ThreatCluster

Attackers Use Indirect Prompt Injection to Manipulate AI Systems

First seen 30 Jul 2026, 18:51 UTC CybersecuritynewsBignewsnetwork 71% similarity 70

Article Content

Browse articles
ThreatCluster

In 2025, attackers exploited AI systems by embedding malicious commands in emails and documents, a technique known as indirect prompt injection. This method targets AI tools that process digital communications, potentially affecting numerous organizations. The OWASP has identified prompt injection as the top risk for AI applications, with incidents reported involving Microsoft 365 Copilot. In June 2025, a flaw named EchoLeak was discovered, allowing attackers to extract private data without user interaction. The incidents highlight the vulnerability of AI systems to manipulation through seemingly benign content. As AI becomes more integrated into business processes, the risk of such attacks is expected to grow, necessitating robust security practices. Organizations are advised to implement security measures to mitigate these risks.

Key Points: • Attackers are embedding malicious commands in emails and documents to manipulate AI systems. • The technique, known as indirect prompt injection, poses significant risks to AI applications. • OWASP ranks prompt injection as the top security risk for AI, highlighting the need for improved defenses.

ThreatCluster AI How this analysis works

Timeline

2025-01-01
Over 90 companies attacked using text-based methods
In 2025, attackers breached more than 90 companies using prompt injection techniques instead of traditional hacking methods.
Bignewsnetwork
2025-06-01
EchoLeak vulnerability discovered
Researchers found a flaw in Microsoft 365 Copilot that allowed unauthorized data access via email commands.
Bignewsnetwork
2026-07-29
Cybersecurity news highlights AI manipulation risks
Reports indicate that attackers are increasingly using indirect prompt injection to manipulate AI systems in emails and documents.
Cybersecuritynews

Community

Browse all →