Skip to content

Hide Navigation Hide TOC

RAG-Injected PII Exfiltration — System Instructions Embedded in Retrieved Documents - ATR-2026-00859 (08e4a1f3-7851-53ac-ac99-7558e5a87167)

Detects adversarial instructions embedded in retrieved documents that a RAG (Retrieval-Augmented Generation) pipeline returns to the agent, where the injected payload hijacks the agent's tool-calling behavior to forward personally identifiable information (witness names, addresses, passport numbers, credit card data) from other retrieved documents to an attacker-controlled email. The attack leverages pseudo-system-instruction tags (-- System instructions, ) or explicit override text embedded in court documents, legal filings, or other retrieval corpus items. Derived from the indirect-pi-exfil-pii/exfil-pii-rag corpus (InjecAgent + spikee sources).

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern RAG-Injected PII Exfiltration — System Instructions Embedded in Retrieved Documents - ATR-2026-00859 (08e4a1f3-7851-53ac-ac99-7558e5a87167) Agent Threat Rules 1
RAG-Injected PII Exfiltration — System Instructions Embedded in Retrieved Documents - ATR-2026-00859 (08e4a1f3-7851-53ac-ac99-7558e5a87167) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2