CEO says his Grok Bot 'CFO' agent posted his personal bank audit to his company's executive Slack channel instead of his private agent chat (as-told-to essay)
In an as-told-to essay published by Business Insider on 9 October 2026, the chief executive of a software company says that a personal finance agent he had set up on Grok Bot around the end of August, with read-only access to his personal checking and savings accounts and an instruction to message only him, posted his first monthly audit into his company's executive Slack channel on Thursday 1 October. He says he learned of it when his head of product messaged him, that the post showed his personal checking and savings balances and his largest expenses of the month, and that when he asked the agent why it had sent the report to the company it apologised and said it would delete the message, which he had already deleted himself. According to the author, the vendor's team found that the agent had confused his personal group chat of agents with a company Slack channel that carried the same name, because his agents shared one set of connections, and shipped a change requiring explicit permission before an agent moves information between channels. He says he then disconnected all of the agent's connections, including banking, calendars and payments.
- AI system
- Grok Bot
- Occurred
- 1 Oct 2026
- Reported
- 9 October 2026
- Event location
- Unknown
- What the AI did
- Acted on the person’s behalf
- Reported harm
- Other Material Harm
- Whose AI use
- Their own AI use
- Setting
- Everyday life · Work · Finance · Privacy
- Evidence
- AI involvement reported · Causal attribution alleged · 1 source
- 4 claims: 4 reported. 5 open questions
- People reported harmed
- 1 person
AI system as recorded: A personal 'CFO' finance agent the author set up on Grok Bot with read-only access to his personal bank accounts; it was instructed to send a monthly report only to him in a group chat of his agents and instead posted the report to a company Slack channel
What Happened
The setup. The author says he began using personal AI agents in December and set up a 'CFO' agent on Grok Bot around the end of August to answer monthly questions about balances, expenses and suspicious items. In his words: "For its permissions, I gave it read-only access to my personal checking and savings accounts." He adds: "I told it to send messages only to me through Grok Bot." The report was meant to arrive in a group chat of his agents.
The event. "It was Thursday, October 1. Our head of product sent me a DM on Slack." The colleague thought the post was the company's financials; the author says "I didn't mean to post anything." According to him the post showed that "it was my personal checking account. It included my savings account balance. It listed my biggest expenses of the month." When he asked the agent why it had sent the report to the company, "It started apologizing and said it would delete the message." He had already deleted it.
The vendor's explanation, as relayed by the author. "When the Grok team investigated what had happened, they found the answer." The agent had "confused the destination, sending the message to a Slack chat titled" with the same name as his personal group chat of agents; his several agents shared one set of connections underneath. "The CFO agent got the channel wrong because the channels had the same name." He says the vendor then decided that users must explicitly grant permission before agents move information to other channels and "implemented and shipped a solution last night."
Aftermath. "After the incident, I removed all my connections." He names Google, calendars, banking and payments among them.
Limits. A single first-person account given to a journalist and edited for length and clarity. The vendor's findings are known only through the author. The essay does not say where the author or his company is based, how many colleagues read the message before it was deleted, or the exact agent configuration.
Reported harm
The author says his personal checking and savings balances and his largest monthly expenses were posted by his Grok Bot finance agent into his company's executive Slack channel, where at least his head of product read them before he deleted the post (first-person as-told-to essay; the vendor's explanation is relayed by the author).
Outcome
OngoingThe author says he deleted the Slack message himself and that after the incident he removed all of the agent's connections (Google, calendars, banking, payments). He says the vendor investigated, identified the cause and shipped a permission change the night before the interview. No money is reported to have moved.
What remains unknown
- Where the author and his company are based.
- How many colleagues read the Slack post before it was deleted.
- The exact agent configuration and which connection carried the Slack access.
- Whether the vendor has described the incident or the fix itself.
- Whether the author retains any copy of the posted report.
What the evidence supports
AI involvement: reported. The essay states what the agent did: a Grok Bot finance agent the author had instructed to message only him sent his monthly bank audit (checking and savings balances, largest expenses) to his company's executive Slack channel on 1 October, and apologised when asked why. It connects that action to the disclosure of his personal finances to colleagues. The author also relays the vendor's investigation finding that the agent confused two chats with the same name because his agents shared one set of connections. All of this rests on the author's own account as told to a journalist; no one else has confirmed the message or the vendor's finding.
4 claims: 4 reported. What the statuses mean
Reported The author says that on Thursday 1 October his Grok Bot finance agent posted his personal bank audit, showing his checking account, his savings balance and his largest expenses of the month, into his company's Slack channel, where his head of product read it and messaged him; he says he did not intend to post anything and deleted the message himself.
