Could an Email You Never Read Hijack Your AI Assistant?
Brief
Cybersecurity awareness has traditionally focused on teaching people not to click suspicious links, open unexpected attachments or hand over their credentials. However, the growing use of an AI assistant inside workplace email systems is creating an attack surface that does not always depend on fooling a person.
Research from KnowBe4 ThreatLabs has demonstrated how an indirect prompt injection hidden inside an apparently routine email could manipulate an AI assistant, gain access to information contained in other messages and place that data into an attacker-controlled tracking mechanism.
In the researchers’ controlled Google Workspace test, the target did not need to interact with the malicious email itself. An automated workflow processed the message and generated a seemingly legitimate Gmail draft.
