Research · curated 27 Sep 2026
Prompt Injection in Healthcare AI: Hiding an Attack in a Scan
First reported cyberlab.co.uk
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Indirect prompt injection hidden in medical scan pixels shows that attacker instructions can enter a clinician-facing diagnostic AI through trusted data channels, potentially corrupting clinical decisions without any direct access to the system.
CyberLab's penetration testing team demonstrated an indirect prompt injection against an NHS-style clinical imaging AI platform by embedding innocuous-looking 'technical note' text directly into the pixels of a medical scan (DICOM image). When a clinician later uploaded the tampered scan and asked routine natural-language questions, the multimodal model ingested the hidden text and let it shape its clinical reasoning, with effects worsening over the conversation.