Full version →
Analysis
Bulgarians worldwide
Cars
History
Interesting
Lifestyle
News
Sport
War in Ukraine
Tourism News
Technologies

Scam emails hide text telling AI assistants to treat them as genuine: a summary is not a check

09.10.2026

Security firm Barracuda has found scam emails with invisible instructions telling AI assistants to present the fraud as genuine or urgent. An AI summary should not be the only check.

Снимка: Mikhail Nilov / Pexels

On 7 October 2026, Barracuda published findings on scam emails aimed at two targets: the person and the AI assistant that summarises their mail. The emails contain hidden text that the human reader cannot see but the AI tool can read. The text tells the tool to present the message as genuine or urgent, so that the recipient opens the email and follows the link.

The people in these campaigns are attacked the old way. The email carries an archive or document locked with a password, and the password sits in the body of the message. That stops email security tools from opening and checking the attachment. The second target is the assistant, which reads the whole email, including what the mail app does not show on screen.

Four ways to hide text

Barracuda describes four methods. The first is HTML comments, which are notes in the email's code that the mail app does not show but that stay in the source text. The second is text hidden with styling: a font size of zero, white text on a white background, or a fully hidden element. The third is Base64 encoding, which writes text as a string of letters and digits, for example in a string that supposedly describes a picture. The fourth is zero-width characters, invisible Unicode symbols placed between ordinary words.

The instructions differ depending on the target. Barracuda says that in an invoice email, the hidden text tells the assistant to add a "fake priority action" that changes a supplier's payment details. In a CV, the applicant writes in an order to score them 10 out of 10 and recommend an interview at once. In a support chatbot, the attacker poses as "authorised support or admin mode" to get the bot's settings out of it.

AI models do not tell instructions from data

The cause lies in how language models work. Dave Chismon, technical director for platforms research at the UK's National Cyber Security Centre (NCSC), writes that the models "simply do not enforce a security boundary between instructions and data" in the text they receive. With SQL injection, an older attack on databases, technical means can set such a boundary. With language models, the NCSC says, a similar attack will probably never be fully ruled out, so the aim must be to limit the damage. The centre also advises that a model reading emails from strangers should not have access to privileged tools. Block lists of known phrases do not work, because the same instruction can be reworded countless times.

A similar case has been described for Google's Gemini. In a report to the 0DIN programme, a researcher looks at an email with text hidden using CSS (size zero or white colour). The text shows up in the "Gemini for Workspace" summary as a warning that appears to come from Google. The report's example is a fake alert about a compromised password, with a phone number to call. The email itself needs no link or attachment.

Google says it protects Gemini in several layers: classifiers that look for malicious instructions in emails and files, extra reminders telling the model to ignore commands from outside, hiding of suspicious links through Safe Browsing, and a request for confirmation before sensitive actions. The company urges users to be alert to suspicious messages that ask the AI for unusual actions.

Check inside the email itself

Experts at 0DIN recommend that users be told that AI summaries are not an authoritative security warning.

Check the sender in the email itself: look at the real address, not the display name. Examine a link without opening it, and compare it with the address that appears when you hover the mouse over it. A password-protected archive in the same email calls for extra care, because Barracuda describes it as a way to get around the scan of attachments. Do not dial a phone number from a summary.

For anything that involves money or personal data, open the original email by hand. Confirm a payment or a change of bank account through another channel, for example by calling a number you already know. Barracuda gives companies the same advice: human approval for payments and for changes to supplier details, and removal of hidden elements before the content reaches the AI.

Barracuda says it continues to track the campaigns for repeated attempts at such injections in email.

★ Add BurgasMedia to your preferred sources on Google →

Свързани статии

Отвори пълната версия в burgasmedia.com →