Cryptobriefing Prompt Injection Attacks Surge, Targeting AI Systems in 2025
Article Content
- •Prompt injection attacks affected over 90 organizations in 2025, with significant financial losses.
- •CrowdStrike reported an 89% increase in AI-enabled cyberattacks year-over-year.
- •The EchoLeak vulnerability (CVE-2025-32711) allowed zero-click exploitation of AI systems.
In 2025, over 90 organizations fell victim to prompt injection attacks, exploiting vulnerabilities in large language models (LLMs). CrowdStrike's 2026 Global Threat Report indicates that AI-enabled cyberattacks surged by 89% year-over-year, with attackers stealing credentials and cryptocurrency. Notably, a single incident drained $175,000 from an AI-controlled crypto wallet using a Morse-code-encoded prompt. The OWASP LLM Top 10 ranked prompt injection as the most critical vulnerability for LLM applications. Significant incidents include the EchoLeak vulnerability (CVE-2025-32711) disclosed in June 2025, allowing zero-click exploitation of Microsoft 365 Copilot. These attacks highlight a growing trend where attackers manipulate AI systems through crafted inputs. Organizations deploying AI must address these vulnerabilities to mitigate risks effectively.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (12)
Following this threat?
Track Microsoft and CVE-2025-32711 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Enterprises Struggle with AI Governance Amid Rising Shadow AI Usage As AI adoption accelerates, only 18% of enterprises maintain a complete AI inventory, according to IBM. Netskope found that 47% of enterprise GenAI users are still utilizing personal AI applications, leading to significant visibility gaps for security teams. The rapid spread of shadow AI complicates governance, as…
Ransomware Data Theft Increases 275% Amid Falling Payments The Zscaler ThreatLabz 2026 Ransomware Report reveals a staggering 275.8% increase in data theft by the top ten ransomware groups, escalating from 123.8 terabytes to 896.2 terabytes year-over-year. Despite this surge, ransom payments have decreased by 15.8% to $327.8 million, indicating a shift in strategy where…