Free Consultation
Home Incident Radar Indirect prompt-injection data exfiltration
AI incident

Indirect prompt-injection data exfiltration

Multiple (Bing/Copilot demos) · 2023

Organisation
Multiple (Bing/Copilot demos)
Year
2023
Failure mode
Prompt injection
Severity
critical
Agentic
Yes — an AI system acting, not just advising
Source
Security research, 2023

What happened

Hidden instructions in web pages/emails hijacked assistants into leaking data or taking actions.

What would have prevented it

Input/output filtering + least-privilege tool access

Requirements this maps to

Editorial cross-reference from our prevention note — it is not a finding that any law was breached.