Retry in progress
You have 1 previous attempt for this scenario. Submitting again will create a new attempt and show a comparison against your most recent response.
Shadow AI Sensitive-Data ExposureDifficulty · easyHigh asset
Hi SOC,
Our DLP / web proxy flagged a possible data exposure and I want a second opinion before I talk to the user.
A Support team member (jordan.kim) used a PERSONAL account on a public AI chatbot from their work laptop and pasted in what looks like a chunk of a customer export plus a snippet of an internal script. This is NOT one of our approved tools — it is "shadow AI". The paste was about 30 minutes ago. Jordan says they were "just trying to summarize a ticket backlog faster".
I have the DLP match details and the proxy log. I have not contacted Jordan yet and I have not changed anything. What is the right order of steps, and how do I work out exactly what was exposed and who needs to know?
— Maria (SOC, Tier 1)
Evidence
DLP match summary + web-proxy log excerpt (JORDAN-WKS)
# DLP match (endpoint agent)
time: 2026-05-04 13:47 UTC
user: jordan.kim@acme-corp.com host: JORDAN-WKS
action: clipboard paste into browser -> chat.example-ai[.]com (category: Generative AI, UNSANCTIONED)
rule hit: "Customer PII (name+email+phone)" x42 rows, "Source code (internal)" x1 block
sample: [REDACTED by DLP] 42 rows matching <name,email,phone,acct_id>; ~60 lines of an internal helper script
# Web proxy (src=10.12.51.30 JORDAN-WKS)
13:46:55 CONNECT chat.example-ai[.]com:443 ALLOW (no GenAI category block configured)
13:47:10 POST chat.example-ai[.]com/api/conversation (request body not inspected — TLS)
13:51:02 GET chat.example-ai[.]com/ 200
# Tool / account context
- chat.example-ai[.]com = public consumer AI chat, PERSONAL login (not SSO, not in the app catalog)
- no enterprise data-retention setting, no DPA / contract with this vendor
- Support role scope: read access to the customer ticket system + a customer-export report
Affected asset
- Name
- Customer records (42) + internal script snippet via jordan.kim
- Type
- Regulated customer PII export + internal source snippet pasted into an unsanctioned public AI chatbot
- Owner
- Customer Support · Jordan Kim (data owner: Support Ops / Privacy)
- Level
- High