By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Researchers say Eurostar accused them of blackmail over AI chatbot flaw disclosure – News
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Researchers say Eurostar accused them of blackmail over AI chatbot flaw disclosure – News
News

Researchers say Eurostar accused them of blackmail over AI chatbot flaw disclosure – News

News Room
Last updated: 2025/12/25 at 9:17 AM
News Room Published 25 December 2025
Share
Researchers say Eurostar accused them of blackmail over AI chatbot flaw disclosure –  News
SHARE

Eurostar International Ltd., the operator of the Eurostar trains that cross the English Channel, has been accused of mishandling the responsible disclosure of security flaws in its customer-facing artificial intelligence chatbot after security researchers were allegedly told their actions could be viewed as blackmail.

The allegation comes from U.K. security firm Pen Test Partners LLP, which said it identified multiple vulnerabilities in Eurostar’s AI-powered chatbot earlier this year. The vulnerabilities were discovered during routine testing rather than as part of a commissioned engagement.

The vulnerabilities detected included weaknesses in how the chatbot handled conversation history and message validation that could allow attackers to manipulate earlier messages in a chat session. The Pen Test Partners researchers were able to bypass safety guardrails, extract internal system information and inject arbitrary HTML into chatbot responses.

Though the chatbot was not connected to sensitive customer data, the firm warned that such flaws could become more serious if the system were later expanded to handle bookings, personal information, or account access.

As a legitimate company that practices ethical disclosure, Pen Test Partners attempted to report the issues through Eurostar’s vulnerability disclosure process beginning in mid-June. After receiving no response, it followed up multiple times via email and later through LinkedIn, but then it gets weird.

According to Pen Test Partners, a Eurostar security executive eventually responded but suggested that continued attempts to draw attention to the issue could be interpreted as blackmail.

“To say we were surprised and confused by this has to be a huge understatement – we had disclosed a vulnerability in good faith, were ignored, so escalated via LinkedIn private message,” Ross Donald, head of core pent test at Pen Test Partners, wrote in a blog post. “I think the definition of blackmail requires a threat to be made and there was of course no threat. We don’t work like that!”

Eurostar later acknowledged that the original disclosure email had been overlooked and said some of the reported issues were subsequently addressed. Exactly what it fixed is unclear, however.

“We still don’t know if it was being investigated for a while before that, if it was tracked, how they fixed it, or if they even fully fixed every issue!” added Donald.

As AI-powered customer interfaces become more widespread across industries, the Eurostar episode serves as a reminder that chatbot security is not just about AI behavior but also about the underlying software infrastructure that supports it.

The case also highlights the need to have trained staff who are willing to work with security professionals instead of erroneously accusing them of wrongdoing.

Image: News/Ideogram

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

About News Media

News Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of News, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — News Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, News Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Solo Satoshi Becomes Authorized Canaan Distributor for Avalon Home Bitcoin Miners. | HackerNoon Solo Satoshi Becomes Authorized Canaan Distributor for Avalon Home Bitcoin Miners. | HackerNoon
Next Article 4 Ways Brands Can Use Instagram’s Pinned Comments –  Blog 4 Ways Brands Can Use Instagram’s Pinned Comments – Blog
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

How to Make a Media Kit for Influencers (Free Template)
How to Make a Media Kit for Influencers (Free Template)
Computing
This is the one thing you must not do with your new Nintendo Switch 2
This is the one thing you must not do with your new Nintendo Switch 2
Gadget
The best advanced iPad board game ports for the strategy gamer in your life
The best advanced iPad board game ports for the strategy gamer in your life
News
Hedgehogs vs. Porcupines: In Defense of ‘Spiky’ Writing in the Age of AI | HackerNoon
Hedgehogs vs. Porcupines: In Defense of ‘Spiky’ Writing in the Age of AI | HackerNoon
Computing

You Might also Like

The best advanced iPad board game ports for the strategy gamer in your life
News

The best advanced iPad board game ports for the strategy gamer in your life

1 Min Read
Your Car’s Lidar Can Destroy Your Phone’s Camera – Here’s How – BGR
News

Your Car’s Lidar Can Destroy Your Phone’s Camera – Here’s How – BGR

3 Min Read
How a Spanish virus brought Google to Málaga |  News
News

How a Spanish virus brought Google to Málaga | News

5 Min Read
Beyond SEO: How AI engine optimization is changing the equation in online visibility –  News
News

Beyond SEO: How AI engine optimization is changing the equation in online visibility – News

8 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?