AI assistants can summarize messages, search inboxes, draft responses, and retrieve information from connected systems.
Those capabilities also give attackers a new target.
Instead of trying to trick the person reading an email, a prompt injection attack can manipulate the AI reading it. Malicious instructions can be hidden inside an otherwise ordinary-looking message and become part of the content an AI assistant processes.
That means security teams need to think about more than what an employee sees in an email. They also need to consider what an AI system may read and interpret.
What Is a Prompt Injection Attack?
In a direct prompt injection, a user intentionally enters instructions designed to alter an AI system’s behavior.
The more deceptive form is indirect prompt injection, where malicious instructions are embedded in outside content the AI processes. Microsoft identifies emails, documents, websites, and plugins as potential sources.
The employee may never enter or even see those instructions. OWASP notes that prompt injections do not have to be visible or readable to a human if the AI system processes the content.
To the employee, the message may look completely normal. To the AI assistant, it may contain something else entirely.
How Prompt Injection Can Reach the Inbox
Consider an ordinary-looking invoice email.
The visible message asks the recipient to review an invoice. Elsewhere in the message, an attacker has included instructions intended for an AI assistant.
The email reaches the employee’s mailbox. Later, an AI assistant summarizes the message, searches the inbox, or uses the email as context for another task.
At that point, the AI may process both the legitimate message and the attacker-controlled instructions.
Depending on the AI system, its safeguards, and the permissions it has been given, a successful injection could influence its output or its interactions with connected data and functions.
Unlike a traditional phishing scenario, the employee may never need to click a malicious link for the AI to encounter the attacker-controlled content.
When the Email Is the Attack
This is not just a hypothetical attack path.
In 2025, researchers disclosed EchoLeak (CVE-2025-32711), an information disclosure vulnerability affecting Microsoft 365 Copilot.
The attack started with an email. The recipient did not need to click a link, open an attachment, or respond to the message. Instead, malicious instructions within the email could be processed by Copilot when it later accessed the message as part of the user’s context.
Microsoft addressed the EchoLeak vulnerability before public disclosure, but the underlying security challenge is broader than a single vulnerability or platform. Microsoft’s own guidance on indirect prompt injection recommends treating external content as untrusted when it is processed by AI systems.
For security teams, the takeaway is straightforward: as AI gains access to email and business data, protecting what enters the mailbox becomes part of protecting the AI environment.
Protecting the Email Environment Around AI
There is no single control that eliminates prompt injection. OWASP recommends multiple safeguards, including limiting an AI system’s privileges, separating untrusted external content, requiring human approval for high-risk actions, and monitoring AI system activity.
When email is one of the inputs an AI system can access, protecting the email lifecycle is another part of that strategy.
That starts with what reaches the mailbox. Trustifi Inbound Shield analyzes incoming email using threat intelligence, sender and domain signals, behavioral patterns, message content, embedded links, attachments, QR codes, and other indicators. Messages identified as malicious can be quarantined before reaching the user.
Trustifi also provides controls around what leaves the organization. Outbound Shield applies administrator-defined DLP policies to sensitive outbound information, including encryption, quarantine, and alerts.
AI platforms still need their own safeguards against prompt injection. Trustifi helps strengthen the email environment around them, with controls spanning inbound threats, post-delivery detection, account security, and sensitive outbound data.
See What Is Reaching Your Mailboxes
Knowing what is reaching employee mailboxes can help security teams identify gaps in their existing email defenses.
Trustifi runs alongside your environment to identify threats that have reached mailboxes despite existing security controls.
See what your current defenses may be missing and where additional protection may be needed.
Request a Demo


