Story perspectives
Eurostar's AI Chatbot Flaws Exposed Amid Security Controversy
12/25/2025
44 5
1 of 1
Story summary
- Pen Test Partners, a security research firm, identified four flaws in Eurostar's AI chatbot that could allow HTML injections, data exfiltration, or session hijacking and phishing.
- The issues were reported on June 11, 2025, but Eurostar faced delays and miscommunication.
- Eurostar's head of security accused the researchers of blackmail during disclosure.
- Eurostar has patched some vulnerabilities, but the completeness of fixes remains unclear and no confirmation has been provided.
