Barracuda: Phishing Emails Hide AI Prompt Injections for Assistants
Barracuda detailed a campaign in which phishing emails carry hidden instructions for AI assistants that summarize inboxes alongside conventional lures. The human sees a password-protected attachment, while the AI receives a prompt injection pushing it to flag the message as urgent and legitimate.
- Hidden instructions use HTML comments, invisible CSS text, Base64 and zero-width characters
- The email mimics internal correspondence and passes reputation-based filtering
- One example: an invoice injection alters vendor payment details to trigger a wire transfer
- Barracuda advises stripping hidden elements and validating AI output
Read next
Security