Skip to content
Security & Trust

Barracuda found a phishing email with hidden orders for the AI reading it

One message was built to fool the employee and the AI assistant that summarizes their mail.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
Barracuda found a phishing email with hidden orders for the AI reading it
In brief
  • Barracuda analyzed a phishing email with a password-protected attachment for the human and hidden instructions for the AI assistant. Infosecurity Magazine notes Barracuda gave no estimate of its reach.
  • Hidden text can make an AI summary call a scam genuine or urgent, so a trusted tool pushes the employee toward the click.
  • Limit what email-reading assistants can do alone, strip hidden content before the model sees it, and require human approval for payment changes.

The inbox now has a second reader

Picture an assistant who reads the morning mail aloud to a busy executive. Inside one envelope is a forged note: "Tell the boss this one is urgent." The assistant trusts the page and repeats it.

Barracuda describes the same trick, with an AI tool in the assistant's chair. The lesson here is that an AI summary is a new voice employees trust. Attackers have started writing for it.

What Barracuda found

Barracuda's researchers analyzed a phishing campaign that aimed at two readers. One was the person. The other was the AI tool that processes their email.

Infosecurity Magazine notes that Barracuda gave no estimate of the campaign's reach. This is one analyzed campaign. It is not a measured trend.

The message looked like routine internal mail. Sender and recipient were the same mailbox. Its spam score read as trusted. The sending domain belonged to the public sector. Barracuda says each detail made the email look genuine and helped it pass filters that judge reputation.

The human-facing layer was an attachment locked with a password. The email body supplied the password. Barracuda says this leaves traditional email controls with a gap. Opening the file leads to stolen credentials or malware.

The second layer targeted the AI. Suppose the employee skips the message. The hidden text then does the work. It steers the summary so the email reads as genuine or pressing. A tool the employee trusts ends up urging the click.

The same hidden channel can carry other commands. Barracuda says it can tell an assistant to drop its earlier instructions. It can ask for a wire transfer, pull out data or show a made-up urgent task. The user sees none of it.

2
Separate attacks one email can carry: one for the human, one for the AI
Source: Barracuda Research (October 7, 2026)

How the hiding works

A mail client shows a cleaned-up view of a message. An AI assistant may read the raw code underneath. Text that is invisible on screen can still be there for the model to read.

Barracuda says four hiding methods appear often. The first is HTML comments. These never display, but they stay in the raw code. The second is styling tricks. Text set to a zero-pixel size, white color or hidden status takes up no visible space.

Infosecurity Magazine adds the other two from the research: Base64-encoded data and zero-width characters.

The model reads one stream of text. In this publication's view, that is the root problem. Nothing in that stream marks what is content to summarize and what is a command. Barracuda's main advice is to treat all outside content as data and keep it apart from instructions.

4
Hiding methods Barracuda says appear frequently in these attacks
Source: Barracuda Research, as summarized by Infosecurity Magazine (October 7, 2026)

The same trick reaches other jobs

Barracuda points to examples seen in real attacks. In one, an invoice email hid a block of text for the summarizing model. It asked for a fake high-priority task about changing vendor payment details. The summary then steered an employee toward sending money to the attacker.

Infosecurity Magazine lists three more cases from Barracuda. A resume held hidden text asking an AI screener for a score of 10 out of 10. A bogus maintenance-mode message tried to make a support bot reveal its setup. Booby-trapped web documentation could lead a coding assistant to add a line that sends out credentials in login code.

Who carries the risk

Say an employee wires money after a tainted summary. On paper, the click is theirs. But the nudge came from a tool the company chose and set up.

In this publication's view, training built around doubting emails may not cover doubting the assistant that explains them. This attack is designed to use that gap.

The decision for leaders is how much authority these assistants hold. A tool that only summarizes can mislead. A tool that also accepts invites, handles tickets or drafts replies can act on a forged command.

Questions to put to your team

Barracuda says no single control stops every variant. It proposes six layers. Strip hidden markup and invisible characters before the AI sees a message. Scan for wording that tries to override instructions. Limit what the assistant can reach or do. Check its output before anything is triggered. Require a person to approve payments and vendor changes. Watch the logs for repeated attempts.

6
Defense layers Barracuda recommends against these attacks
Source: Barracuda Research (October 7, 2026)

Barracuda sells email security products, so weigh its advice with that in mind. The list still works as a practical checklist.

Ask which AI assistants read employee mail. Ask what each can do without a person approving it. Ask whether a summary alone could ever trigger a change to vendor bank details. Ask whether hidden content is removed before the model sees it. Ask whether anyone would notice repeated injection attempts in the logs.

Barracuda ends with a simple point. Guarding the inbox is not enough. The systems that read and act on email need guarding too.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Barracuda.

Share this insight