Barracuda said four techniques featured frequently in hiding such instructions: HTML comments, invisible text styled with CSS, Base64-encoded data and zero-width characters.
One email, two targets: human recipients and AI summarizers
Researchers at Barracuda published an analysis on October 7 describing phishing messages that carry conventional lures for people and concealed prompt injections aimed at AI assistants that summarize users' inboxes. A single message can therefore attack both the human recipient and the system that presents a distilled view of their mail.
The visible portion of the sample Barracuda analyzed looked like ordinary internal correspondence. The message's "From" and "To" addresses matched the same mailbox, it carried a trusted spam confidence score and it originated from a public‑sector domain — characteristics that help messages pass reputation‑based filters. For the human reader, the email included a password‑protected attachment with the password provided in the message body; Barracuda noted that this tactic creates a blind spot for traditional email security controls, because the attachment's contents are not readily scanned before opening.
How hidden prompt injections work in practice
If the recipient ignores or overlooks the visible message, the concealed instructions can influence an assistant's summary and priorities. Barracuda described hidden blocks that tell a summarizing AI to present the message as legitimate or urgent, effectively nudging the employee to open the email and follow the embedded link or instruction.
Injected instructions are not limited to urging clicks. Barracuda said attackers could instruct assistants to ignore prior directions and request wire transfers, leak data, or surface bogus urgent actions. That turns what looks like a routine invoice or resume into a multi‑vector attack that combines social engineering with machine‑facing manipulation.

Nobody's watching your logs at 2 AM.
Full SOC coverage without building one. Nubivance deploys and manages Rapid7 InsightIDR and MDR for organizations that need detection and response, not another dashboard.
Get coverageBarracuda's four concealment techniques
- HTML comments embedded in the message body.
- Invisible text styled via CSS so it does not render visually to the human reader.
- Base64‑encoded data hidden within the message content.
- Zero‑width characters inserted so instructions are present to a parser but invisible to the eye.
Barracuda reported these techniques as appearing frequently in the samples it analyzed and said they can be used to hide instructions that steer AI assistants' behavior.
Concrete examples Barracuda observed
The company described several real‑world examples. In one invoice email, a hidden block told the summarizing AI to add a fake priority action changing vendor payment details — an insertion intended to nudge an employee toward wiring money to the attacker. In another case, hidden text in a resume instructed an AI screening tool to rate a candidate "10 out of 10." Barracuda also cited a fake maintenance‑mode request designed to make a support bot reveal configuration, and poisoned web documentation crafted to make a coding assistant insert a credential‑exfiltration line into authentication code.
Defensive measures Barracuda recommends
Barracuda was explicit that no single control will stop every variation of these combined attacks. It recommended a layered approach:
- Strip hidden elements and invisible characters before content reaches AI systems.
- Detect instruction‑override language that attempts to supersede prior guidance.
- Use AI sandboxing and apply output validation to catch unexpected or dangerous assistant responses.
- Require human approval for payments and changes to vendor details.
- Monitor for repeated injection attempts and treat external content as data, keeping it separate from instructions.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: Expect to add preprocessing steps that remove invisible content and to instrument AI pipelines for instruction‑override detection and output validation.
- Affected enterprises and procurement leaders: Evaluate vendors' ability to strip hidden elements and sandbox AI models; insist on human approval workflows for financial and vendor changes.
- End users and the general public: Treat password‑protected attachments with embedded passwords and “trusted” internal‑looking messages as suspicious, even if an inbox summarizer flags them as urgent.
Barracuda's findings show a subtle but consequential pivot: attackers are no longer targeting only human judgment. By embedding machine‑readable instructions alongside human‑oriented lures, they create a layered risk that can bypass reputation checks and exploit automation designed to save time. The company’s core prescription — strip hidden content, validate outputs, and require humans for high‑risk actions — is simple in concept but will require coordinated changes to mail processing and AI integration pipelines if organizations are to close the gap.
Original reporting: https://www.infosecurity-magazine.com/news/attackers-hide-ai-prompt/




