Microsoft Warns of AI Email Attacks Hiding Malicious Commands in Innocent Messages
Microsoft security researcher Shaked Ilan from Microsoft Israel R&D reveals a new cyber threat targeting AI agents integrated with email systems. Attackers embed hidden malicious instructions within seemingly harmless emails using techniques like white text on white backgrounds, tiny fonts, or long email threads. These commands can manipulate AI agents to perform unauthorized actions such as extracting sensitive data, changing payment details, or sending documents externally without the user's knowledge.
Unlike traditional phishing aimed at humans, this "Prompt Injection" attack targets AI agents directly, exploiting their ability to read and act on email content autonomously. For example, an attacker might insert a command in a payment-related email thread that causes the AI to alter bank account details when summarizing the conversation, deceiving the user who only sees a normal summary.
This risk is especially critical in organizations where AI agents have broad access to emails, contracts, invoices, and HR documents, and can execute tasks independently. Microsoft distinguishes between chatbots, which only provide answers, and AI agents that can perform actions, increasing potential damage if compromised.
To counter this, Microsoft recently introduced enhanced protections within Microsoft Defender for Office 365. This system scans incoming emails before delivery to users or AI agents, detecting and quarantining hidden malicious instructions. The defense leverages synthetic datasets of millions of attack variations to identify new and evolving threats.
Ilan emphasizes the importance of limiting AI agent permissions, requiring human approval for sensitive operations, and monitoring AI activities. He compares AI agents to new employees who should not receive unrestricted access immediately. While the threat is currently most significant in corporate environments, it may also affect private users as AI assistants gain access to personal emails and calendars.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.