Indirect Prompt Injection Hijacking the System
間接提示注入劫持系統
When an organization's email assistant reads an incoming message containing hidden instructions and automatically forwards internal data to an external address; due to unmitigated control gaps, the user merely received a normal email and noticed nothing unusual, triggering external stakeholder impacts and causing the incident is discovered only through audit log comparison.
Framework Mappings
Risk Treatment & Implementation Guidance
Apply trust tiers to external content so instructions inside untrusted material like email are never executed as system directives; Detect hidden content, identifying embedded instruction patterns in messages and documents; Restrict exfiltration-capable actions like auto-forwarding with policy limits and human confirmation so agents cannot send internal data externally on their own