Description
Sean Park, Principal Threat Researcher, TrendAI, speaks at [un]prompted 2026 on: When Passports Execute: Exploiting AI Driven KYC Pipelines.
Modern KYC workflows increasingly delegate passport parsing, database writes, and customer verification to A...
Sean Park, Principal Threat Researcher, TrendAI, speaks at [un]prompted 2026 on: When Passports Execute: Exploiting AI Driven KYC Pipelines.
Modern KYC workflows increasingly delegate passport parsing, database writes, and customer verification to AI driven extraction agents. This workflow is assumed to be safe because it is “just extraction,” tightly scoped by schema, and wrapped in compliance controls. In practice, it is an execution environment. We show how document embedded injects and compliance controls together steer AI agents into cross record reads and writes, enabling data theft and exfiltration without bypassing access controls.
This research goes beyond a one off agent or MCP exploit. We present a scalable exploitation approach that generalizes across KYC extraction agents, using LLM generated high success payloads and validating the attack with a tool using Claude Code extraction agent. A document embedded inject can steer the agent, while regulatory verification workflows complete the exploit chain.
Read more