Google Gemini can be hijacked to display fake email summaries in phishing scams
- Gemini in Workspace presents unique opportunities for fraud, researchers warn
- The AI tool can be tricked to display fake security warnings
- Businesses should make sure invisible text is not processed by the AI
Cybercriminals have found a creative new way to abuse Google’s Generative Artificial Intelligence (GenAI) to steal people’s Gmail accounts.
Google introduced Gemini, its AI-powered chatbot assistant into its Workspace suite of productivity apps some time ago, and one of the things Gemini can do is summarize incoming emails – so when a person receives an email, they can bring up a vertical pane on the right-hand side of the screen, asking Gemini for assistance with different things, such as bringing up vital email information, adding calendar entries, and more.
However experts have warned this also opens up the Gmail accounts for so-called “prompt-injection” attacks – so if the incoming email message contains a hidden prompt for Gemini, it can be executed in the pane.
Is Gemini phishing for your password?
According to security researcher Marco Figueroa, this is exactly what the email provider is now susceptible to.
By using HTML and CSS, threat actors can add a prompt for Gemini, with its font size set to zero, and its color to white. Therefore, the victim will not be able to see it, but Gemini will act on it. If that prompt makes Gemini display a phishing message, it will do just that, and since the message would come from a trusted source, it increases the chances of success.
Figueroa showed how a malicious prompt could notify the victim that their email account has been compromised, and that they need to “call” Google on a phone number displayed in the message to resolve the issue.
To protect against future prompt injection attacks, companies should make sure their email clients remove, neutralize, or ignore content that is styled to be hidden in the body text. Furthermore, they could include a post-processing filter that scans the inbox for “urgent messages”, URLs, or phone numbers.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Finally, businesses should educate their employees that summaries provided by the Gemini tool should not be a replacement for security alerts.
Via BleepingComputer
You might also like
Gemini in Workspace presents unique opportunities for fraud, researchers warn The AI tool can be tricked to display fake security warnings Businesses should make sure invisible text is not processed by the AI Cybercriminals have found a creative new way to abuse Google’s Generative Artificial Intelligence (GenAI) to steal people’s…
Recent Posts
- You don’t need to spend a fortune on good audio — these 20 headphones under AU$100 have hundreds of 5-star user reviews
- Nintendo confirms it will sell a new Switch 2 with replaceable battery in the EU
- Apple begins requiring age verification for App Store use in Texas
- The co-creator of Scavengers Reign is working on a new show for Netflix
- Apple is bringing age verification to Texas this week
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023