An executive asks their AI assistant to summarize overnight emails before their morning meeting. One email — sent by a competitor's contractor — contains hidden instructions below a wall of whitespace. The agent reads the instructions, locates the executive's NDA drafts and board communications, and encodes them into an analytics pixel URL that fires silently.
The executive receives a clean summary. Their confidential documents are already gone.
A vendor shares a project brief via a shared drive link. An employee asks their AI agent to review the document and extract the key deliverables. The document contains injected instructions in white-on-white text at the bottom. The agent extracts the deliverables — and also follows the hidden instruction to forward the employee's internal project roadmap to an external email address using the email tool it has access to.
The employee gets their summary. The roadmap is in a stranger's inbox.
A SaaS company deploys an AI support agent with access to its customer database to help users track orders. An attacker submits a "support request" that begins with normal-sounding text and ends with an instruction to list all accounts with unpaid invoices and their associated email addresses. The agent — lacking strict goal enforcement — complies.
The attacker gets a structured customer list. No SQL injection required.