ATTACKERS are hiding prompts instructing AI assistants inside phishing emails, in addition to traditional lures aimed at human recipients. Barracuda’s 7 October 2026 analysis describes campaigns that combine social engineering—such as password-protected attachments—with prompt injections concealed within the same messages. The emails appeared as ordinary internal correspondence, with From/To fields matching the same mailbox and a public-sector domain helping them bypass some reputation checks.
When opened, the password-protected attachment could enable credential theft or malware delivery; if overlooked, the concealed prompt could cause an AI summariser to treat the message as legitimate and surface it as urgent in its summary, nudging the user toward clicking a link or acting on a bogus instruction.
Barracuda notes four common techniques for hiding instructions: HTML comments, invisible text styled with CSS, Base64-encoded data, and zero-width characters. In real-world examples, a fake invoice email allegedly directed a summarising AI to add a high-priority action that modified vendor payment details, potentially prompting a wire transfer to the attacker.
Other instances included hidden prompts in a resume to skew an AI screening tool’s scoring, or a maintenance-mode request that could expose a tool’s configuration. The report emphasises that no single control will stop every variant; organisations should strip hidden elements before content reaches AI systems, detect instruction-override language, deploy AI sandboxing and output validation, and require human approval for payments or vendor changes. Monitoring for repeated injection attempts and treating external content strictly as data are also advised.