Aide Exposed Sensitive Data Through AI Tool

A security lapse involving a UAE-based messaging service and an unencrypted GitHub repository left private communications accessible.

Updated on Sept. 27, 2026 in Artificial Intelligence

Bold flat-color editorial illustration of a lone server rack, symbolizing the vulnerability of data infrastructure.
A security breach involving government aide Jonatan Urich exposed sensitive data through an unencrypted AI tool and insecure third-party messaging services. AI Illustration. Upload story photo >

Live Poll

Do you trust that your private messages remain secure when using third-party messaging services?

Jonatan Urich, an aide to Prime Minister Benjamin Netanyahu, utilized a UAE-based third-party service called Ultramsg for WhatsApp messaging, which under local law grants the Emirati government access to stored data. Simultaneously, Urich publicly exposed sensitive information by uploading an unencrypted artificial intelligence monitoring tool to the code-sharing site GitHub.

Why it matters

The incident demonstrates the risks inherent in using third-party services that operate under different jurisdictional data-sharing laws. It further highlights how the rapid deployment of custom artificial intelligence tools can create critical security vulnerabilities when proper encryption and data governance are ignored.

The monitoring tool, built using Anthropic's Claude engine, scanned 50 news sources every 90 seconds to automate media tracking. The entire codebase was hosted on a public GitHub repository without encryption, leaving it visible to unauthorized users.

The players

Jonatan Urich

An aide to Prime Minister Benjamin Netanyahu who developed an automated media monitoring tool.

Benjamin Netanyahu

The Prime Minister of Israel who employs Jonatan Urich as an aide.

Ultramsg

A United Arab Emirates-based third-party service provider used for managing WhatsApp messaging integrations.

Anthropic

The research lab and developer of the Claude artificial intelligence engine used in Urich's monitoring tool.

The details

The AI system functioned by querying news feeds and processing the text through the Claude engine to extract relevant updates. By relying on Ultramsg—a third-party intermediary for managing WhatsApp messaging traffic—the operator bypassed local data protections. The vulnerability was compounded when the source code, which handled these data flows, was pushed to GitHub in an unencrypted state.

Timeline

  1. September 27, 2026: A report was published detailing the access to WhatsApp messages and the security flaw.

The Tech Race

This incident follows a broader trend where automated AI agents are integrated into sensitive workflows without rigorous security auditing. It illustrates the competitive gap between rapid feature deployment and the slow adoption of secure, enterprise-grade data management practices.

Users of third-party API services should verify the legal jurisdiction where data is processed, as local laws may grant authorities broad access. Security teams must ensure that AI deployment pipelines exclude sensitive authentication tokens or database keys from public code repositories like GitHub.

The takeaway

Individuals and organizations must treat third-party messaging integrations as high-risk vectors for data exposure. Watch for potential regulatory updates regarding the use of international SaaS providers by high-level government staff.

Further reading

Learn more about the current landscape of AI safety and security research in Artificial Intelligence.

Live Poll

Do you trust that your private messages remain secure when using third-party messaging services?