Hackers Embed Hidden Commands in Emails to Exploit AI Systems

Cybercriminals are increasingly embedding concealed instructions within emails, documents, calendar invites, and online advertisements to manipulate artificial intelligence (AI) systems that process digital communications. This technique, known as indirect prompt injection, targets AI tools responsible for scanning and summarizing content, potentially leading to unauthorized actions or data exposure.

Unlike direct prompt attacks, where malicious commands are input directly into AI interfaces, indirect prompt injection involves embedding hidden instructions within seemingly benign content. For instance, an email may appear normal to a human recipient but contain invisible text that an AI mail agent interprets as commands. This method can also be applied to attachments like PDFs and DOCX files, which, while appearing standard, carry embedded prompts designed to influence AI scanning agents.

Security researchers have observed discussions and sales activities related to these methods in underground forums, indicating that cybercriminals are developing tools to generate hidden prompts at scale. Although widespread real-world exploitation has not yet been documented, the emergence of these tools suggests a growing threat. Subscriptions for such tools are reportedly being advertised in criminal spaces, starting at approximately $150 per month.

The risk associated with indirect prompt injection varies based on the permissions granted to the AI system. An AI agent capable of summarizing messages poses a different threat level compared to one that can search files, send content, open links, or connect to cloud services. Hidden instructions become particularly dangerous when AI tools can act autonomously without explicit human approval.

To mitigate these risks, security teams should treat all external content as untrusted, regardless of its format. Implementing measures such as separating untrusted text from system instructions, limiting AI agents’ access, and requiring human confirmation for significant actions can help prevent concealed commands from causing harm.

Additionally, cybercriminals are developing prompt-injection generators for calendar invitations. Malicious instructions can be embedded within event descriptions disguised as meeting agendas, allowing AI assistants that summarize calendar content to process them without the recipient’s interaction. This evolution represents a shift from traditional calendar phishing, which typically relied on user engagement with invites or linked pages.

As AI systems become more integrated into digital workflows, the potential for their exploitation through indirect prompt injection grows. Organizations must proactively adapt their security strategies to address these emerging threats, ensuring that AI tools are equipped to handle and neutralize such sophisticated attacks.