Recent phishing attacks analysed by Barracuda Research found attackers combining two sets of tactics in a single email: social engineering aimed at the human recipient, and prompt injection attacks designed to influence their AI-powered email assistants. The findings are published in a new report.
The ‘dual-target’ emails have multiple layers of content. One layer contains the text and images visible to the recipient, while another contains hidden instructions intended for AI systems. These instructions can be concealed in HTML comments, invisible text elements such as zero-sized fonts or white text, encoded content, or protected attachments.
Examples of AI-targeted prompts seen by Barracuda
AI email assistants are designed to read, summarise, prioritise and manage messages. Hidden prompts can attempt to manipulate how these systems interpret and respond to email content. Examples observed by Barracuda researchers include:
Adding a false high-priority action that instructs an employee to update vendor payment details, increasing the likelihood of a fraudulent payment.
Manipulating automated CV screening by embedding hidden instructions that tell the AI to award a perfect rating and recommend an interview regardless of qualifications.
Instructing an AI assistant to switch to an authorised maintenance or administrative mode and reveal its configuration.
Directing a coding assistant to insert credential-stealing code whenever it generates authentication functions.
“A single email can now carry two separate attacks: a traditional phishing message to capture credentials through a malicious attachment, for example, and a prompt injection to manipulate the AI systems to influence behaviour,” said Guruprasad Kenja, Threat Analyst, Barracuda. “As AI assistants become embedded in everyday business workflows, organisations must secure not only users and inboxes, but also the AI systems that consume and act on email data.”