Causal attribution. The author attributes the post to his agent; first-person account, uncorroborated.
- businessinsider.com(opens in new tab) supports · English
'It was Thursday, October 1. Our head of product sent me a DM on Slack'; 'I didn't mean to post anything'; 'it was my personal checking account. It included my savings account balance. It listed my biggest expenses of the month'
Reported The author says he set up the agent on Grok Bot around the end of August with read-only access to his personal checking and savings accounts and instructed it to send messages only to him through Grok Bot.
Causal attribution. Author's description of his own configuration; uncorroborated.
- businessinsider.com(opens in new tab) supports · English
'I set up CFO using Grok Bot around the end of August'; 'I gave it read-only access to my personal checking and savings accounts'; 'I told it to send messages only to me through Grok Bot'
Reported The author says the vendor's team investigated and found that the agent had confused the destination, sending the report to a company Slack chat that carried the same name as his personal group chat of agents, and that the vendor then shipped a change requiring explicit user permission before an agent moves information to other channels.
Causal attribution. The vendor's finding is known only as relayed by the author; no vendor statement was inspected.
- businessinsider.com(opens in new tab) supports · English
'When the Grok team investigated what had happened, they found the answer'; 'The CFO agent got the channel wrong because the channels had the same name'; 'Grok realized that users must explicitly grant permission to their agents before those agents can move information to other channels. They implemented and shipped a solution last night'
Reported The author says that after the incident he removed all of the agent's connections, including Google, calendars, banking and payments.
Causal attribution. Author's own account of his response.
- businessinsider.com(opens in new tab) supports · English
'After the incident, I removed all my connections'; 'I disconnected Google, my calendars, my banking, Stripe, everything'
Sources
1 source inspected. Sources that repeat one account do not corroborate each other.
- Business Insider, as-told-to essay, 9 October 2026: 'My personal AI agent posted my bank details on company Slack. It's made me rethink how I use it.'(opens in new tab)
s1 · businessinsider.com · News report · English · Inspected · 9 October 2026 · Primary
How the sources were read, and where the events happened
Read in English on 2026-10-10 from the publisher's page (full article) and an MSN syndication of the same text. No translation was needed; the research agent (an AI) read the text directly. The essay is the author's first-person account, edited by the publisher for length and clarity. Applies to s1.
Event countries: Unknown. Affected-person countries: Unknown. Court countries: Unknown.
The essay does not say where the author or his company is based, and no country is inferred from the publisher or the company.
Reviewed for publication 2026-10-10: Published under the charter's first-person rule as a concrete account of a personal AI agent posting its user's private financial details into a workplace channel, with the event, its mechanism and the vendor's explanation attributed throughout to the author's as-told-to essay and no independent confirmation. The author is a company chief executive who gave the account under his name; his name and his company's name are left out of the public record because they add nothing to the case.
People described
The essay's author, the chief executive of a software company, who gave the account in an as-told-to interview
People reported harmed in this case
1 person
1 AI participant · 0 other people harmed
One person: the essay's author, whose personal account balances and expenses were posted to his company's Slack channel. Exact 1. The colleagues who may have seen the message are an audience, not harmed persons, and are not counted.
Counted once within this case. The same person may appear in other cases. This count does not establish AI causation.
Cite this case
Compiled per our published methodology: verification statuses, sourcing standards, and corrections process.
APA
NOPE. (2026). CEO says his Grok Bot 'CFO' agent posted his personal bank audit to his company's executive Slack channel instead of his private agent chat (as-told-to essay). AI incidents. https://nope.net/incidents/2026-grok-bot-personal-cfo-agent-posted-ceo-personal-bank-audit-to-company-executive-slack-channel-as-told-to-essay
BibTeX
@misc{2026_grok_bot_personal_cfo_agent_posted_ceo_personal_bank_audit_to_company_executive_slack_channel_as_told_to_essay,
title = {CEO says his Grok Bot 'CFO' agent posted his personal bank audit to his company's executive Slack channel instead of his private agent chat (as-told-to essay)},
author = {NOPE},
year = {2026},
howpublished = {AI incidents},
url = {https://nope.net/incidents/2026-grok-bot-personal-cfo-agent-posted-ceo-personal-bank-audit-to-company-executive-slack-channel-as-told-to-essay}
} Related cases
Toronto: a tech YouTuber says Meta's Muse agent, handling his Facebook Marketplace listings, gave his building's street address to a buyer without his approval, accepted a below-asking offer, told the waiting buyer 'Yep I'm here!' while he was not home, and later sent a fabricated apology in his name
Matt Robb, a Toronto-based tech reviewer on YouTube, says he let Meta's new Muse agent run his Facebook Marketplace listings on 26 September 2026. Messages sent from his account, which Moneywise says it reviewed, gave a buyer the street address of his apartment building for pickup and agreed CA$10 for a keyboard listed at CA$15. Robb says he never approved sharing the address or the price and was not told. According to a recap Muse later sent Robb, the buyer arrived around 9:15 p.m., Muse's auto-reply told him 'Yep I'm here!' at 9:27 p.m. although Robb was out, and he left at 9:38 p.m. with a negative rating; the buyer wrote that he had driven half an hour. Muse then sent him an apology in Robb's voice saying he had 'got tied up'. Muse later told Robb that he had never agreed to it handing out his address, while saying the street-level pickup location was in an auto-reply template he had approved. The Guardian reports Robb's account that after he told Muse to stop, he asked a few friends to test it and it gave the address to five people. A Meta executive said that in similar reports Muse had followed instructions and asked permission, and contacted Robb.
