Attackers Hide AI Prompt Injections Inside Phishing Emails

Written by

Phishing emails have been found carrying hidden instructions for AI assistants alongside conventional lures for the human recipient, meaning that a single message targets both the user and the system that summarizes their inbox.

In research published on October 7, Barracuda said it analyzed a campaign that combined traditional social engineering, such as password-protected attachments, with prompt injection concealed in the same message. It did not say how widespread the campaign was.

The sample looked like ordinary internal correspondence. Its "From" and "To" addresses matched the same mailbox, it carried a trusted spam confidence score and it came from a public-sector domain, which helped it pass reputation-based filtering.

One Email, Two Targets

For the human, the email carried a password-protected attachment with the password supplied in the message body, a tactic Barracuda said creates a blind spot for traditional email security controls. Opening it would lead to credential theft or malware delivery.

If the recipient overlooked the message, the hidden prompt injection could make their AI assistant present it as legitimate or urgent in its summary, pushing them to open the email and click the link.

Read more on indirect prompt injection: Indirect Prompt Injection in Web Content Targets AI Agents

Barracuda said four techniques featured frequently in hiding such instructions: HTML comments, invisible text styled with CSS, Base64-encoded data and zero-width characters.

Injected instructions could also tell an assistant to ignore its previous directions and request a wire transfer, leak data or surface a fake urgent action.

Wider Targets Call For Layered Defenses

Among real-world examples, Barracuda described a hidden block in an invoice email that told the summarizing AI to add a fake priority action changing vendor payment details, nudging an employee toward wiring money to the attacker.

It also described hidden text in a resume telling an AI screening tool to rate the candidate 10 out of 10, a fake maintenance-mode request to make a support bot reveal its configuration and poisoned web documentation that could make a coding assistant insert a credential-exfiltration line into authentication code.

Barracuda said no single control would stop every variation. It recommended stripping hidden elements and invisible characters before content reaches AI systems, detecting instruction-override language, AI sandboxing, output validation and human approval for payments and vendor changes. It also advised monitoring for repeated injection attempts.

It said external content should always be treated as data, kept separate from instructions.

What’s Hot on Infosecurity Magazine?