Digital Needle illustrating a Prompt Injection

Google Warns of Prompt Injection Attacks on AI Platforms

Indirect prompt injection can let attackers manipulate AI systems through compromised external content and tools.

Google’s security team is warning of a dangerous attack method that could allow threat actors to manipulate AI platforms.

Known as indirect prompt injection, the technique exploits the way large language model, or LLM, tools pull input from multiple sources when processing user queries. Google describes it as an “evolving threat vector” affecting complex AI applications with multiple data sources, including Workspace with Gemini.

If an attacker can map that input chain and gain access to one of those sources, it may be possible to poison part of the chain with malicious instructions that are then incorporated into the model’s processing. In that scenario, a threat actor could quietly taint the system’s inputs and influence its output over time. In security terms, the risk is less like a traditional man-in-the-middle attack and more like poisoning a trusted upstream source the AI depends on.

“This technique enables the attacker to influence the behavior of an LLM by injecting malicious instructions into the data or tools used by the LLM as it completes the user’s query,” Adam Gavish of the Google GenAI Security Team wrote. “This may even be possible without any input directly from the user.”

At RSAC 2026, prompt injection attacks were identified as a OWASP Top 10 for Large Language Model (LLM) Applications and the emerging OWASP Top 10 Risks for Agentic Applications (2026).

OWASP warns that attackers can manipulate a model through crafted inputs, including indirect prompt injection delivered through outside content the model treats as trustworthy.

Gavish said Google’s security team has been using several techniques to counter the indirect prompt injection threat. One is automated red-teaming. In that approach, machine-learning-driven frameworks generate and iterate on attack payloads to stress-test environments at scale and validate whether defenses hold up across a wider range of edge cases than manual testing alone could cover.

The AI security team also feeds in reports from publicly disclosed AI attacks, open-source intelligence feeds and findings from human red-team exercises. Those inputs are reproduced, cataloged and used to help harden the security and integrity of Google’s AI services and LLM platform.

“This process is essential because it allows the team to develop attack variants for completeness and coverage, and to prepare new training and validation data sets,” Gavish wrote. “This accelerated workflow has boosted synthetic data generation by 75%, supporting large-scale defense model evaluation and retraining, as well as updating the data set used for calculating and reporting on defense effectiveness.”

OWASP’s guidance stresses that the risk is not limited to chat prompts typed by a user; it can also arrive through documents, websites, emails and other external data sources connected to the model.

Shaun Nichols headshot

Shaun Nichols is an IT news journalist. He has spent nearly 20 years covering the industry with a specialty in the cybersecurity

Photo by Simon Takatomi on Unsplash

Total
0
Shares
Previous Article
Cartoon monitor displaying text: LOCKED OUT!, TRY AGAIN IN 59:59 MINUTES, INCORRECT PASSWORD! (AGAIN!).

Account Recovery is Broken

Next Article
Broken link with npm logo breaking connection to a world globe

Axios npm Hack Widens Beyond Initial Package

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading