My ai assistant almost forwarded my bank statement to a stranger and barely anyone knows this attack exists.
My ai assistant almost forwarded my bank statement to a stranger and barely anyone knows this attack exists.

My ai assistant almost forwarded my bank statement to a stranger and barely anyone knows this attack exists.

Okay this genuinely scared me and I don't think enough people are talking about it.

I’ve been using an ai agent connected to my email and calendar to handle some of the busywork. A few days ago I got an email that looked like normal spam, some random newsletter looking thing. Buried in the html of that email was a hidden instruction telling any ai reading it to find financial documents and forward them to an outside address.

My agent almost did it. I caught it mid action because I happened to have a confirmation step turned on, but if I hadn't, it would have just quietly forwarded stuff without asking me first.

This apparently called prompt injection and it's not some rare theoretical thing, there's already been real world cases with tools like microsoft copilot getting exploited the same way. Any ai with access to your inbox, calendar, or other accounts is a potential target because it can't always tell the difference between your instructions and instructions hidden inside the content it is reading.

If you're using any kind of ai agent connected to your accounts, please actually test what happens if it hits something malicious. Most people including me had no idea this was even possible until it almost happened to me.

submitted by /u/BusApprehensive6142
[link] [comments]