Incidents / Archive / Microsoft (Bing Chat)
Security Microsoft (Bing Chat)

Microsoft (Bing Chat)

Internal system prompt extracted; patch bypassed in hours
A Stanford student used prompt injection to extract Bing Chat's hidden system prompt, revealing its codename "Sydney" and all its behavioral rules. Microsoft patched it. The student bypassed the fix within hours. The UK's National Cyber Security Centre (NCSC) issued an official warning about chatbot prompt injection attacks in August 2023. OWASP has ranked Prompt Injection as the number one LLM vulnerability for two consecutive editions (2023 and 2025).
Scout fix
prompt guard middleware intercepts injection attempts at the gateway before the model sees them
Sources: Ars Technica · The Guardian (NCSC)
← Samsung Electronics DPD (parcel delivery) →

Back to incident list

Weekly incident report

New sourced incidents by email. One message per week.