Skip to content

Hide Navigation Hide TOC

Indirect PI — MFA Code / OTP Security Code Exfiltration via Injection - ATR-2026-00862 (5a138bd6-0184-547e-92a6-13ba61ece22a)

Detects indirect prompt injection payloads that instruct an agent to read an OTP (one-time password), MFA verification code, or security code from the user's email or SMS and forward it to an attacker-controlled address. This enables real-time account takeover: the attacker injects a payload, the agent reads the MFA code from an incoming email, and forwards it to the attacker before the time window expires. The attack pattern uses a "IMPORTANT!!! Ignore all previous instructions" override combined with MFA/security-code keywords and an email-forward action. Derived from vpibench indirect-pi-exfil-mfa-code corpus.

Cluster A Galaxy A Cluster B Galaxy B Level
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern Indirect PI — MFA Code / OTP Security Code Exfiltration via Injection - ATR-2026-00862 (5a138bd6-0184-547e-92a6-13ba61ece22a) Agent Threat Rules 1
Indirect PI — MFA Code / OTP Security Code Exfiltration via Injection - ATR-2026-00862 (5a138bd6-0184-547e-92a6-13ba61ece22a) Agent Threat Rules LLM Data Leakage (45d378aa-20ae-401d-bf61-7f00104eeaca) MITRE ATLAS Attack Pattern 1
Indirect PI — MFA Code / OTP Security Code Exfiltration via Injection - ATR-2026-00862 (5a138bd6-0184-547e-92a6-13ba61ece22a) Agent Threat Rules Multi-Factor Authentication Interception - T1111 (dd43c543-bb85-4a6f-aa6e-160d90d06a49) Attack Pattern 1
Indirect (a4a55526-2f1f-403b-9691-609e46381e17) MITRE ATLAS Attack Pattern LLM Prompt Injection (19cd2d12-66ff-487c-a05c-e058b027efc9) MITRE ATLAS Attack Pattern 2