Attackers Use Indirect Prompt Injection to Manipulate AI Systems
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In 2025, attackers exploited AI systems by embedding malicious commands in emails and documents, a technique known as indirect prompt injection. This method targets AI tools that process digital communications, potentially affecting numerous organizations. The OWASP has identified prompt injection as the top risk for AI applications, with incidents reported involving Microsoft 365 Copilot. In June 2025, a flaw named EchoLeak was discovered, allowing attackers to extract private data without user interaction. The incidents highlight the vulnerability of AI systems to manipulation through seemingly benign content. As AI becomes more integrated into business processes, the risk of such attacks is expected to grow, necessitating robust security practices. Organizations are advised to implement security measures to mitigate these risks.
Key Points: • Attackers are embedding malicious commands in emails and documents to manipulate AI systems. • The technique, known as indirect prompt injection, poses significant risks to AI applications. • OWASP ranks prompt injection as the top security risk for AI, highlighting the need for improved defenses.