SalesBleed Flaws Let Attackers Drain Salesforce CRM Data With Zero Clicks on Agentforce
Zenity Labs found three Agentforce weaknesses, dubbed SalesBleed, that let an anonymous web form plant instructions an AI agent follows to leak CRM data and phish staff over Slack.

A stranger fills out a contact form on a company website. Nobody at the company clicks anything. Hours later, the company's own Salesforce AI agent is quietly handing over customer data and sending phishing messages to employees in Slack.
That is the attack chain researchers at Zenity Labs disclosed this week in three weaknesses in Salesforce Agentforce, which they collectively call "SalesBleed," as detailed by Dark Reading.
How the attack works
The entry point is Web-to-Lead, the Salesforce feature that turns public website forms into sales leads. Companies want strangers to fill those forms in. That is the whole point.
Zenity found that an attacker can hide AI instructions inside a form submission. When an Agentforce agent later processes the lead as part of a normal workflow, it reads those instructions and carries them out inside the victim's own Salesforce tenant.
From there, the agent can pull CRM records out of the organization. It can also post phishing messages to employees through the company's trusted Slack channels, which are the places staff are least likely to be suspicious, because the message arrives from an internal tool they already rely on.
A patched hole that did not stay closed
SalesBleed is not the first time Web-to-Lead has been turned against Agentforce. About a year ago, Noma Security reported a similar prompt-injection path through the same forms. Salesforce responded by tightening its URL filters.
Zenity found ways around those filters. The researchers' larger point is that the fix treated the symptom. The underlying problem, agents that cannot reliably tell trusted instructions from text supplied by an outsider, is still there. The Register also describes the flaws as enabling zero-click CRM data theft and anonymous phishing.
The attacker has no name
The detail that should worry security teams most is accountability. A Web-to-Lead submitter is anonymous by design. There is no account to suspend, no login to trace and often no reliable way to identify who planted the payload.
Classic attacks usually require a compromised credential or a user who clicks a link. Here, the attacker only needs to reach a public form.
What is and is not known
SalesBleed is a research disclosure. Zenity has shown the paths are exploitable, but the reporting does not describe a confirmed mass campaign in the wild, and there is no suggestion that every Agentforce customer has been breached.
It lands as AI agents keep turning up in security stories, including the Medicare hack case in Australia. Salesforce sells Agentforce as a way to let AI act on customer data. Zenity has shown how easily that same authority can be borrowed by someone typing into a contact form.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free