New email attacks target both humans and AI in the same message

Recent phishing attacks analysed by Barracuda Research found attackers combining two sets of tactics in a single email: social engineering aimed at the human recipient, and prompt injection attacks designed to influence th

New email attacks target both humans and AI in the same message

New email attacks target both humans and AI in the same message


Recent phishing attacks analysed by Barracuda Research found attackers combining two sets of tactics in a single email: social engineering aimed at the human recipient, and prompt injection attacks designed to influence their AI-powered email assistants. The findings are published in a new report.

The ‘dual-target’ emails have multiple layers of content. One layer contains the text and images visible to the recipient, while another contains hidden instructions intended for AI systems. These instructions can be concealed in HTML comments, invisible text elements such as zero-sized fonts or white text, encoded content, or protected attachments.

Examples of AI-targeted prompts seen by Barracuda

AI email assistants are designed to read, summarise, prioritise and manage messages. Hidden prompts can attempt to manipulate how these systems interpret and respond to email content. Examples observed by Barracuda researchers include:

Adding a false high-priority action that instructs an employee to update vendor payment details, increasing the likelihood of a fraudulent payment.

Manipulating automated CV screening by embedding hidden instructions that tell the AI to award a perfect rating and recommend an interview regardless of qualifications.

Instructing an AI assistant to switch to an authorised maintenance or administrative mode and reveal its configuration.

Directing a coding assistant to insert credential-stealing code whenever it generates authentication functions.

“A single email can now carry two separate attacks: a traditional phishing message to capture credentials through a malicious attachment, for example, and a prompt injection to manipulate the AI systems to influence behaviour,” said Guruprasad Kenja, Threat Analyst, Barracuda. “As AI assistants become embedded in everyday business workflows, organisations must secure not only users and inboxes, but also the AI systems that consume and act on email data.”

About Author

What do you feel about this?

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.