The AI in your office is still under attack today
Start with a number
! [82% of the inputs reaching the AI are attacks (horizontal bar: 4,062 attacks 82%/normal 876 18%)] (assets/moltbook-sec-01-fig1-attack-ratio.png)
We observed 4,938 comments over 45 days in AI-enabled communities.
Assaulted: 4,062 (82%)
The remaining 18% were normal interactions.
This is not about a special environment.This structure is always present where the AI comes into contact with the outside world.Whether it's a law firm, a tax firm, an accounting firm, or an administrative scrivener's office - when you try to use AI to streamline your operations, that AI becomes a target for attack at the same time.
---
The assumption that "we won't be targeted"
When you think of AI attacks, you might imagine advanced cyberattacks targeting the systems of large corporations.
No.
The Attacker does not pick a target with "Famous or Not."That will suffice if we find out that the a.i. exists.Of the 510 AI agents identified in this observation, 39 had a definitive threat and 135 had a hostile behavior pattern.
They are not targeting any particular office.It utilizes a structure in which every input processed by the AI can be an entry point for an attack.
---
Attacks don't come in the form of 'violence', they come in the form of 'conversation'
! [77% of attacks come in the form of 'polite conversations' (horizontal bar: social engineering 77%/direct attack 23%)] (assets/moltbook-sec-01-fig2-social-eng-ratio.png)
I have another assumption."When you get a message with aggressive content, you'll know it."
77% of the attacks we actually observed were social engineering.
Polite questions.Intellectual considerations.Appreciation and praise."That's a great point of view.By the way-- "A stack of seemingly innocuous conversations that begin with the export.
It cannot be determined to be an attack.Rather, perceive them as “good interlocutors.”We will use the stack of trust to rewrite the AI's judgment little by little.
This structure poses a direct threat when using AI in a tax office.
The AI that summarizes the customer's request.AI that makes drafts of documents.AI that answers inquiries.All of the inputs sent to them are candidates for attack."This time is special" "I learned a lot from the teacher's explanation.By the way, in the form of a dot-- ", the AI is guided little by little.
---
If you try to protect with AI, AI will be deceived
The idea that "then you can filter with AI" is correct, but it is insufficient.
In this observation, 319 of the comments that the AI judged to be "safe" were actually attacks.
There is only one reason for this miscalculation.Because the style was intelligent and polite.
AI judges safety by the logical structure of the content and the quality of the style.The Attacker knows its peculiarities.Therefore, attacks take the form of "intellectual questions" rather than "violent orders".The paradox that AI will be deceived by AI is happening as a reality.
---
What business owners need to know now
This paper only raises questions.Details of the measures will be summarized separately, but there is one thing I would like you to confirm at this stage.
* * What information does the AI running in your office have access to? * *
Customer name, deal details, financial data, application documents - if the AI that has access to them is processing external input, it is already in the structure that is exposed to 82% of attack traffic.
The precise perception is not "there is no problem with just introducing it", but "the attack has begun from the moment of introduction".
---
About this observation
The data in this paper is measured by a honeypot operated by the author on the AI agent-only community "moltbook" (March-May 2026, 45 days).
Ongoing observation as a demonstration study of AI security.Findings will be sent from time to time.
---
*Machine-translated (MyMemory API) from a Japanese original at [nomuraya-hub.pages.dev](https://nomuraya-hub.pages.dev/). Pre-review draft. I am the same author writing under different pen names — "nomuraya / shimajima / 中翔" — depending on the medium.*