[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6-Scp6ZMCsnHd_VTpQAnv0WzVSmFHfF3d5C3Y88jyfI":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"68b89181-b32e-49ca-bb66-a212c67b6bbb","Fake Email Thread Tricks AI Summarizer Without Hidden Text","fake-email-thread-tricks-ai-summarizer-without-hidden-text-8110b3","Forcepoint X-Labs has published new research showing that indirect prompt injection against AI email summarizers can work without…","Forcepoint X-Labs research demonstrates that AI email summarizers can be manipulated through indirect prompt injection, even without hidden text or explicit commands. By inserting forged content into an email thread, attackers can alter the AI-generated summary to reflect fabricated details, such as incorrect dates and invoice amounts. This bypasses traditional detection methods that rely on hidden text or instruction-like phrasing, highlighting a new vulnerability in AI-powered summarization tools.","AI email summarizers can be tricked by forged email threads without hidden text.","Security Artificial IntelligenceFake Email Thread Tricks AI Summarizer Without Hidden TextbyDeeba AhmedSeptember 28, 20262 minute read Listen to this article 0:00 — ← 10s ▶ Play 10s → Speed 0.75× 1× 1.25× 1.5× 2× Voice Loading voices… Press play to start listening Forcepoint X-Labs has published new research showing that indirect prompt injection against AI email summarizers can work without hidden text or instruction-like commands, allowing forged content in an email thread to alter the resulting summary. Senior researcher Ben Gibney led the study, following an August 2026 proof of concept in which hidden HTML content altered an AI-generated email summary. A Forged Email Thread Fooled the Summarizer The researchers created six test emails using three presentation methods: plain view, 30 blank lines of padding, and hidden styling. Each method was tested both with and without explicit instructions to the AI. They ran each sample 10 times across 60 trials, using an unguarded Outlook-based pipeline powered by Claude Haiku 4.5 at temperature zero. The original message listed a quarterly supplier review for August 24, 2026, and an outstanding invoice of €8,650. A forged second header block inserted into the email thread changed those details to September 3, 2026, and €46,200. AI-generated summaries showing the original details (top) and the fabricated date and invoice amount (bottom) (Source: Forcepoint X-Labs) The results were consistent across all 60 trials, with every summary containing the fabricated date and invoice amount. In the plain-view, no-instruction test, the forged message still produced the false details in all 10 runs. Because the fake content appeared as another message in the email thread, there was no instruction-like wording for a keyword- or pattern-based detector to flag. As Gibney explained in the latest Forcepoint analysis, which was shared with Hackread.com, “the instruction in these samples is carried by the structure of two messages in an email thread rather than wording.” The earlier proof of concept had combined hidden HTML and direct instructions to manipulate the same summarizer. The new tests separated those variables, showing that concealment was not required for fabricated information to appear in the output. Forcepoint’s Outlook-based email summarizer processing the forged thread and returning the altered meeting date and invoice amount (Source: Forcepoint X-Labs) Direct Instructions Changed What the AI Kept The researchers also found that explicit instructions changed which information remained in the summary. Those samples consistently removed the genuine facts from the summary. Without direct instructions, the true €8,650 amount and other details could survive, but some were pushed into a smaller “Note” section. Another unexpected result appeared when the researchers added 30 blank lines. The summarizer dropped half of the pre-registered facts in that test, although Forcepoint said it could not determine why. The findings come as researchers examine other ways email content can appear differently to users, security tools and AI systems. Microsoft recently reported attackers using invisible Unicode characters to evade email filtering in phishing campaigns. The study does not show that all email security filters fail. The experiment used one email client, one model, synthetic data, and an intentionally unguarded pipeline. Forcepoint said the results also do not establish how the behavior changes with other models, higher temperature settings, or additional guardrails. However, the research shows why hidden-text detection and instruction scanning should not be treated as complete defenses. Malicious information presented as ordinary content inside an email thread can also influence an AI-generated summary without obvious prompt-like instructions. Deeba Ahmed Deeba is a veteran cybersecurity reporter at Hackread.com with over a decade of experience covering cybercrime, vulnerabilities, and security events. Her expertise and in-depth analysis make her a key contributor to the platform’s trusted coverage. View Posts AI SummarizerAI SummaryCybersecurityForcepointPrivacyTechnology Leave a Reply Cancel reply View Comments (0) Related Posts Read More Malware Security New variant of PRISM Backdoor ‘WaterDrop’ targets Linux systems According to researchers, the PRISM backdoor has been on their radar for more than 3.5 years. byDeeba Ahmed Read More Hacking News Leaks Security OurMine hacks video hosting service Vevo; leaks 3.12TB data online Vevo Becomes Victim of Targeted Data Breach – OurMine Hackers Posted 3.12TB worth of Data Online. The Self-claimed… byWaqas Read More Security Vulnerability in Samsung Galaxy S4 allows hacker to track emails and record communication data Critical vulnerability in Samsung Galaxy S4 allows hacker to install a malicious code, track emails and record sensitive… byWaqas Read More Security Artificial Intelligence Why AI Systems Need Red Teaming Now More Than Ever AI systems are becoming a huge part of our lives, but they are not perfect. Red teaming helps… byUzair Amir","https:\u002F\u002Fhackread.com\u002Ffake-email-thread-tricks-ai-summarizer-hidden-text\u002F","https:\u002F\u002Fhackread.com\u002Fwp-content\u002Fuploads\u002F2026\u002F09\u002Ffake-email-thread-tricks-ai-summarizer-hidden-text.jpg","2026-09-28T15:11:54+00:00","2026-09-28T18:00:35.298452+00:00",7,[18,21,24,27],{"name":19,"type":20},"Claude Haiku 4.5","product",{"name":22,"type":23},"Forcepoint","vendor",{"name":25,"type":26},"AI email summarizers","technology",{"name":28,"type":20},"Outlook","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":29,"icon":31,"name":32,"slug":33},null,"AI Security","ai-security",[35,40,42],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":41},{"id":29,"icon":31,"name":32,"slug":33},{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]