Analysis · curated 14 Jul 2026
Email Agent Hijacking: The Hidden Threat That Breaks Post-Delivery Security
First reported checkpoint.com
Coverage timeline
Single-source analysis — first reported, latest, and curated coincide.
Why it matters
Email Agent Hijacking illustrates how indirect prompt injection turns AI email assistants into a new attack surface, letting adversaries exfiltrate data or trigger actions without any user interaction and bypassing traditional post-delivery email security.
Check Point describes "Email Agent Hijacking" (EAH), a threat class where attackers embed hidden instructions in email content, signatures, or attachments to manipulate how AI agents summarize, prioritize, or respond to messages before a human ever sees them. The analysis cites the EchoLeak vulnerability in Microsoft Copilot (CVE-2025-32711) as an example of a zero-click attack that manipulated the AI acting on a user's behalf, and argues post-delivery email controls are ineffective when agents act instantly.