Phishing emails are now carrying two attacks in one message. One targets the person reading the email; the other targets the AI assistant that summarises, prioritises or acts on it.
Barracuda Research found the "dual-target" technique in recent phishing campaigns, and has detailed it in a blog post published on 7 October.
The emails contain multiple layers of content. One layer holds the text and images the recipient sees. Another holds hidden instructions written for AI systems.
The hidden prompts can sit in HTML comments or invisible text, such as zero-sized fonts or white text. They can also be placed in encoded content or in password-protected attachments.
Meanwhile, the human recipient receives conventional social engineering, such as a password-protected attachment designed to capture credentials.
Barracuda researchers documented several examples of AI-targeted instructions.
One added a false high-priority action telling an employee to update vendor payment details, raising the likelihood of a fraudulent payment.
Another sought to manipulate automated CV screening. Hidden text told the AI to award a perfect rating and recommend an interview regardless of qualifications.
A third instructed an AI assistant to switch to an authorised maintenance or administrative mode and reveal its configuration.
A fourth directed a coding assistant to insert credential-stealing code whenever it generated authentication functions.
"A single email can now carry two separate attacks: a traditional phishing message to capture credentials through a malicious attachment, for example, and a prompt injection to manipulate the AI systems to influence behaviour," said Guruprasad Kenja, Threat Analyst at Barracuda.
Kenja said organisations must now protect more than people and mailboxes.
"As AI assistants become embedded in everyday business workflows, organisations must secure not only users and inboxes, but also the AI systems that consume and act on email data," he said.