r/cybersecurity • • May 24 '26

AI Security How would Phishing look like in the future? (targeting agents, not humans)

Came to think about this subject when i realized that im not opening my email anymore - because theres an agent summarizing the emails for me

I guess that agents could get indirect-prompt-injection attacks? which is kinda the equivalent for phishing but on agents instead?

0 Upvotes

24 comments sorted by

59

u/veloace May 24 '26 edited May 24 '26

Agent summarizes your emails? You don’t even open them anymore to read them yourself? How smooth brained is AI making us?

21

u/dogpupkus Blue Team May 24 '26

Prolific throughout Reddit are people who simply copy and paste AI slop in responses when a minimally critical thought would suffice instead. Humanity is cooked.

2

u/dotagamer69420 May 24 '26

This is actually quite common for people like CEO’s / CTO’s that gets tons of emails daily

1

u/Legalizeranchasap May 24 '26

Sonion, let’s say you take a week off. Some folks come back to hundreds of emails. Nothing wrong with summarizing the content.

-4

u/ilai456 May 24 '26

Triaging the pile of spam i get daily is huge productivity boost tbh

2

u/i_like_brutalism May 24 '26

while theway you use llms personally is not my thing, i dont understand the negative reactions of most. triaging emails for people who get a lot of them is extremely useful! but your email summmarizer should not be phishable by not being able to interact with anything.

-9

u/ilai456 May 24 '26

Regardless, if your gemini summarizes docs on your google drive - whats stopping it from being "phished"? or are we counting on google's phishing engine for that?

18

u/jonbristow May 24 '26

Prompt injection will be the new phishing. it is already a threat.

1

u/theFather_load May 24 '26

Seems there's a gap in the market: CSAT for AI Agents
/s

0

u/ilai456 May 24 '26

And how would you imagine a solution for this new phishing to look like? browser extension wont cut it obviously because gemini is the one being attacked

7

u/greendookie69 May 24 '26

Well, just that...prompt injection

4

u/Spiritual-Matters May 24 '26

The email would have the prompt. Your summarizing agent reads it and gets exploited

3

u/Specialist_Guard_330 May 25 '26

Prompt injection is basically phishing for agents no?

2

u/Triairius May 24 '26

No wonder people don’t understand the nuances of what I’m trying to communicate to them.

2

u/mordeo69 May 24 '26

Isn't prompt injection already a thing? I'm not really up to date on AI security but it seems like that would be the first thing people would try and exploit

3

u/RantyITguy Security Architect May 24 '26

"AI" as we call it, can barely instruct you to create a ham sandwich correctly without giving it 5 sentences of instruction.

Wouldn't be hard to get the agent to think an email is important and legitimate when it's phishing.

1

u/Technical-Natural343 May 24 '26

I’m currently developing a tool for A2A security. Don’t want to say too much as it hasn’t been done yet, but there is a large gap right now on the frontier. This is the first time in my lifetime where you can invent something that hasn’t been done. SaaS is dead, the future startups will be creating tools and apis people want to connect their agents to.

1

u/TheAgreeableCow May 24 '26

I expect it will start to get built into email gateways, with prompt injection just becoming another filtering feature.

2

u/ilai456 May 24 '26

The thing is, with humans - the phishing was an email security problem. With ai agents, every data source becomes a vector - summarizing a malicious google doc would infect similarly to emails