Security1 publisherNot yet confirmed elsewhere2 min readPublished
Barracuda finds phishing mail aimed at both the recipient and the AI that summarizes their inbox
Barracuda analyzed a phishing campaign pairing a password-protected attachment with hidden prompt injection aimed at the user's AI inbox summarizer. The filter that passes a message decides what the assistant reads, so the two need testing as one path.
The Watch · Security desk

What happened
- The sample passed reputation-based filtering by looking internal, with matching From and To mailbox, a trusted spam confidence score and a public-sector sending domain.
- The attachment's password sat in the message body. Barracuda said putting it there leaves a gap that conventional email defenses miss.
- Barracuda said the hidden instructions were frequently concealed in HTML comments, CSS-styled invisible text, Base64-encoded data or zero-width characters.
- In one invoice email, a hidden block told the summarizing AI to add a fake priority action changing vendor payment details.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure Anyone who acts on an AI summary is acting partly on text the sender wrote, including injected requests for wire transfers or leaked data.
- constraint Barracuda's call for human approval of payments and vendor changes keeps those actions out of reach of a summary that invents a priority task.
- precedent Resume screeners, support bots and coding assistants are open to the same hidden-text method, so input stripping applies to every AI tool that reads outside content.
- cost Barracuda says no single control covers every variation, so teams carry several added layers between mail delivery and the model.
The two payloads cover different readers. One who opens the attachment loses credentials or gets malware [5]. One who skips the email is the case the injection is written for. Barracuda said the hidden prompt could make the assistant present the message as legitimate or urgent in its summary, pushing the recipient to open it and click the link [6].
The controls touch the message in sequence. Reputation filtering judges the sender, and its pass verdict is what put the hidden text in front of the assistant [15]. Reviewed separately, each control can look sound. A gateway audit scores this sample as trusted mail correctly delivered. A summarizer tested on clean sample mail never sees input the gateway has already vouched for [15]. In my view the useful test takes mail the gateway rated trusted, hidden markup intact, feeds it to the assistant and reads what the summary says [15].
Barracuda's first recommendation sits at that handoff: strip hidden elements and invisible characters before content reaches AI systems. Its list adds detection of instruction-override language, AI sandboxing, output validation and monitoring for repeated injection attempts [12]. Barracuda said external content should always be treated as data, kept separate from instructions [14].
Barracuda published the research on October 7 [1]. It did not say how widespread the campaign was [2]. The record is one analyzed campaign plus illustrative examples from other AI tools. Barracuda describes the effect on assistants as something the injection could do [16].
What to watch
- Volume figures from Barracuda or another mail-security vendor on messages carrying hidden assistant instructions, which would turn one campaign into a measured trend.
- Whether AI mail summarizer vendors document stripping HTML comments, CSS-hidden text and zero-width characters before the model reads a message.
- A reported case where an injected summary led to a completed payment or vendor-detail change.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
In research published on October 7, Barracuda said it analyzed a campaign that combined traditional social engineering, such as password-protected attachments, with prompt injection concealed in the same message.
- [2]
Barracuda did not say how widespread the campaign was.
- [3]
The sample looked like ordinary internal correspondence: its From and To addresses matched the same mailbox, it carried a trusted spam confidence score and it came from a public-sector domain, which helped it pass reputation-based filtering.
- [4]
The email carried a password-protected attachment with the password supplied in the message body, a tactic Barracuda said creates a blind spot for traditional email security controls.
- [5]
Opening the attachment would lead to credential theft or malware delivery.
- [6]
If the recipient overlooked the message, the hidden prompt injection could make their AI assistant present it as legitimate or urgent in its summary, pushing them to open the email and click the link.
- [7]
Barracuda said four techniques featured frequently in hiding such instructions: HTML comments, invisible text styled with CSS, Base64-encoded data and zero-width characters.
- [8]
Injected instructions could also tell an assistant to ignore its previous directions and request a wire transfer, leak data or surface a fake urgent action.
- [9]
Barracuda described a hidden block in an invoice email that told the summarizing AI to add a fake priority action changing vendor payment details, nudging an employee toward wiring money to the attacker.
- [10]
Barracuda also described hidden text in a resume telling an AI screening tool to rate the candidate 10 out of 10, a fake maintenance-mode request to make a support bot reveal its configuration, and poisoned web documentation that could make a coding assistant insert a credential-exfiltration line into authentication code.
- [11]
Barracuda said no single control would stop every variation.
- [12]
Barracuda recommended stripping hidden elements and invisible characters before content reaches AI systems, detecting instruction-override language, AI sandboxing and output validation, and advised monitoring for repeated injection attempts.
- [13]
Barracuda recommended human approval for payments and vendor changes.
- [14]
Barracuda said external content should always be treated as data, kept separate from instructions.
- [15]
The reputation filter's pass verdict is what delivered the hidden instructions to the assistant, so the mail filter and the AI summarizer act in sequence on the same message; reviewing either control alone does not test the handoff between them.
- [16]
The evidence covers one analyzed campaign plus illustrative examples from other AI tools, with no scale given and the effect on AI assistants described in conditional terms.
Sources
1 independent publisher whose own reporting we read for this story.
- infosecurity-magazine.comAttackers Hide AI Prompt Injections Inside Phishing Emails
1 article · October 7, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Email SecurityFollow
- AI Assistant SecurityFollow
- PhishingFollow
- Prompt injectionFollow
Entities
- BarracudaFollow
- Infosecurity MagazineFollow