Are Your AI Assistants the Next Attack Surface?
KnowBe4, Wednesday, September 23rd, 2026
KnowBe4 demonstrated an indirect prompt injection attack that used Gemini in Gmail to exfiltrate a one-time password from an unrelated email.
KnowBe4 researchers tested an indirect prompt injection attack against an AI assistant in a lab, sending a crafted email into a Gmail inbox that an Apps Script workflow routed through Google's Gemini for drafting a reply.
Hidden instructions embedded in the email's HTML caused Gemini to read unrelated inbox content, extract a one-time password from a different email, and exfiltrate it to an external server, requiring only that the victim open the draft reply the script had already generated.
The researchers say they are also finding structurally similar, if less sophisticated, live phishing campaigns targeting AI assistants rather than humans directly.