DKDKCISSPSearch
AI SecurityDEVELOPING

Attackers Hide AI Prompt Injections Inside Phishing Emails

In research published on October 7, Barracuda said it analyzed a campaign that combined traditional social engineering, such as password-protected attachments, with prompt injection concealed in the same message.

DKCISSP News DeskInfosecurity Magazine7 Oct 2026, 6:30 pm
Attackers Hide AI Prompt Injections Inside Phishing Emails
Image courtesy of Infosecurity Magazine. Original report
DKCISSP REPORT

In research published on October 7, Barracuda said it analyzed a campaign that combined traditional social engineering, such as password-protected attachments, with prompt injection concealed in the same message.

Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, included in the bizarre push notification sent to ASOS customers on October 6 where a threat actor claimed to have hacked the company via a Snowflake instance.

ASOS’ first communication regarding the hacker claims confirmed the firm was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers." The company said it took "immediate action to restrict access to the notification platforms" and is "working with our internal and external specialist advisers, as well as all relevant authorities." The company also acknowledged that basic personal information including names and contact details may have been accessed by the threat actor, but the investigators do not believe payment-card information or account passwords were impacted.

She found that the channel was brand new – created on October 6 – and that the Telegram account behind it, now ‘Xuanyewen’ (@xuanyegroup), previously carried other names, largely in gaming-item trading.

She also told Infosecurity she has not yet found any evidence to verify the claims that the group has access to ASOS customer data.

Additionally, ASOS confirmed that its website and app are operating as normal, and that the company's operations are fully unaffected.

Injected instructions could also tell an assistant to ignore its previous directions and request a wire transfer, leak data or surface a fake urgent action.

However, the fashion retailer did not mention Snowflake in any of its statements and the cloud service firm told Infosecurity it has found “no compromise of the Snowflake platform.” Group-IB’s Tikhonova noted that “being able to send a notification shows access to a customer-messaging channel, not possession of a customer database.” Will Thomas, senior threat intelligence advisor at Team Cymru, assessed that this incident likely points in the direction of some form of a software-as-a-service (SaaS) platform compromise, an approach that has been used in high-profile attacks on UK retailers over recent years.

Opening it would lead to credential theft or malware delivery.

It also described hidden text in a resume telling an AI screening tool to rate the candidate 10 out of 10, a fake maintenance-mode request to make a support bot reveal its configuration and poisoned web documentation that could make a coding assistant insert a credential-exfiltration line into authentication code.

What happened

In research published on October 7, Barracuda said it analyzed a campaign that combined traditional social engineering, such as password-protected attachments, with prompt injection concealed in the same message.

Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, included in the bizarre push notification sent to ASOS customers on October 6 where a threat actor claimed to have hacked the company via a Snowflake instance.

What changed

ASOS’ first communication regarding the hacker claims confirmed the firm was investigating unauthorized activity "involving third-party platforms that we use to communicate with customers." The company said it took "immediate action to restrict access to the notification platforms" and is "working with our internal and external specialist advisers, as well as all relevant authorities." The company also acknowledged that basic personal information including names and contact details may have been accessed by the threat actor, but the investigators do not believe payment-card information or account passwords were impacted.

She found that the channel was brand new – created on October 6 – and that the Telegram account behind it, now ‘Xuanyewen’ (@xuanyegroup), previously carried other names, largely in gaming-item trading.

Who is affected

She also told Infosecurity she has not yet found any evidence to verify the claims that the group has access to ASOS customer data.

Additionally, ASOS confirmed that its website and app are operating as normal, and that the company's operations are fully unaffected.

Why it matters

Injected instructions could also tell an assistant to ignore its previous directions and request a wire transfer, leak data or surface a fake urgent action.

However, the fashion retailer did not mention Snowflake in any of its statements and the cloud service firm told Infosecurity it has found “no compromise of the Snowflake platform.” Group-IB’s Tikhonova noted that “being able to send a notification shows access to a customer-messaging channel, not possession of a customer database.” Will Thomas, senior threat intelligence advisor at Team Cymru, assessed that this incident likely points in the direction of some form of a software-as-a-service (SaaS) platform compromise, an approach that has been used in high-profile attacks on UK retailers over recent years.

Technical details

Opening it would lead to credential theft or malware delivery.

It also described hidden text in a resume telling an AI screening tool to rate the candidate 10 out of 10, a fake maintenance-mode request to make a support bot reveal its configuration and poisoned web documentation that could make a coding assistant insert a credential-exfiltration line into authentication code.

Tikhonova also stressed that attackers target the platforms and integrations companies depend on, “because one point of access reaches a long way” and retailers are particularly vulnerable to such techniques.

Response

Among real-world examples, Barracuda described a hidden block in an invoice email that told the summarizing AI to add a fake priority action changing vendor payment details, nudging an employee toward wiring money to the attacker.

It recommended stripping hidden elements and invisible characters before content reaches AI systems, detecting instruction-override language, AI sandboxing, output validation and human approval for payments and vendor changes.

What security teams should do

It said external content should always be treated as data, kept separate from instructions.

It also advised monitoring for repeated injection attempts.

Attribution

Infosecurity Magazine: In research published on October 7, Barracuda said it analyzed a campaign that combined traditional social engineering, such as password-protected attachments, with prompt injection concealed in the same message.

Infosecurity Magazine: Anastasia Tikhonova, global head of threat research at Group-IB, investigated the Telegram channel t.me/xuanyewengateway, included in the bizarre push notification sent to ASOS customers on October 6 where a threat actor claimed to have hacked the company via a Snowflake instance.

MORE IN AI SECURITY

More cybersecurity reporting

Anthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsThe Hacker News · 10 Oct 2026, 6:54 pmWikimedia Says Rogue AI Agents Abused its PlatformsInfosecurity Magazine · 9 Oct 2026, 8:30 pmHow AI can fix cybersecurity compliance: From dashboards to continuous execution - Help Net SecurityHelp Net Security · 8 Oct 2026, 10:30 amPoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining BotnetThe Hacker News · 7 Oct 2026, 9:03 pm