Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google
    Cybersecurity

    Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google

    adminBy adminApril 27, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    AI Jailbreak
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Google has analyzed AI indirect prompt injection attempts involving sites on the public web and noticed an increase in malicious attacks over the past months, but the tech giant’s researchers say their sophistication is relatively low.

    Direct prompt injection is a ‘jailbreak’ where a user interacts with the AI to bypass its rules, whereas indirect prompt injection is a ‘hidden trap’ where the AI is tricked by malicious instructions found in external data.

    Cybersecurity researchers have discovered many indirect prompt injection methods in recent years, using specially crafted prompts planted on websites, in emails, and developer resources to trick Gemini, Copilot, ChatGPT, and other gen-AI tools into bypassing security and facilitating data theft.

    While many theoretical attack methods exist, threat intelligence experts at Google recently set out to determine the extent to which these AI vulnerabilities are being exploited in the wild.

    Specifically, their research focused on indirect prompt injection attempts set up on websites on the public internet. They scanned the website snapshots saved by Common Crawl for known prompt injection patterns and used Gemini and human reviews to weed out false positives.

    An analysis of the identified prompt injections found harmless pranks, attempts to deter AI agents, search engine optimization, and helpful guidance, as well as some malicious attacks.

    Advertisement. Scroll to continue reading.

    Prank prompt injections can, for instance, instruct visiting AI assistants to change their behavior (eg, act like a baby bird and tweet like a bird). 

    Some website owners place helpful instructions for AI tasked with summarizing a site, but others add prompts designed to prevent assistants from crawling the website, including by telling the AI that the content is dangerous and sensitive. 

    Google researchers have also come across websites whose administrators attempt to boost SEO by instructing AI assistants to claim their company is the best.

    The most important, however, from a security standpoint are the malicious prompt injection attempts. The researchers uncovered two types of such attacks: exfiltration and destruction.

    Some websites contained prompts instructing AI to collect data, including IPs and credentials, and send it to an attacker-specified email address. 

    “However, for this class of attacks, sophistication seemed much lower,” the Google researchers said, adding, “We did not observe significant amounts of advanced attacks (eg, using known exfiltration prompts published by security researchers in 2025). This seems to indicate that attackers have yet not productionized this research at scale.”

    In the destruction category, some prompts attempted to trick AI into deleting all files on the user’s machine, but the researchers noted that such attacks are unlikely to succeed. 

    While they did not see any particularly sophisticated attacks, the Google experts pointed out that they did see a 32% increase in malicious prompt injection attempts between November 2025 and February 2026. They warned that both the scale and sophistication of prompt injection attacks are expected to increase in the near future.

    “Our findings indicate that, while past attempts at IPI attacks on the web have been low in sophistication, their upward trend suggests that the threat is maturing and will soon grow in both scale and complexity,” the researchers concluded. 

    Related: Why Cybersecurity Must Rethink Defense in the Age of Autonomous Agents

    Related: Trump Administration Vows Crackdown on Chinese Companies ‘Exploiting’ AI Models Made in US

    attacks Google Increasing Injection Malicious Prompt sophistication
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleGinny Marvin on 20 years of change from manual PPC to AI
    Next Article How to summarize your AI visibility
    admin
    • Website

    Related Posts

    Robinhood account creation flaw abused to send phishing emails

    April 28, 2026

    UNC6692 Combines Social Engineering, Malware, Cloud Abuse

    April 27, 2026

    Fast16 Malware, XChat Launch, Federal Backdoor, AI Employee Tracking & More

    April 27, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Congress Must Reject New Insufficient 702 Reauthorization Bill

    April 28, 2026

    Bing Previews AI Citation Share For Webmaster Tools

    April 28, 2026

    Robinhood account creation flaw abused to send phishing emails

    April 28, 2026

    How to summarize your AI visibility

    April 27, 2026
    Categories
    • Blogging (69)
    • Cybersecurity (1,544)
    • Privacy & Online Earning (186)
    • SEO & Digital Marketing (944)
    • Tech Tools & Mobile / Apps (1,796)
    • WiFi / Internet & Networking (247)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Congress Must Reject New Insufficient 702 Reauthorization Bill

    April 28, 2026

    Bing Previews AI Citation Share For Webmaster Tools

    April 28, 2026

    Robinhood account creation flaw abused to send phishing emails

    April 28, 2026
    Most Popular
    • Congress Must Reject New Insufficient 702 Reauthorization Bill
    • Bing Previews AI Citation Share For Webmaster Tools
    • Robinhood account creation flaw abused to send phishing emails
    • How to summarize your AI visibility
    • Malicious AI Prompt Injection Attacks Increasing, but Sophistication Still Low: Google
    • Ginny Marvin on 20 years of change from manual PPC to AI
    • UNC6692 Combines Social Engineering, Malware, Cloud Abuse
    • Why AI Is Citing Third-Party Sources Instead of Your Site?
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.