Attackers are beginning to hide malicious instructions inside ordinary emails, documents, calendar invites, and online advertisements. The goal is not always to fool a person.
Instead, the hidden text is designed to manipulate the artificial intelligence tools that scan, summarize, and protect digital communications.
This technique, called indirect prompt injection, can turn trusted AI assistants into an unexpected target.
A message may look harmless to an employee while containing instructions that an AI mail agent reads as commands, potentially pushing it toward unsafe actions or data exposure.
Analysts at Proofpoint identified growing discussions and sales activity around these methods in underground forums.
The activity suggests criminals are developing tools to create hidden prompts at scale, even though widespread real-world abuse has not yet been observed.

The shift matters because AI systems increasingly review inbound mail, attachments, calendars, and websites before users ever see them. Criminals are now looking for ways to exploit that automated access, adding another layer of risk to already familiar phishing and social-engineering attacks.
Proofpoint said in a report shared with Cyber Security News (CSN) that the emerging tools are still experimental, but organizations should prepare for their use.
The researchers noted that subscriptions advertised in criminal spaces start at roughly $150 per month.
Hackers Are Hiding Commands in Emails
Indirect prompt injection works when an AI system processes content from an outside source and mistakes hidden instructions for legitimate requests.
Unlike a direct prompt attack, where someone enters a command into a chatbot, this approach lets attackers conceal commands in content that an AI agent reads automatically.

One advertised email-generation tool creates messages containing white-on-white text.
Recipients may see a normal email, but the invisible wording can still be available to a mail-processing agent, a tactic closely related to concerns raised in AI prompt injection attacks that target email-based workflows.
Attackers can use the same idea in attachments. Proofpoint observed examples involving PDF and DOCX files that appear to be ordinary documents, including a sample non-disclosure agreement, while carrying embedded text intended to influence an AI scanning agent.
The danger depends on what permissions the AI system has. An agent that can summarize messages presents a different risk from one that can search files, send content, open links, or connect to cloud services.
Hidden instructions become more serious when an AI tool can act without clear human approval.
Security teams should therefore treat external content as untrusted, even when it arrives in a familiar format.
Separating untrusted text from system instructions, limiting what AI agents can access, and requiring human confirmation for important actions can reduce the chance that a concealed command causes harm.
Calendar Invites Expand Risk
Criminals are also developing prompt-injection generators for calendar invitations.
The malicious instruction can be written into an event description disguised as a meeting agenda, allowing an AI assistant that summarizes calendar content to process it without the recipient clicking a link or accepting the invitation.
This is an important change from conventional calendar phishing. Earlier campaigns generally relied on a person opening an invite or visiting a linked page, but an AI agent may inspect an invitation as part of routine work, echoing risks seen when calendar files become weaponized.

Proofpoint also found interest in placing prompts within malicious advertisements and webpages.
Hidden commands could be stored in HTML, image alternative text, tiny fonts, or other elements that a human visitor may overlook while an automated browser or AI assistant still processes them.
Organizations should review where AI tools ingest email, files, calendars, and web content, then apply strict access controls around sensitive data and actions.
Employees should continue reporting suspicious messages and unexpected invites, while security teams watch for evolving phishing campaign tactics that combine familiar delivery methods with AI-focused manipulation.
The research does not describe a widespread campaign using these techniques today.
However, the active development and marketing of related tools shows that attackers are preparing for a future in which AI systems are a routine part of the attack surface, rather than simply another line of defense.