So in their malicious prompt, they requested that a list of internal customer leads and their email addresses be sent to that domain, which in a real attack ... can track all kinds of data in notes ...