Threat Spotlight: Email attacks target both humans and AI in the same message
Barracuda Research has uncovered phishing attacks aimed at both human recipients and the AI-powered systems they use to summarize, prioritize, and process email.
Key takeaways
- Analysis by Barracuda Research shows how attackers are combining tactics to manipulate both human users and their email AI assistants in the same phishing email.
- Humans are targeted with social engineering such as password-protected attachments, and AI assistants are targeted with prompt injections designed to influence or override user behavior.
- Organizations must secure not only users and inboxes, but also the AI systems that consume and act on email data.
The dual-target email attack
Traditional phishing emails are designed to trick a human recipient into clicking a link, opening an attachment, or handing over information.
As users increasingly rely on AI assistants to summarize email messages, prioritize inboxes, accept calendar invites, process support tickets, and help make business decisions, the phishing attack model is changing. Attackers now have a second target in their sights: the AI systems that sit between the email and the user.
A recent attack campaign analyzed by Barracuda researchers demonstrates how such attacks combine traditional social engineering with malicious prompt injection.
Anatomy of a sample dual target email
On the surface the sample looks like ordinary internal correspondence.
The ‘From’ and ‘To’ addresses match the same mailbox, the message carries a trusted spam confidence score, and it originates from a public sector domain, all of which lend it perceived legitimacy and help it pass reputation-based filtering.
The email has multiple layers. One layer contains the text and images that the recipient sees. Another layer carries hidden malicious instructions known as prompt injection. These are aimed at the AI assistant.
Attack vector 1: Traditional phishing
The first technique is familiar to email security professionals. The message appears routine and trustworthy. It may come from a legitimate-looking domain, reference a business process, and include a document attachment. This attachment is protected with a password, which is conveniently provided in the email body — a tactic that creates a blind spot for traditional email security controls.
If the user opens the attachment with the provided password, the attack progresses to credential theft or malware delivery.
However, if the user overlooks the email, the attacker can rely on the malicious prompt injection concealed in the email’s second layer. This manipulates the user’s AI assistant so that the email summary it presents to the user marks the phishing email as legitimate or urgent — pushing the human to open the email and click on the link.
Attack vector 2: Hiding instructions from the human but not the AI assistant
In addition to the user manipulation example above, malicious prompt injection can hijack the assistant’s response and instruct the email to ignore its previous directions and instead send an urgent request to wire funds to a specified account, leak data, or surface a fake urgent action. None of these instructions are visible to the user.
According to Barracuda’s analysis, four techniques feature frequently in such attacks:
1. Hidden text in HTML comments. Instructions are tucked inside comment tags that never render in a mail client but remain in the raw source code an AI parses.
2. Invisible text techniques (CSS). Text is styled with a zero-pixel font size, white color, or hidden completely, so it occupies no visible space yet still exists in the document the model reads.
Examples seen by Barracuda in real-world attacks
In one example, a hidden block of text in an invoice email instructs the summarizing AI model to add a fake priority action changing vendor payment details, and the compromised summary nudges an employee toward wiring money to the attacker.
To the AI assistant, the hidden block embedded in the invoice looks like this:
How organizations can defend themselves
No single security control will stop every variation of these attacks. Effective protection requires multiple layers.
Key defensive measures include:
- Input sanitization to identify and remove hidden elements, comments, and invisible characters before content reaches AI systems.
- Prompt injection detection to identify instruction-override language and suspicious patterns.
- AI sandboxing to limit what an AI assistant can access or do.
- Output validation to review AI-generated responses before they trigger actions.
- Human approval requirements for financial transactions, vendor changes, and other sensitive decisions.
- Monitoring and logging to identify repeated injection attempts and emerging attack patterns.
Most importantly, organizations must ensure that external content of any kind is always treated as data only and kept separate from instructions.
The most dangerous aspect of this emerging threat is how ordinary it looks. A single email can now carry two separate attacks: one aimed at convincing a recipient to open a malicious attachment, and another aimed at manipulating the AI systems trusted to process that message.
As AI assistants become embedded in everyday tasks, organizations must expand their security mindset. Protecting the inbox is no longer enough. The systems that read, summarize, and act on email content also need protection.
How Barracuda helps protect against these threats
Barracuda provides multiple layers of defense against both traditional email attacks and emerging AI-enabled threats.
Barracuda Email Gateway Defense helps identify and block suspicious messages, analyze attachments in sandbox environments, and enforce controls around high-risk attachment types, including password-protected files.
Behavioral AI helps identify phishing attempts, business email compromise, and other attacks that may evade traditional signature-based detection.
When an account is compromised, Automated Threat Response can rapidly contain the threat by removing malicious emails, disabling suspicious access, and remediating compromise indicators.
Combined with user reporting capabilities, security awareness training, and threat intelligence, these controls help strengthen both human and technical defences.
2026 Email Threats Report
Learn how AI and phishing-as-a-service are reshaping the email threat landscape and how to stay protected
Subscribe to the Barracuda Blog.
Sign up to receive threat spotlights, industry commentary, and more.
The Managed XDR Global Threat Report
Key findings about the tactics attackers use to target organizations and the security weak spots they try to exploit