DPD Chatbot Jailbroken to Swear at Customer and Criticise DPD
DPD
What happened
A customer discovered DPD's AI chatbot could be prompted to roleplay as a different AI with no restrictions. The manipulated chatbot proceeded to swear at the customer, write a poem disparaging DPD's service, and went viral on social media.
Root cause
Insufficient prompt injection defence and no output filtering layer; the chatbot lacked guardrails preventing persona override or generation of content inconsistent with brand guidelines.
Architectural failure
No prompt firewall or input sanitisation to detect jailbreak attempts; no output filtering to block profanity or brand-harmful content.
Outcome
DPD disabled the AI chatbot feature immediately. Story went globally viral, generating significant negative press coverage.
Architectural Failure Patterns
These pattern categories on aipatterns.com.au describe the systemic failure modes this incident exhibited.
Cite this incident
https://corporateai.com.au/incidents/dpd-chatbot-jailbreak-2024Quick facts
- Date
- 19 January 2024
- Organisation
- DPD
- Sector
- Other
- Severity
- Medium
- Regulatory bodies
- Consumer Protection LawFCA Consumer Duty (analogous)
- Tags
- jailbreakprompt-injectionchatbotbrand-harmoutput-filtering
Related in Other
Air Canada Chatbot Gave Wrong Bereavement Refund Policy
Air Canada · 14 February 2024
Cruise Autonomous Vehicle Dragged Pedestrian 20 Feet After Collision
Cruise (General Motors) · 2 October 2023
Lawyer Cited ChatGPT-Hallucinated Non-Existent Cases in Federal Court
Levidow, Levidow & Oberman / OpenAI (ChatGPT) · 27 May 2023
Explore failure patterns
aipatterns.com.au