AI Assistant Nearly Forwarded Bank Statement via Hidden Email Prompt Injection
BusApprehensive6142 · reddit · 2026-08-07
A Reddit user shared a frightening experience where their AI assistant, which had access to their email and calendar, almost automatically forwarded financial documents to a stranger.
The attack came from a seemingly normal spam email containing hidden HTML instructions (a prompt injection attack) commanding the AI to find financial files and send them to an external address. The user caught the action mid-execution only because they had a confirmation step enabled. The author warns that any AI agent with account access is vulnerable to this threat and advises users to test their agents against malicious inputs.
More from coding & agent
- Tencent Releases UI-Mate-27B, a Desktop GUI Agent Model — tencent · 2026-08-24
- Comparing AI Subscriptions: DeepSeek API vs. Claude Pro vs. Local LLMs — Unlikely_Bluejay5392 · 2026-08-24
- Claude Code introduces 'Remote Control' feature to boost coding efficiency — rohanpaul_ai · 2026-08-24
- rauchg lays out fx extension philosophy: MCP, Skills, Plugins and Unix composition — AccBalanced · 2026-08-24
- Netflix details its production LLM judge: hundreds of thousands of recommendations scored weekly — omarsar0 · 2026-08-24
- smolvm passes Simon Willison's Fable 5 agent test as a secure sandbox — yawnxyz · 2026-08-24