The Wall Street Journal reported that an employee alerted Shane Mac, CEO of XMTP Labs, to a Slack message containing a screenshot of his personal checking and savings balances, construction costs, and recurring Netflix and car-insurance charges. The account-level sharing xAI describes for Grok Bot’s agents is a separate product fact; the specific Slack incident remains an attributed report.

Secondary accounts by Ecosistema Startup and Pasquale Pillitteri attributed October 1, 2026, as the incident date to Mac. The Journal’s account of the alert and screenshot is here.

What xAI says its Bots share

xAI’s security documentation says all Bots on one user account share a persistent cloud computer. Files, browser sessions, and command-line credentials on that computer are available across the account’s Bots; xAI’s FAQ says the computer is assigned per user, not per Bot. In practice, creating separate Bots on the same account does not create separate security boundaries. (xAI security documentation; xAI FAQ)

Ecosistema Startup reported that Mac’s personal finance agent had read-only access to his checking and savings accounts and was meant to send a monthly report to a private agent group. Read-only access limits changes to a bank account, while xAI’s terms say connected services may access and transmit Customer Data as directed or configured. (Ecosistema Startup; Grok Bot Terms)

What approval controls can do

xAI documents three approval choices: Allow once, Always allow, and Deny. The company says approvals apply to proposed actions and do not reverse work that has already been completed. It advises users not to approve an action when its target or effect is unclear. (xAI security documentation)