Throughout every move via the injected e mail, the abstract output reported an bill deadline of September 3, 2026, as a substitute of the particular August 21, 2026, and omitted the title “Diego Siciliani” talked about within the authentic e mail. This was precisely what the injected directions had requested the summarizer to do.
The mannequin used to drive the summarizer on this investigation was Claude-haiku-4-5. Nevertheless, Forcepoint clarifies that there isn’t a particular problem with an LLM supplier or a business summarizer, however relatively a common threat in how untrusted e mail is fed to an LLM with out safeguards.
“The assault isn’t in opposition to Outlook, any named summarizers, or the mannequin used to drive the summarizer,” Gibney stated. To guard in opposition to such immediate injections, Forcepoint recommends extracting solely content material seen to the consumer, detecting hidden or suspicious HTML/CSS styling, separating e mail headers from the physique, treating e mail content material as untrusted information, and validating AI-generated summaries in opposition to the unique supply.


