- Dark Reading reports that attackers can use prompt injection to manipulate AI agents that already hold authority over business systems, much as BEC manipulates employees.
- Experts quoted say a correct login and permission do not show an action is appropriate, so agents need controls outside themselves.
- Build an inventory of every agent, what it can do and who owns it, and require human approval for sensitive actions.
Business email compromise has always needed one thing: a person with the power to say yes. The attacker writes a convincing message, and an accounts-payable clerk changes a bank detail. Awareness training exists to make that clerk stop and check. Now companies are giving software the same power, and the clerk is no longer the only target.
That is the argument in a Dark Reading report published October 9, 2026. The lesson here is simple. The attack is moving from persuading a person to persuading a permission. An AI agent that is already allowed to act does not need to be tricked into breaking the rules. It only needs to be tricked into using them.
From the clerk to the agent
Dark Reading describes the classic case first. An employee gets a message that looks like it comes from a vendor. The message says the vendor's banking details have changed. The employee believes it and redirects a future payment to an attacker's account, using their own legitimate access.
The report says an agent with privileged access changes that picture. Through prompt injection, an attacker may not need a person at all. The reporting lists possible aims: stealing data to use later as an extortion lever, redirecting invoice funds, or gaining a foothold for later access. In a scenario modelled on BEC, a poisoned outside AI tool might edit a supplier's record or send money to the wrong account.
That BEC-style payment redirect is a scenario in the report. Dark Reading does not describe a documented case of it.
Verizon's report also put that figure at a 60% increase year over year. Dark Reading pairs the number with a trend: companies are plugging AI tools into the software and interfaces behind their daily operations. The figure counts third-party involvement. It does not measure AI-specific incidents.
How the trick works
Prompt injection means hiding instructions inside content that an AI model reads. John Wilson, a senior fellow of threat research at Fortra, told Dark Reading that agents "can struggle to distinguish between instructions and the data they are asked to process." A model reads a document and a command in the same stream of words. It can treat one as the other.
Wilson gave an example. An agent screens job applicants, and one résumé says to ignore all previous scoring instructions and move the candidate forward. If the agent is not hardened against this, the hidden line could subvert the screening.
Some attacks are indirect. The attacker plants instructions in a web page or email, and an LLM ingests them later. The victim never sees the attacker. The agent simply reads the wrong page.
There is also a point about psychology. Wilson said human attackers exploit fear, urgency, authority, curiosity and greed. Agents feel none of these. Equivalent attacks instead exploit how a model interprets instructions and decides which ones to trust.
Prompt injection is already being used in the wild
Dark Reading points to several research groups. Their findings concern prompt injection in general. Palo Alto Networks' Unit 42 identified 22 techniques that attackers used in the wild to build payloads. Their goals ranged from search engine poisoning to promoting phishing sites, unauthorized transactions and leaking sensitive information. Check Point Research cites a rise in indirect prompt injection.
OWASP's GenAI Exploit Round-up Report for the first quarter of 2026 described a clear move from theoretical risks to real-world exploitation. It said attackers increasingly target agent identities, orchestration layers and supply chains, not just model outputs.
The FBI figure matters because the older fraud has not gone away. Those losses made BEC the second-costliest crime category IC3 tracks, behind investment fraud. Human training stays necessary. The agent adds a second front.
Permitted is not the same as appropriate
The hard part is that a poisoned agent may do everything correctly on paper. It logs in properly and holds the right permission. Danny Jenkins, CEO of ThreatLocker, told Dark Reading that authentication says who is acting and authorization says what they may do. Neither says whether the action fits the moment.
Jaimin Patel of Palo Alto Networks said the strongest signal is a gap between what the agent was meant to do and what it did. He also warned about shadow AI, meaning agents deployed without IT oversight. Agents with shared API keys or standing privileges blur who is accountable.
Jenkins argues that controls should sit outside the agent. Sensitive or unusual actions should be blocked by default until a human approves them. Dark Reading compares this to checking a suspicious request from a colleague through a second channel. The report adds that guardrails do not stop an attacker reaching an agent, but they limit how far access turns into action.
Questions to put to your team
Start with visibility. Gabe Knuth, a principal analyst at Omdia, says the first job is to see what already has access. In practice, that means checking the connectors that link agents to tools (MCP servers), delegated logins (OAuth), access keys and machine accounts. Then ask staff how they use agents, inside and outside the company.
Wilson would treat agents and outside software like employees. Keep one master list of anything that can act in the company's name. For each entry, record what it can reach, what it can do, which credentials it holds and who answers for it. For agents, add what sets them off and which outside services they can call.
Then test it. Wilson's tabletop questions are a useful agenda:
Can we tell something is wrong when every action was properly authorized? Can we trace unusual agent behavior? Can we disable one agent or revoke its credentials without breaking others? Can we reverse fraudulent actions and keep the evidence?
If the answers are unclear, the gap is in governance, not in the model. A clerk works inside a structure of managers and verification steps. An agent that can move money needs equivalent checks, owned by people who know it exists.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Dark Reading.





