Categories: Cyber Security News

77% of Employees Share Company Secrets on ChatGPT Leading to Policy Breaches

The digital workplace is undergoing a dramatic transformation as generative AI tools, such as ChatGPT, and enterprise SaaS solutions become central to productivity; however, this shift has also introduced new, poorly understood risks.

The latest telemetry report drawn from real enterprise browsing data exposes a startling trend: GenAI tools have overtaken classic SaaS applications as the primary conduit for sensitive corporate data leaving the organization.

Nearly half of all employees within the observed environments regularly interact with GenAI platforms, and an alarming 40% of file uploads contain regulated data, such as PII or PCI information.

Despite security policies emphasizing file controls, attackers and employees alike have begun to favor file-less data movement, quickly copying and pasting sensitive information into AI chat prompts and SaaS workflows.

Telemetry revealed that 77% of employees paste confidential records, such as client contact lists, financial numbers, and source code snippets, directly into GenAI input fields.

The vast majority (82%) of these actions occur via accounts and device sessions not registered with enterprise identity management, effectively making this data invisible to security and compliance auditing systems.

Unlike traditional DLP, which monitors file transfers and attachments, file-less exchanges evade detection and leave minimal artifacts for investigation.

The risk is compounded by the rapid sharing of content across browser windows, remote desktops, and mobile apps that are beyond the reach of legacy endpoint protections.

Corporate Logins and Chat Apps Are Not Safer

Many businesses rely on Single Sign-On (SSO) mechanisms, assuming that official corporate credentials ensure security.

Yet, the report found that even sanctioned logins for CRM and ERP platforms are compromised by the widespread use of non-SSO access methods.

Unmanaged accounts often access critical platforms, blurring the distinction between legitimate and unauthorized activity.

Chat and IM applications, which are increasingly vital for real-time collaboration, create additional risk, with 87% of observed chat activity flowing through accounts outside of enterprise oversight.

The telemetry data shows 62% of users pasted sensitive data, such as customer information or business plans, directly into chat apps under unmanaged identities, bypassing all corporate logging and monitoring.

Rethinking DLP: GenAI and SaaS Demand New Controls

This emerging threat matrix demands a radical rethink of enterprise security strategies. The focus must shift from legacy file-centric DLP to dynamic controls that monitor browser-based data flow, copy/paste transactions, and unmanaged SaaS session activities.

Real-time telemetry capture and behavioral analysis become critical technical controls for detecting and preventing exfiltration attempts that escape file-level scrutiny.

Adaptive access policies should block risky paste or chat operations, and enterprises must expand monitoring to unmanaged GenAI and SaaS usage.

Only these measures can address new blind spots introduced by file-less interactions and external identities, protecting against accidental and intentional data leaks in the age of AI-enabled productivity.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post 77% of Employees Share Company Secrets on ChatGPT Leading to Policy Breaches appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

Today’s Top Deals: Ninja Gaiden: Ragebound for Switch, LEGO Sets, and an Xbox Gift Card

If you’re after some new games for your Switch 2, you’re in luck, as Ninja…

31 minutes ago

Pokémon Fan Funds Wedding With $44,000 Charizard Card Sale

A Pokémon fan has been able to fund his own wedding, after rediscovering a trio…

32 minutes ago

The Beginner-Friendly DJI Mini 4K Drone Fly More Combo With Extra Batteries Has a 30% Price Drop

The DJI Mini 4K is an excellent quadcopter drone camera for beginners looking to try…

32 minutes ago

Handle Long Press/Tap Event In JavaScript – long-press-event

long-press.js is a small JavaScript library which detects and handles the long press/tap event on…

1 hour ago

The art of honest conversation: the one shift that makes people finally feel heard

Tension: We perform listening instead of practicing presence, creating distance while appearing close. Noise: The…

1 hour ago

The leadership style that worked in 2010 is actively damaging teams in 2026

Tension: The command-and-control leadership that built successful companies in 2010 now creates anxious, depleted teams.…

1 hour ago

This website uses cookies.