{"id":579,"date":"2025-11-04T14:52:21","date_gmt":"2025-11-04T06:52:21","guid":{"rendered":"https:\/\/www.finndy.com\/?p=579"},"modified":"2025-11-04T14:52:21","modified_gmt":"2025-11-04T06:52:21","slug":"your-ai-agent-is-now-a-target-for-email-phishing","status":"publish","type":"post","link":"https:\/\/www.finndy.com\/index.php\/2025\/11\/04\/your-ai-agent-is-now-a-target-for-email-phishing\/","title":{"rendered":"Your AI Agent Is Now a Target for Email Phishing"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Email security has always been a cat-and-mouse game.\u00a0Viruses\u00a0are invented, and\u00a0antivirus\u00a0software is invented to catalog known\u00a0viruses\u00a0and detect their presence in email attachments and URLs. As viruses morphed into more sophisticated forms of\u00a0malware,\u00a0cybersecurity\u00a0tools adapted to be able to scan for and detect these new threats.\u00a0Phishing\u00a0became the next arena, giving birth to new tools as well as a whole new category of defense known as security awareness training. Now,\u00a0the bad guys are attacking\u00a0AI agents\u00a0to bypass current security guardrails.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cAI assistants, copilots, and agents significantly expand the enterprise attack surface in ways that traditional security architectures were not designed to handle,\u201d said Todd Thiemann, a\u00a0cybersecurity\u00a0analyst at research firm\u00a0Omdia.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Enter a series of AI-based features for\u00a0Proofpoint Prime Threat Protection\u00a0that were introduced at the company\u2019s Proofpoint Protect 2025 event in September. They thwart the efforts of\u00a0hackers\u00a0to subvert the actions of AI agents by scanning for potential threats before email messages arrive at an inbox.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Traditional Approach to Email Security<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Most email security tools are designed to spot known bad signals like suspicious links, fake domains that look real, or attachments carrying malware. This approach works well against conventional\u00a0phishing, spam, and known exploits. But cybercriminals are now going after the many AI assistants and AI agents that have become embedded in the workplace.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">They do this by taking advantage of prompts (questions or commands in text or code form) that guide\u00a0AI models\u00a0and AI agents to either produce relevant responses or execute certain tasks. Increasingly, emails carry hidden, malicious prompts that use invisible text or special formatting designed to trick\u00a0generative AI\u00a0tools like\u00a0Microsoft Copilot\u00a0and\u00a0Google Gemini\u00a0into taking unsafe actions, such as exfiltrating data or bypassing security checks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cPrompt injections and other AI-targeted exploits represent a new class of attacks that use text-based payloads that manipulate machine reasoning rather than human behavior,\u201d said Thiemann.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Daniel Rapp, Chief AI and Data Officer at\u00a0Proofpoint, provided an example: The standard used for email messages known as\u00a0RFC-822\u00a0lays out the use of headers, plain text, and\u00a0HTML. Not all of this is visible to a user. Attackers take advantage of this by embedding instructions in messages that are invisible to humans but fully readable by an AI agent. When AI processes the text, the embedded instructions are inadvertently executed. This can lead to data being exfiltrated or system behavior being altered or corrupted. Legacy filters looking for malware or malformed links see nothing amiss.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/spectrum.ieee.org\/media-library\/smiling-portrait-of-daniel-rapp.jpg?id=61774422&amp;width=900&amp;quality=85\" alt=\"Smiling portrait of Daniel Rapp.\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><small>Daniel Rapp, Chief AI and Data Officer at\u00a0Proofpoint.Proofpoint<\/small><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cIn recent attacks we are seeing cases where the HTML and plain text version are completely different,\u201d said Rapp. \u201cThe email client renders the HTML version while invisible plain text contains a prompt injection that can be picked up and possibly acted on by an AI system.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are two reasons why this strategy is proving effective: First, if an AI assistant has access to an inbox, it can automatically act on an email the instant it arrives. Second,\u00a0Rapp said the literal nature of AI agents makes them susceptible to phishing and other\u00a0social engineering\u00a0tricks. A human might think twice about sending money to a Nigerian bank account. An AI agent might blindly carry out a command to do so.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What differentiates the Proofpoint approach is that the company scans emails before they hit inboxes. It\u2019s had plenty of practice. The company scans 3.5 billion emails every day, one third of the global total. In addition, it scans close to 50 billion URLs and 3 billion attachments daily. This is done inline i.e., while the email is traveling from the sender to the recipient.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cWe have placed detection capabilities directly in the delivery path, which means latency and efficiency are critical,\u201d said Rapp.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This necessary level of speed is accomplished by training smaller AI models specifically on detection, based on examples and the foundational knowledge of a large language model (LLM). For example,\u00a0OpenAI\u2019s\u00a0GPT-5 is estimated to have as many as\u00a0635 billion parameters. Wading through that amount of data for every email isn\u2019t feasible. Proofpoint has fine-tuned its models down to about 300 million parameters. It distills and compresses its models to attain low-latency, in-line performance without sacrificing detection fidelity. It also updates those models every 2.5 days to be able to effectively interpret the intent of the message itself, not just scan for indicators. In this way, it spots concealed prompt injections, malicious instructions, and other AI exploits before delivery.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cBy stopping attacks pre-delivery, Proofpoint prevents user compromise and AI exploitation,\u201d said Rapp.\u00a0\u201cOur secure email gateway can see emails and stop threats before they hit the inbox.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In addition, Proofpoint uses an ensemble detection architecture. Instead of relying on a single detection mechanism, it combines hundreds of behavioral, reputational, and content-based signals to get around attack vectors that might navigate their way past one method.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">AI Changes the Security Game<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">AI agents are being rolled out across the enterprise and consumer landscape. Unfortunately, the rush to capitalize on AI\u2019s potential often relegates security to an afterthought. The bad guys know this. They are AI-enabling their\u00a0cybercrime\u00a0techniques and technologies to perfect the art of phishing for the AI agent era.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">\u201cSecurity tooling must evolve from detecting known bad indicators to interpreting intent for humans, machines, and AI agents,\u201d said Thiemann. \u201cApproaches that identify malicious instructions or manipulative prompts pre-delivery, ideally using distilled AI models for low-latency inline protection, address a significant gap in today\u2019s defenses.\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Proofpoint is ahead of the pack with the role out of these capabilities. Expect other cybersecurity vendors to follow suit in the coming months. By that time, however, what other AI-borne threat will emerge?<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Email security has always been&hellip;<\/p>\n","protected":false},"author":2,"featured_media":580,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[8,4],"tags":[25,24,127,128,129],"class_list":["post-579","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-deep-tech","category-policy-impact","tag-agent","tag-ai","tag-email","tag-phishing","tag-virus"],"_links":{"self":[{"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/posts\/579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/comments?post=579"}],"version-history":[{"count":1,"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/posts\/579\/revisions"}],"predecessor-version":[{"id":581,"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/posts\/579\/revisions\/581"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/media\/580"}],"wp:attachment":[{"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/media?parent=579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/categories?post=579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.finndy.com\/index.php\/wp-json\/wp\/v2\/tags?post=579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}