Cybercriminals Turn to Indirect Prompt Injection Attacks

Cybercriminals are developing indirect prompt injection tools to target AI agents.

Written By
Ken Underhill
Ken Underhill
Aug 13, 2026
4 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Proofpoint researchers found that cybercriminals are developing and selling tools designed to hide malicious instructions inside emails, documents, calendar invites, and webpages that AI systems routinely process. 

This could allow attackers to manipulate AI agents without direct user interaction. 

“These advertisements and discussions reveal novel techniques organizations are likely to observe in upcoming months, such as IDPI included in calendar invites and incorporated into malvertising attack chains,” said the researchers in their analysis.

Key takeaways of the prompt injection findings

  • Cybercriminals are developing and selling IDPI tools that target AI systems through emails, documents, calendar invitations, and webpages.
  • IDPI can manipulate AI agents as they process external content, potentially without requiring direct user interaction.
  • Threat actors are testing IDPI in phishing, malicious documents, calendar invitations, and malvertising, although widespread exploitation has not yet been observed.
  • Organizations should limit AI agent privileges, monitor agent activity, control sensitive actions, and test incident response plans for prompt injection scenarios.

The growing threat of indirect prompt injection  

Proofpoint reports that indirect prompt injection (IDPI) is gaining attention on underground criminal forums, where threat actors are developing, testing, and advertising tools designed to target AI systems. 

Some subscription-based offerings reportedly start at approximately $150 per month and include generators for malicious emails, PDFs, calendar invitations, and webpages. 

The emergence of these services suggests cybercriminals are beginning to explore how IDPI can be packaged into tools and incorporated into existing attack chains.

How indirect prompt injection works 

Prompt injection attacks generally fall into two categories. 

A direct prompt injection occurs when a user provides input directly to an AI model that causes it to behave in an unintended or unexpected way. 

With indirect prompt injection, malicious instructions are embedded within external content that an AI system later processes, such as an email, document, calendar invitation, or webpage.

Advertisement

Why AI agents are at risk 

This distinction matters as organizations give AI agents greater access to business applications, corporate data, and automated workflows. 

Unlike traditional phishing, an IDPI attack may not depend on an employee clicking a malicious link or following an attacker’s instructions.

An AI agent could encounter the malicious prompt while performing a routine task, such as summarizing an email, reviewing a document, processing a meeting invitation, or browsing a webpage. 

If the agent has sufficient permissions, an attacker could potentially manipulate its behavior to access sensitive information or perform unauthorized actions.

According to Proofpoint, threat actors are currently experimenting with several IDPI delivery methods.

Email-based attacks

Email-based attacks can conceal malicious instructions using text that matches the background color of a message. 

The email may appear harmless to the recipient, while an AI assistant processing the content could still detect and interpret the hidden prompt.

PDF and document attacks

PDF and document attacks embed instructions within attachments using techniques such as hidden text or embedded elements. 

Proofpoint observed testing involving a PDF containing instructions that attempted to direct an AI agent to locate and transmit XLSX files. 

These techniques are designed to place instructions where an AI system may process them even if they are overlooked during normal document viewing.

Advertisement

Calendar invitation attacks

Calendar invitation attacks place malicious prompts within meeting invitations, including content presented as part of an agenda. 

An AI assistant tasked with summarizing the invitation could process the instructions without the recipient intentionally interacting with them. 

The technique builds on attackers’ existing abuse of calendar invitations for phishing but shifts part of the target from the employee to the AI system processing the invitation.

Malvertising and malicious webpage attacks

Malvertising and malicious webpage attacks could expose AI agents to prompts embedded within advertisements or website content. 

Attackers are exploring methods such as placing instructions in HTML, extremely small text, hidden page elements, or image alt text that may be processed by an AI agent even when they are not readily visible to a human visitor.

According to the researchers, these techniques have not yet seen widespread exploitation, and several remain in the experimental stage.  

However, the development and sale of dedicated IDPI tools marks an important shift from largely hypothetical attack scenarios toward practical experimentation by cybercriminals. 

As AI agents become more integrated into enterprise systems, organizations should prepare for attackers to incorporate IDPI into attack campaigns. 

Reducing indirect prompt injection risk 

Organizations adopting AI agents should assume that content originating outside their environment could contain adversarial instructions.  

  • Restrict agent permissions by giving AI agents only the access and privileges required for their intended tasks.
  • Separate trusted instructions from external content by treating emails, documents, webpages, and calendar invitations as untrusted input.
  • Require approval for sensitive actions such as sending files, changing permissions, deleting data, or initiating external transfers.
  • Control external communications by restricting AI agents to approved domains, APIs, applications, and file-sharing services.
  • Monitor agent activity for unusual file access, outbound connections, data transfers, tool usage, and automated actions.
  • Protect sensitive data with segmentation and data loss prevention (DLP) controls that limit what AI agents can access and transmit.
  • Test incident response plans and use attack simulation tools with scenarios around prompt injection and other AI-powered attacks.
Advertisement

Collectively, these measures can help organizations reduce overall exposure and build resilience. 

Bottom line

The more immediate concern is how quickly IDPI could become operationalized within attack chains that security teams already manage. 

As underground tooling lowers the barrier to entry, organizations should evaluate whether existing controls can detect and contain malicious instructions targeting AI agents. 

They should also assess whether current telemetry provides enough visibility to investigate agents that begin operating outside their intended scope. 

A zero trust approach can help organizations reduce some of this risk by continuously verifying access and limiting AI agents’ permissions across enterprise systems and data.

Ken Underhill

Ken Underhill is an award-winning cybersecurity professional, bestselling author, and seasoned IT professional. He holds a graduate degree in cybersecurity and information assurance from Western Governors University and brings years of hands-on experience to the field.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.