Security News

Phishing Emails Now Target Your AI Assistant as Well as You

Infosecurity Magazine · 7 Oct 2026
Key Takeaway Do not rely on an AI assistant's summary to judge whether an email is safe or urgent, and verify any payment change or password-protected attachment through a separate, trusted channel.

Barracuda has described a phishing campaign that aims at two targets in one message: the human reader and the AI assistant that summarises their inbox. In research published on October 7, the company said it analysed a campaign combining traditional social engineering, such as password-protected attachments, with prompt injection hidden in the same email. It did not say how widespread the campaign was.

The sample looked like ordinary internal correspondence. The "From" and "To" addresses matched the same mailbox, it carried a trusted spam confidence score and it came from a public-sector domain, all of which helped it pass reputation-based filtering. The password for the attachment was supplied in the message body, which Barracuda said creates a blind spot for traditional email security controls. Opening it would lead to credential theft or malware delivery. If the recipient overlooked the email, the hidden instructions could make their AI assistant describe it as legitimate or urgent, nudging them to open it and click the link.

Barracuda said four techniques were frequently used to hide such instructions: HTML comments, invisible text styled with CSS, Base64-encoded data and zero-width characters. Injected instructions could tell an assistant to ignore its previous directions, request a wire transfer, leak data or surface a fake urgent action. Examples included an invoice email telling a summarising AI to add a fake priority action changing vendor payment details, and a resume with hidden text telling an AI screening tool to rate the candidate 10 out of 10.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from Infosecurity Magazine, written with Claude Sonnet 5.5. We link back to every original so you can read it yourself.