Barracuda researchers have found phishing emails that carry two payloads at once: a conventional lure for the person and concealed instructions for the AI assistant summarising their inbox. For UK organisations rolling out Copilot-style tools, it turns the NCSC’s long-running warning about prompt injection into a live email threat.
What happened
On 7 October 2026 Barracuda Research published analysis of what it calls “dual-target” phishing: messages engineered to manipulate both the human recipient and the AI tooling that now sits between many users and their mailbox. The work, written up by Barracuda threat analyst Guruprasad Kenja, was based on a campaign the company examined, and was covered by Infosecurity Magazine and several other trade titles. Barracuda did not put a figure on how widespread the campaign is, so this should be read as an emerging technique rather than a measured wave.
The sample described by the researchers was built to look mundane. It appeared to be internal mail, with sender and recipient set to the same mailbox, carried a trusted spam confidence score and came from a public sector domain. Those traits help a message slip past filtering that leans heavily on reputation. Barracuda has not said which country that domain belongs to.
The technical picture
Each email works on two layers. The visible layer is classic social engineering: a routine-looking business message with a password-protected attachment, the password helpfully supplied in the body. Encrypting the file stops many gateways from inspecting it, which is why this trick has been popular with phishing crews for years. Opening the document leads on to credential theft or malware.
The second layer is invisible to the reader but fully legible to a language model. Barracuda lists four hiding places it sees repeatedly: HTML comments that never render in a mail client, text styled by CSS to be zero-sized or white, instructions tucked inside Base64-encoded blocks, and zero-width Unicode characters woven through normal text. An assistant asked to summarise or triage the inbox ingests all of it.
The aim is to steer the assistant. If the user ignores the email, the hidden prompt can push the AI to describe it as genuine or urgent in its summary, nudging the person back towards the attachment. Barracuda says injected text can also try to override the assistant’s earlier instructions, surface a bogus action item, request a payment or leak data.
The firm gave several real-world examples beyond email triage. An invoice carried a concealed block telling the summarising model to add a priority task changing a supplier’s bank details. A CV contained hidden text demanding a perfect score from an automated screening tool. A support bot was told it had entered an authorised maintenance mode and should disclose its configuration. And poisoned documentation on a web page attempted to make a coding assistant add a credential-stealing line whenever it wrote authentication code.

Why it matters for UK organisations
None of this will surprise anyone who read the NCSC’s December 2025 blog on the subject. In it, the NCSC’s Dave Chismon argued that large language models do not enforce any boundary between instructions and data, so prompt injection may never be fully fixed in the way parameterised queries killed off most SQL injection. The NCSC described these systems as “inherently confusable” and warned that, without better design, the UK could see a breach wave comparable to the SQL injection era of the 2010s. Indirect injection through content an attacker can send you, such as an email or a CV, was the example the NCSC chose to illustrate the point.
What Barracuda’s findings add is evidence that criminals are folding the technique into ordinary phishing rather than treating it as a research curiosity. UK businesses and public bodies have spent the past two years switching on mailbox summaries, AI triage of shared inboxes and assistants that can draft replies or act on calendar invites. Every one of those features reads untrusted external content by design.
The financial angle is the most immediate concern. Invoice redirection and payment diversion fraud is already a familiar headache for UK finance teams. An assistant that confidently tells a finance clerk a supplier has changed account details lends that lie a veneer of system authority that a suspicious-looking email never had.
Expert view
When we test AI assistants and agents, the injection itself is rarely the hard part. Getting a model to follow hidden text is usually straightforward; the real question is what that model is allowed to do next. An assistant that only summarises is a nuisance when it is fooled. One that can send mail, approve invites, query SharePoint or call APIs becomes a confused deputy holding the user’s privileges.
That is why I agree with the NCSC’s emphasis on deterministic controls over clever filtering. Blocking phrases such as “ignore previous instructions” will catch the lazy attempts and miss the rest, because there are endless ways to reword an instruction. Stripping hidden markup before content reaches the model is worthwhile hygiene, but it is not a boundary.
In my experience, the organisations that cope best are the ones that treat an AI summary as a convenience, never as a source of truth. If a payment, a password reset or a supplier change is only ever verified through the same channel that delivered the request, the AI has simply made an old weakness faster.
What to do now
- Lock down payment processes. Require out-of-band verification, using known contact details, for any change to supplier bank details or urgent payment request, whatever an assistant says.
- Limit assistant privileges. Audit what your email and productivity AI can access and do. Remove send, approve and broad file access where it is not needed, in line with the Cyber Essentials principle of least privilege under user access control.
- Revisit password-protected attachments. Configure gateways to quarantine or sandbox encrypted archives and documents from external senders, and review whether trusted spam scores can be inherited by spoofed internal mail.
- Sanitise inbound content. Where your platform allows it, strip HTML comments, hidden styling and zero-width characters before mail is passed to AI features.
- Log AI activity. Capture assistant inputs, outputs and tool calls so that injection attempts and odd behaviour can be investigated.
- Brief your staff. Update awareness training so finance, HR and support teams know an AI summary can be manipulated by the email it describes.
- Test it. Include indirect prompt injection in penetration tests of any AI feature that processes external content, including CV screening and support bots.
Bottom line
Phishing now has two audiences, and the second one never gets suspicious. Prompt injection cannot be patched away, so UK organisations need to cap what their assistants can do, verify sensitive actions out of band and assume that anything an AI reads aloud may have been written by an attacker.
Sources
- Barracuda: Email attacks target both humans and AI in the same message
- Infosecurity Magazine: Attackers Hide AI Prompt Injections Inside Phishing Emails
- Information & Data Manager: One Email, Two Attacks: Human and AI
- Australian Cyber Security Magazine: New email attacks target both humans and AI in the same message
- NCSC: Prompt injection is not SQL injection (it may be worse)
- NCSC: Mistaking AI vulnerability could lead to large-scale breaches, NCSC warns