Research · curated 6 Aug 2026
Testing a Prompt injection Attack Against an Enterprise AI Agent
First reported darktrace.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Indirect prompt injection delivered via email can trick email-reading enterprise AI agents into deleting or exfiltrating data without any traditional malware signature, so defenders must pair model guardrails with behavioral monitoring.
Darktrace ran a controlled experiment testing whether an enterprise Gemini AI agent in Google Cloud could be compromised by an indirect prompt injection hidden in an inbound email, and whether its behavioral email analysis could detect the attack first. Although the email contained no malware, malicious links, or sender-reputation indicators, Darktrace / EMAIL flagged and quarantined it based on anomalous language and behavioral context, referencing the EchoLeak (CVE-2025-32711) Copilot vulnerability as a real-world analog.