Press play to start listening
Forcepoint X-Labs has published new research showing that indirect prompt injection against AI email summarizers can work without hidden text or instruction-like commands, allowing forged content in an email thread to alter the resulting summary.
Senior researcher Ben Gibney led the study, following an August 2026 proof of concept in which hidden HTML content altered an AI-generated email summary.
A Forged Email Thread Fooled the Summarizer
The researchers created six test emails using three presentation methods: plain view, 30 blank lines of padding, and hidden styling. Each method was tested both with and without explicit instructions to the AI. They ran each sample 10 times across 60 trials, using an unguarded Outlook-based pipeline powered by Claude Haiku 4.5 at temperature zero.
The original message listed a quarterly supplier review for August 24, 2026, and an outstanding invoice of €8,650. A forged second header block inserted into the email thread changed those details to September 3, 2026, and €46,200.

The results were consistent across all 60 trials, with every summary containing the fabricated date and invoice amount. In the plain-view, no-instruction test, the forged message still produced the false details in all 10 runs. Because the fake content appeared as another message in the email thread, there was no instruction-like wording for a keyword- or pattern-based detector to flag.
As Gibney explained in the latest Forcepoint analysis, which was shared with Hackread.com, “the instruction in these samples is carried by the structure of two messages in an email thread rather than wording.”
The earlier proof of concept had combined hidden HTML and direct instructions to manipulate the same summarizer. The new tests separated those variables, showing that concealment was not required for fabricated information to appear in the output.

Direct Instructions Changed What the AI Kept
The researchers also found that explicit instructions changed which information remained in the summary. Those samples consistently removed the genuine facts from the summary. Without direct instructions, the true €8,650 amount and other details could survive, but some were pushed into a smaller “Note” section.
Another unexpected result appeared when the researchers added 30 blank lines. The summarizer dropped half of the pre-registered facts in that test, although Forcepoint said it could not determine why.
The findings come as researchers examine other ways email content can appear differently to users, security tools and AI systems. Microsoft recently reported attackers using invisible Unicode characters to evade email filtering in phishing campaigns.
The study does not show that all email security filters fail. The experiment used one email client, one model, synthetic data, and an intentionally unguarded pipeline. Forcepoint said the results also do not establish how the behavior changes with other models, higher temperature settings, or additional guardrails.
However, the research shows why hidden-text detection and instruction scanning should not be treated as complete defenses. Malicious information presented as ordinary content inside an email thread can also influence an AI-generated summary without obvious prompt-like instructions.