> ## Content Index
> Fetch the complete content index at: https://www.theleftshift.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Researchers Demonstrate How ChatGPT Could Leak Private Emails Through MCP Tools
- URL: https://www.theleftshift.com/researchers-demonstrate-how-chatgpt-could-leak-private-emails-through-mcp-tools/
- Published: 2025-09-14T05:53:42.000Z
- Updated: 2025-09-14T05:53:42.000Z
- Description: OpenAI recently rolled out full support for the Model Context Protocol (MCP).
- Author: The Left Shift Bureau
- Tags: AI Developments

A new security demonstration by [Eito Miyamura](https://www.linkedin.com/in/eito-miyamura-157305121/?ref=theleftshift.com), co-founder of cybersecurity startup Edisonwatch, has raised alarms about the risks posed by AI assistants with expanded tool access.

On Wednesday, [OpenAI rolled out full support for the Model Context Protocol (MCP)](https://www.theleftshift.com/openai-introduces-mcp-server-tools-in-chatgpt-developer-mode/), a framework that allows ChatGPT to connect to external services such as Gmail, Google Calendar, SharePoint, and Notion. While designed to make the AI more useful, the integration could also open the door to novel attack methods.

According to Miyamura, all an attacker needs is a target’s email address. By sending a malicious calendar invite embedded with a jailbreak prompt, the attacker can hijack ChatGPT the moment a user asks it to review their calendar. Once compromised, the AI may follow the attacker’s hidden instructions—such as searching through private emails and forwarding [sensitive data](https://www.theleftshift.com/okta-uncovers-voidproxy-advanced-phishing-service-bypassing-mfa-protections/)—without the user realizing.

> We got ChatGPT to leak your private email data 💀💀  
>  
> All you need? The victim's email address. ⛓️‍💥🚩📧  
>  
> On Wednesday, [@OpenAI](https://twitter.com/OpenAI?ref%5Fsrc=twsrc%5Etfw&ref=theleftshift.com) added full support for MCP (Model Context Protocol) tools in ChatGPT. Allowing ChatGPT to connect and read your Gmail, Calendar, Sharepoint, Notion,… [pic.twitter.com/E5VuhZp2u2](https://t.co/E5VuhZp2u2?ref=theleftshift.com)
> 
> — Eito Miyamura | 🇯🇵🇬🇧 (@Eito\_Miyamura) [September 12, 2025](https://twitter.com/Eito%5FMiyamura/status/1966541235306237985?ref%5Fsrc=twsrc%5Etfw&ref=theleftshift.com)

Currently, OpenAI has limited [MCP tools](https://www.theleftshift.com/oracle-introduces-mcp-server-in-sqlcl-to-supercharge-ai-asks-to-db-workflows/) to developer mode, requiring manual approval for each session. But Miyamura warns that “decision fatigue is a real thing, and normal people will just trust the AI and click approve, approve, approve.”

*"Remember that AI might be super smart, but can be tricked and phished in incredibly dumb ways to leak your data," he said.*