🔥 Trending on HN

A Personal AI Sent a Financial Report to the Wrong Slack Channel

3 min read Tiny Why Newsroom · By Curio, Martian correspondent

Words
AI agent

A software helper that can read information and take actions.

Slack

A messaging service used for work.

permission

A rule about what an AI may read or send.

What happened

A Business Insider report published on October 9, 2026, describes a personal AI assistant sending a household finance report to a company’s Slack. The story was edited from a conversation with Shane Mac, the 40-year-old CEO of XMTP Labs, a software company. It is a detailed personal account, not an independent technical audit.

Mac set up a personal finance agent with Grok Bot, an AI service that can follow instructions and work across connected tools. In late August, he gave the agent read-only access to his personal checking and savings accounts. He wanted a monthly report with balances, expenses, recurring costs, and possible suspicious spending. The report was supposed to go only to him, inside a private group chat for his AI agents.

On October 1, the report appeared in his company’s Slack instead. It went to a chat called “Exec-team,” used by company executives. The report included his checking and savings balances, his largest expenses, and spending connected to a barn he was building. It also showed that he was far above his monthly spending target. A product leader noticed the message and contacted Mac. He deleted it.

How the mix-up happened

Mac had created several agents and connected Slack to one of them. According to the report, the agents looked separate, but they used the same underlying connections. His private AI group and the company chat shared the name “Exec-team.” The agent therefore chose the wrong destination.

That distinction matters. The report does not describe an AI inventing a plan to expose private data. It describes an automated system selecting the wrong place inside a set of connected accounts. A natural-language instruction such as “send this only to me” did not prevent the mistake.

Why it matters

Personal AI agents are useful because they can read information and perform repeated tasks. The same connections can create trouble when personal finance data and workplace messaging meet in one workflow. Reading an account and posting to a work channel are different powers. They need separate permissions, clear boundaries, and a visible check before information leaves its original context.

This is a security story, but the reported issue is not a technical exploit. It is a permission and destination error. That makes it easier to miss. A system can be allowed to do something useful and still send the result to the wrong audience.

What is confirmed

Business Insider says the Grok team investigated the incident. The report says the team added a rule requiring users to give explicit permission before an agent moves information to another chat. Mac then removed his connections to Google, calendars, banking, Stripe, and other services. The article does not independently test whether the new control works in every case.

The related Hacker News post had 60 points and 66 comments. Hacker News is a technology news forum. Those figures show community attention. They do not prove that the report is correct.

What remains unknown

The report does not say how many people saw the company message. It does not provide a complete copy of everything the message contained. It specifically describes balances and spending. It does not confirm that account numbers or login credentials were included. The article also does not explain the new permission system in enough detail to judge its full coverage.

What to watch next

The important follow-up is whether personal and work connections can be kept separate. It also matters whether users can clearly review the destination and contents before an agent posts. The broader lesson is modest but important: an AI assistant needs limits around both what it can read and where it can send information.

💬 When a personal AI agent crosses the work–personal boundary

Hacker News commenters debated a user-reported incident in which a Grok Bot received both personal financial access and company Slack permissions, then posted bank information to a company channel. The discussion focused on human judgment, product design, and corporate and regulatory responsibility.

  • In the user's own account, Grok Bot was given access to personal financial information and read/write access to company Slack at the same time.
  • A commenter relaying the article's account said the agent confused two Slack channels with the same name and posted bank information to an executive channel instead of the user's private AI-agent chat. This is a user-reported misrouting incident, not independently verified here.
  • One side blamed the human permission design: combining personal finances with work communications would be dangerous even without an AI agent.
  • The counterargument blamed vendors and regulators too: AI companies encourage people to connect bank and health data and present agents as capable of understanding and acting, while ordinary users may not be able to judge the risks.
  • Technical commenters argued that instructing an agent not to leak data is insufficient. Sandboxing, network controls, and deterministic separation between personal and work domains should prevent access across boundaries.
  • To avoid same-name destination errors, use stable channel IDs rather than display names, restrict where the agent can post, and apply least privilege.
  • Another user reported using an intermediary program to let an agent correlate spending with invoices while routing external actions through an outbox for review. That is an individual report, not evidence of general safety.
  • The comments do not establish whether the leaked bank details were account or routing numbers, or login credentials. Because bank-account information can sometimes be shared for transfers, the risk depends on exactly what was exposed.

initial digest at 66 comments (revision 1). We fetched 66 comments and sampled 66 across the thread. These are HN users’ reports, not independently verified facts.

🔥 Trending on HN

A personal AI sent a money report to the wrong work chat

📰 Full story: A Personal AI Sent a Financial Report to the Wrong Slack Channel

A personal AI read money details and sent them to a company chat. Two chats had the same name.

2 min read Tiny Why Newsroom · By Curio, Martian correspondent

Words
Grok Bot

An AI service that follows instructions and helps with tasks.

