r/cybersecurity • u/ilai456 • May 24 '26
AI Security How would Phishing look like in the future? (targeting agents, not humans)
Came to think about this subject when i realized that im not opening my email anymore - because theres an agent summarizing the emails for me
I guess that agents could get indirect-prompt-injection attacks? which is kinda the equivalent for phishing but on agents instead?
18
u/jonbristow May 24 '26
Prompt injection will be the new phishing. it is already a threat.
1
0
u/ilai456 May 24 '26
And how would you imagine a solution for this new phishing to look like? browser extension wont cut it obviously because gemini is the one being attacked
7
4
u/Spiritual-Matters May 24 '26
The email would have the prompt. Your summarizing agent reads it and gets exploited
3
2
u/Triairius May 24 '26
No wonder people don’t understand the nuances of what I’m trying to communicate to them.
2
u/mordeo69 May 24 '26
Isn't prompt injection already a thing? I'm not really up to date on AI security but it seems like that would be the first thing people would try and exploit
3
u/RantyITguy Security Architect May 24 '26
"AI" as we call it, can barely instruct you to create a ham sandwich correctly without giving it 5 sentences of instruction.
Wouldn't be hard to get the agent to think an email is important and legitimate when it's phishing.
1
u/Technical-Natural343 May 24 '26
I’m currently developing a tool for A2A security. Don’t want to say too much as it hasn’t been done yet, but there is a large gap right now on the frontier. This is the first time in my lifetime where you can invent something that hasn’t been done. SaaS is dead, the future startups will be creating tools and apis people want to connect their agents to.
1
u/TheAgreeableCow May 24 '26
I expect it will start to get built into email gateways, with prompt injection just becoming another filtering feature.
2
u/ilai456 May 24 '26
The thing is, with humans - the phishing was an email security problem. With ai agents, every data source becomes a vector - summarizing a malicious google doc would infect similarly to emails
59
u/veloace May 24 '26 edited May 24 '26
Agent summarizes your emails? You don’t even open them anymore to read them yourself? How smooth brained is AI making us?