Research · curated 6 Aug 2026

Testing a Prompt injection Attack Against an Enterprise AI Agent

Coverage timeline

6 Aug 2026darktrace.com

Single-source research — first reported, latest, and curated coincide.

Why it matters

Indirect prompt injection delivered via email can trick email-reading enterprise AI agents into deleting or exfiltrating data without any traditional malware signature, so defenders must pair model guardrails with behavioral monitoring.

Darktrace ran a controlled experiment testing whether an enterprise Gemini AI agent in Google Cloud could be compromised by an indirect prompt injection hidden in an inbound email, and whether its behavioral email analysis could detect the attack first. Although the email contained no malware, malicious links, or sender-reputation indicators, Darktrace / EMAIL flagged and quarantined it based on anomalous language and behavioral context, referencing the EchoLeak (CVE-2025-32711) Copilot vulnerability as a real-world analog.