers Used Anthropic Tool to Access OpenAI Employee Account
ClosedQuorum Malware Uses Four AI Models to Choose Attack Steps
Daily AI Brief: the AI news that matters, in your inbox.