Slack

A work messaging service.

permission

Approval for an AI to use information or send it.

💡 The gist

  • A personal AI read a user’s money details.
  • It sent the report to a company Slack chat.
  • Two chats had the same name.

Shane Mac is the CEO of XMTP Labs, a software company. He built a personal finance helper with Grok Bot, an AI service. He gave it read-only access to his checking and savings accounts. It could read them, but not change them. He wanted a monthly report in his private AI group.

On October 1, the report went to his company’s Slack. Slack is a work messaging service. It landed in a chat called “Exec-team.” Company executives used that chat. The report listed balances and large expenses. It also mentioned a barn he was building. A product leader noticed the message. Mac deleted it.

The reason was simple, but important. Mac had several AI helpers. They used shared connections underneath. His private group and company chat shared the name “Exec-team.” The AI chose the wrong destination. This was a sending mistake, not a new plan.

This shows why AI helpers need clear limits. A person can tell an AI, “send this only to me.” Names can still confuse a system. The tool must also control which chats it can use. Reading personal money and posting at work should be separate permissions.

Connecting several services makes an agent useful. It also joins separate parts of a person’s life. A private money report and a work chat should not share unclear paths. Clear permissions reduce that risk.

Business Insider, a news outlet says the Grok team added an approval step. The AI must ask before moving information to another chat. Mac also removed his banking, Google, calendar, and Stripe connections. The report does not say how many people saw the message.

The related post on Hacker News, a technology news forum had 60 points and 66 comments. Those numbers show attention, not proof. The report names balances and spending. It does not confirm that account numbers or passwords were shared. The new approval system also needs watching.

The lesson is clear. Helpful AI still needs boundaries. Users should know what it can read. They should also know where it can send information.

💬 The danger of giving one AI your money and your work chat

The comments discussed a user-reported incident in which a Grok Bot could access personal financial information and company Slack, then sent bank information to a company channel. Some blamed the person; others blamed AI companies and regulators.

  • In the user's account, a personal Grok Bot could see money information and use the company's Slack.
  • The article's account, as described by a commenter, says the AI mixed up two Slack rooms with the same name and sent bank information to the executives' room instead of the personal room. This was reported by the user, not independently checked.
  • Some commenters blamed the person for connecting personal and work data. Others blamed AI companies and regulators for making this kind of connection look safe and easy.
  • Saying only that the AI must not leak is not enough. Put it in a sandbox, limit its network, and keep personal and work data in separate locked areas.
  • Use a fixed channel ID, give only the permissions the AI needs, and put outgoing actions in an outbox, a waiting place where a person can check them. Another user described using an intermediary program, but that example is also self-reported.
  • The comments do not say exactly what bank data was exposed. An account number is different from a login secret.

initial digest at 66 comments (revision 1). We fetched 66 comments and sampled 66 across the thread. These are HN users’ reports, not independently verified facts.

🔥 Trending on HN

The AI sent a money note to the wrong chat

📰 Full story: A Personal AI Sent a Financial Report to the Wrong Slack Channel

The AI picked the wrong chat room.

1 min read Tiny Why Newsroom · By Curio, Martian correspondent

Words
Grok Bot

An AI helper that follows instructions.

Slack

A chat used for work.

Hacker News

A place where people discuss technology news.

Shane Mac is a boss at XMTP Labs, a software company. He asked Grok Bot, an AI helper, to check his home money. Grok Bot made a small report. It showed money left and things he bought.

The report should go to his private AI chat. Instead, it went to Slack, a work chat. It landed in a company room called “Exec-team.”

Mac also had a private room called “Exec-team.” Both rooms had the same name. The AI picked the wrong room. A coworker noticed the message. Mac deleted it.

The Grok team said the helper should ask first. Mac then disconnected his accounts.

Business Insider, a news outlet reported the story. The related post on Hacker News, a technology discussion board had 60 points and 66 comments. Those numbers show attention. They do not prove every detail.

People still do not know how many saw the message. The report names balances and spending. It does not confirm that account numbers or passwords were shared.

An AI can be helpful. It can also choose the wrong place. People must check what it can read and where it can send.

💬 Keep the money room and work room apart

The user says a personal Grok Bot could see money information and also use company Slack.

  • The bot picked the wrong room because two rooms had the same name, and sent bank information to the company room. The story does not say exactly which bank information it was, and the event was only reported by the user.
  • Some people said the person connected two things that should stay apart. Others said the AI company also had a duty to make this safer.
  • A safer plan is to keep work and personal things separate, give the bot only a small key, and have a person check before anything is sent.
  • One commenter mentioned putting a helper program in the middle, but that was only their own report.

initial digest at 66 comments (revision 1). We fetched 66 comments and sampled 66 across the thread. These are HN users’ reports, not independently verified facts.

Sources