Prompt Injection Attacks Surge, Targeting AI Systems in 2025

Prompt Injection Attacks Surge, Targeting AI Systems in 2025

First seen 28 Jun 2026, 20:32 UTC VenturebeatCryptobriefingpromptarmor.substack.com 81% similarity 67.5
Share:

Article Content

Browse articles
ThreatCluster

In 2025, over 90 organizations fell victim to prompt injection attacks, exploiting vulnerabilities in large language models (LLMs). CrowdStrike's 2026 Global Threat Report indicates that AI-enabled cyberattacks surged by 89% year-over-year, with attackers stealing credentials and cryptocurrency. Notably, a single incident drained $175,000 from an AI-controlled crypto wallet using a Morse-code-encoded prompt. The OWASP LLM Top 10 ranked prompt injection as the most critical vulnerability for LLM applications. Significant incidents include the EchoLeak vulnerability (CVE-2025-32711) disclosed in June 2025, allowing zero-click exploitation of Microsoft 365 Copilot. These attacks highlight a growing trend where attackers manipulate AI systems through crafted inputs. Organizations deploying AI must address these vulnerabilities to mitigate risks effectively.

Key Points: • Prompt injection attacks affected over 90 organizations in 2025, with significant financial losses. • CrowdStrike reported an 89% increase in AI-enabled cyberattacks year-over-year. • The EchoLeak vulnerability (CVE-2025-32711) allowed zero-click exploitation of AI systems.

ThreatCluster AI

Timeline

2025-02-24
CrowdStrike report reveals prompt injection attacks
The report documented prompt injection attacks targeting over 90 organizations, emphasizing the rising threat to AI systems.
Cryptobriefing
2025-06-11
CVE-2025-32711 published
The first documented zero-click prompt injection exploit against Microsoft 365 Copilot was published, highlighting significant vulnerabilities in AI systems.
Venturebeat
2025-06-28
First public PoC for CVE-2025-32711
A proof of concept was released for the EchoLeak vulnerability, demonstrating its exploitation potential.
Venturebeat
2026-05-01
AI-controlled crypto wallet drained
An AI-controlled cryptocurrency wallet lost $175,000 due to a prompt injection attack using Morse code.
Cryptobriefing
Recent
AI-enabled attacks increase
CrowdStrike noted an 89% increase in AI-enabled attacks, with attackers moving laterally in compromised networks in under 30 minutes.
Cryptobriefing

Community

Browse all →