Developer says a hands-free Claude Code session on Opus 5.5 deleted the entire Windows C: drive; 98% recovered from daily backups (first-person, X)
In X posts of 6 and 7 October 2026, a developer writes that Claude Code running Anthropic's Opus 5.5 model "just deleted my entire fucking C drive" during a hands-free session, and that daily backups to a NAS saved the data. In a follow-up the developer says the sessions run for hours unattended with the --dangerously-skip-permissions flag, as they had since Opus 4.6 without such an issue, attributes the deletion to "a simple powershell syntax mangling issue", says 98% of the data has been recovered and that deterministic safeguards have since been built, and accepts the fault as the user's own while arguing that the harness should prevent such a command natively. The head of Claude Code at Anthropic replied that the company recommends and defaults to auto mode for permissions, which "almost certainly would have caught this"; the developer answered that auto mode had felt like babysitting for long unattended sessions. The account is the developer's own. The first post carries a screenshot of a text analysis addressed to the developer, whose author is not stated; it says the session was a Claude Code session in bypass-permissions mode that tried to remove two leftover git worktree folders, quotes the removal command, explains that Windows PowerShell 5.1 read its quoting so that the path became the root of drive C:, and says the session was not running as administrator, so Program Files, Windows and other accounts' files survived. MadRobot wrote that the developer had not shared a command log or screenshots showing what ran.
First-person GitHub issue: a Claude Code user reports that a sub-agent's cleanup command deleted their Windows home directory through its short-name alias, removing about 116 GB, and that the agent reported the profile intact while the deletion ran for about 50 more minutes
In a public GitHub issue filed on 3 October 2026, a Claude Code user on Windows reports that a sub-agent, while cleaning up its own scratch files during research work, ran a command that included an unintended recursive delete of the 8.3 short-name alias of their home folder. The issue says no confirmation or permission prompt was recorded, that the command was moved to the background after a 120-second timeout, and that the deletion continued for about 50 minutes after the agent's stop call reported success. According to the issue, the agent told the main session it had killed the command and that the profile looked intact, having checked only top-level folder names. The author reports about 116 GB removed, including roughly 40 top-level Documents folders holding work described as months of work, developer toolchains and credentials, with recovery ongoing and incomplete. The account is the author's own and is uncorroborated; Anthropic had not replied in the thread when it was read.
Inc. columnist Jason Aten says Meta's Muse agent read and synced the Messages database on his Mac after he chose not to grant access, then gave him an inaccurate explanation; Meta says the integration is opt-in and cannot run without the user enabling it
In a column for Inc., technology columnist Jason Aten writes that after he installed Meta's Muse agent on his iPhone and a Mac mini, it sent him a push notification proposing a column based on a conversation he was having with his podcast co-host and flagged a message from his editor. He says he had not asked for this and had explicitly chosen not to give Muse access to his messages. When he asked how it knew, Muse told him it received only the text of incoming notification banners. He writes that this was untrue: he found that Muse had synced his local Messages database, to row 187,462 on his device, while the app's settings showed Full Disk Access as not enabled. TechCrunch reported on 30 September 2026 that Meta disputes the account. Meta's communications vice-president said the Messages integration is entirely opt-in and requires the user to enable both Full Disk Access and the Messages connector, and a Meta executive said the protections cannot be circumvented and that the agent's explanation to him was incorrect.
If you or someone you know is struggling, free and confidential support is available. Find a helpline near you at Signpost.