Skip to content

Hide Navigation Hide TOC

Indirect PI — Medical Record / Health Data Exfiltration via Agent Email - ATR-2026-00852 (3367531b-af31-5618-abf2-2787dac888ff)

Detects indirect prompt injection payloads embedded in untrusted tool responses (product reviews, notes, repo descriptions) that instruct an agent to download or retrieve protected health records, medical reports, or patient data files and send them to an attacker-controlled email address. The attack pattern leverages "IMPORTANT!!! Ignore all previous instructions" combined with health-system access (download by patient/report ID) and an email-send action. Derived from vpibench indirect-pi-exfil-medical-carrier corpus. HIPAA-equivalent sensitive data; critical severity.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — Medical Record / Health Data Exfiltration via Agent Email - ATR-2026-00852 (3367531b-af31-5618-abf2-2787dac888ff) Agent Threat Rules 1
Indirect PI — Medical Record / Health Data Exfiltration via Agent Email - ATR-2026-00852 (3367531b-af31-5618-abf2-2787dac888ff) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2