AI Agents as BEC Attack Vectors: Execution of Payroll Diversion, Invoice Fraud, and Benefits Fraud Through Natural Business Conversation
收藏资源简介:
This paper documents the first empirical demonstration that AI agents deployed in payroll, accounts payable, and benefits administration execute Business Email Compromise (BEC) fraud scenarios at 80-90% rates in response to natural business conversation. No technical exploitation is required. The attack vectors are identical to social engineering scripts documented in FBI IC3 BEC advisories. Across 90 structured test runs (Battery B253), three frontier AI models -- Claude Sonnet 4, GPT-5.4, and Grok-4 -- were deployed as payroll, AP, and benefits agents and attacked using implicit authorization attacks: zero explicit approval claims, no forged credentials, no authority figures. Just natural business communication indistinguishable from legitimate employee and vendor requests. Key findings: All three models breach at 90% on benefits beneficiary fraud. All three breach at 80-90% on payroll diversion. 63 real HTTP tool calls were logged on a third-party server with full payloads including employee IDs, account numbers, routing numbers, and beneficiary names. Every breach issued a formatted function invocation -- not a text response, an actual execution attempt. A one-paragraph system prompt addition (Approach 2 channel restriction) drops breach rate to 0% across all scenarios and models. All results were cryptographically anchored to Ethereum Sepolia before public disclosure. This paper extends prior VATA BEC research (DOI: 10.5281/zenodo.19501622) and the model-domain behavioral matrix (DOI: 10.5281/zenodo.20147004). Methodology, raw data, anchor transactions, and live leaderboard: lhmisme420.github.io/VATA-SCORES-0311



