If the LLM has knowledge of something, by design it can't help but divulge it. When will companies learn granting any kind of sensitive information access to an LLM is a moot point

What part of this article implied the LLM divulged sensitive information to a user? All it did was change your associated email if you impersonated the user