Cybercriminals Turn to Indirect Prompt Injection Attacks
TechTarget, Tuesday, August 19th, 2025
Subscription tools starting around $150 a month embed hostile instructions in email, PDFs, and invites.
Proofpoint researchers found threat actors building and selling tools that embed malicious instructions inside emails, documents, calendar invites, and web pages that AI systems process.
These indirect prompt injection attacks manipulate AI agents without requiring any direct user interaction, and subscription offerings start around $150 a month.
Techniques include hidden text in PDFs, concealed prompts in calendar invitations, and instructions embedded in page elements.
The tooling remains largely experimental but signals a shift toward practical exploitation, and the recommended mitigations are restricting agent permissions, monitoring unusual activity, requiring approval for sensitive actions, and rehearsing prompt injection incident response.