Analysis · curated 20 Aug 2026

AI Prompt Injection in Email: How It Works, How to Stop It

Coverage timeline

20 Aug 2026mailroute.net

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

Indirect prompt injection via email turns AI inbox assistants into a new attack surface where hidden instructions the human never sees can drive phishing or mailbox data exfiltration, forcing defenders to filter content aimed at the machine reader, not just the human.

MailRoute's explainer describes indirect prompt injection delivered via email, where attackers hide machine-readable instructions (white-on-white text, zero-size fonts, HTML comments, invisible Unicode tag characters) inside messages that AI assistants like Microsoft 365 Copilot, Gemini for Workspace, and Apple Intelligence ingest when summarizing or acting on inboxes. The piece explains how such hidden instructions can plant phishing lures inside trusted summaries or turn assistants into exfiltration tools, and outlines mitigations.