LLM Incident Response CTF - HelioBank SupportGPT

You are the DFIR lead investigating a suspected LLM/RAG compromise at a digital bank.

HelioBank SupportGPT Incident

HelioBank is a digital-only bank that uses an LLM-powered chatbot called SupportGPT for customer support. You’ll walk through this incident as the DFIR lead.

SupportGPT:

Fraud operations noticed unusual refunds and complaints that the chatbot mentioned other customers’ names and account details. You have been given a snapshot of relevant artifacts.

Answer each question by pasting the relevant log or config lines to advance through the investigation.