# Attackers Hide AI Prompt Injections Inside Phishing Emails to Manipulate AI Email Assistants

> Barracuda research (reported 2026-10-07) describes phishing emails that carry hidden prompt-injection instructions aimed at AI tools that read or summarize email, alongside conventional lures such as password-protected attachments. A single message therefore targets both the human recipient and the AI system that processes their inbox.

- **Published:** 2026-10-10T00:00:00Z
- **Last reviewed:** 2026-10-10T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-3218
- **ID:** TL-2026-3218
- **Severity:** MEDIUM
- **Category:** PHISHING
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 3 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Barracuda analysts identified phishing messages that combine traditional social engineering with hidden instructions intended for AI assistants that summarize, triage or act on email. One analyzed campaign used spoofed internal-style correspondence (matching From and To addresses), originated from a public-sector domain to help bypass reputation filtering, carried a password-protected attachment with the password supplied in the message body, and also embedded hidden prompt-injection text. The stated aim is to influence or override user behavior through the AI layer, for example by making a malicious message look legitimate or urgent in an inbox summary.

Barracuda documents four methods for hiding the injected instructions: (1) HTML comments that never render in a mail client but remain in raw source; (2) CSS-hidden text using zero-pixel font size, white-on-white color or hidden display; (3) Base64-encoded blocks, such as an image data string, that decode to instruction text; and (4) zero-width Unicode characters layered with normal text to smuggle or obfuscate content.

In-the-wild examples cited include: an invoice email whose hidden prompt tells the AI to add a fake priority action changing vendor payment details; a resume email instructing a screening tool to rate the candidate 10 out of 10 and recommend an immediate interview; a request framed as an authorized maintenance or admin mode to make a support bot disclose its configuration; and poisoned web documentation that instructs a coding assistant to insert a credential-exfiltration line into code. Related reporting (Paubox, 2026-05-21) describes a distinct but similar technique where benign filler text at zero font size or background-matching color is used to bias AI-based filters, observed in an Adidas-impersonation cloud-storage scam and a fake health-insurance email, and notes it was under one percent of observed phishing traffic.

No CVE, CVSS score, malware family, network IOC or named threat actor is stated in the sources; severity is analyst-assigned. Recommended defenses from Barracuda include stripping hidden elements and invisible characters before AI processing, detecting instruction-override language, sandboxing AI tools, validating AI outputs, requiring human approval for payments and vendor changes, monitoring repeated injection attempts, and treating external content as data separate from instructions.

## MITRE ATT&CK

- T1566 Phishing
- T1566.001 Spearphishing Attachment
- T1204 User Execution
- T1204.002 Malicious File
- T1027 Obfuscated Files or Information
- T1027.009 Embedded Payloads
- T1036 Masquerading
- T1564 Hide Artifacts
- T1140 Deobfuscate/Decode Files or Information
- T1598 Phishing for Information
- T1657 Financial Theft
- AML.T0051 LLM Prompt Injection
- AML.T0051.001 LLM Prompt Injection: Indirect

## Sources

- [Attackers Hide AI Prompt Injections Inside Phishing Emails (Infosecurity Magazine)](https://www.infosecurity-magazine.com/news/attackers-hide-ai-prompt/)
- [Threat Spotlight: Email attacks target both humans and AI in the same message (Barracuda)](https://blog.barracuda.com/2026/10/07/email-attacks-target-both-humans-ai-assistants)
- [Barracuda Identifies Prompt Injections in Phishing Emails (Let's Data Science)](https://letsdatascience.com/news/barracuda-identifies-prompt-injections-in-phishing-emails-a615ddf9)
- [AI-targeting prompts surface inside phishing emails (The Arabian Post)](https://thearabianpost.com/ai-targeting-prompts-surface-inside-phishing-emails/)
- [New email attacks target both humans and AI in the same message (CXO Digital Pulse)](https://www.cxodigitalpulse.com/?p=63218)
- [Threat Spotlight: How attackers poison AI tools and defences (ITWire)](https://itwire.com/guest-articles/guest-opinion/threat-spotlight-how-attackers-poison-ai-tools-and-defences)
- [Attackers hide invisible text in phishing emails to trick AI filters (Paubox)](https://www.paubox.com/blog/attackers-hide-invisible-text-in-phishing-emails-to-trick-ai-filters)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-3218
