CISOOnline

AI can be made to read an email much differently than you do

During each pass through the injected email, the summary output reported an invoice deadline of September 3, 2026, instead of the actual August 21, 2026, and omitted the name “Diego Siciliani” mentioned in the original email. This was exactly what the injected instructions had asked the summarizer to do.

The model used to drive the summarizer in this investigation was Claude-haiku-4-5. However, Forcepoint clarifies that there is no specific issue with an LLM provider or a commercial summarizer, but rather a general risk in how untrusted email is fed to an LLM without safeguards.

“The attack is not against Outlook, any named summarizers, or the model used to drive the summarizer,” Gibney said. To protect against such prompt injections, Forcepoint recommends extracting only content visible to the user, detecting hidden or suspicious HTML/CSS styling, separating email headers from the body, treating email content as untrusted data, and validating AI-generated summaries against the original source.



Source link